Monitor Entra ID high-risk users with Microsoft Graph, TheHive and Slack
Quick Overview
Description
Quick Overview This workflow polls Microsoft Entra ID Protection for new high-risk risk detections, aggregates them per user, enriches them with risky-user and recent sign-in context from Microsoft Graph, then creates or updates matching alerts in TheHive and posts a summary to a Slack security channel. How it works Runs every 30 minutes on a schedule. Queries Microsoft Graph Identity Protection for risk detections with risk level set to high from the last 20 minutes, following @odata.nextLink pagination. Groups detections by user and aggregates key context such as detection types, risk states, IP addresses, locations, and first/last detection timestamps. Retrieves additional user context from Microsoft Graph by fetching the risky user record and the user’s five most recent sign-in events. Correlates deterministic signals (for example privileged roles, multiple countries, confirmed compromise state, or non-compliant devices) to classify severity and build a detailed incident description. Queries TheHive for existing open alerts of type entra-id-risk and either updates the matching alert (by sourceRef) or creates a new alert with observables. Posts a formatted alert summary and TheHive reference to a chosen Slack channel. Setup Create a Microsoft Entra ID (Microsoft Graph) OAuth2 credential with permissions for IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, and AuditLog.Read.All. Add a TheHive 5 credential with permission to query, create, and update alerts, and ensure your TheHive instance is reachable from n8n. Add a Slack OAuth2 credential and select the security/SOC channel to post notifications to. Review and adjust the lookback filter (currently last 20 minutes) and schedule interval (every 30 minutes) to match your monitoring requirements. An n8n automation workflow template by Muhammad Bin Zohaib.
Community Metrics
Author
Muhammad Bin Zohaib
Platform
web
Pricing model
free
Categories
- Automation
Tags
- n8n
- workflow
- http-request
- slack
- code
- thehive-5
Capabilities
- 4 nodes