Skip to content

New Query: Account Enabled (Microsoft Defender for Identity)#53

Merged
dweissbacher merged 1 commit into
mainfrom
submission/5e041d47-8f50-4893-9c6a-27f8db26806f
May 21, 2026
Merged

New Query: Account Enabled (Microsoft Defender for Identity)#53
dweissbacher merged 1 commit into
mainfrom
submission/5e041d47-8f50-4893-9c6a-27f8db26806f

Conversation

@byteray-cql-hub-bot
Copy link
Copy Markdown
Contributor

New Query Submission

Name: Account Enabled (Microsoft Defender for Identity)
Author: Kundan Kumar
Submission ID: 5e041d47-8f50-4893-9c6a-27f8db26806f

Description

Detects when a previously disabled user account is re‑enabled in Active Directory. While this may be part of normal administrative activity, it can also indicate an attempt to restore access to an account for unauthorized use and should be reviewed.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher dweissbacher merged commit f050e5f into main May 21, 2026
2 checks passed
@dweissbacher dweissbacher deleted the submission/5e041d47-8f50-4893-9c6a-27f8db26806f branch May 21, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant