{"id":21145365,"url":"https://github.com/jsa2/aadlegacyfork","last_synced_at":"2026-03-19T19:03:59.606Z","repository":{"id":103263550,"uuid":"328624820","full_name":"jsa2/AADLegacyFork","owner":"jsa2","description":"Forked version of Sign-ins using Legacy Auth with Non-interactive Sign-ins included (use at own discretion)","archived":false,"fork":false,"pushed_at":"2021-01-12T10:25:16.000Z","size":386,"stargazers_count":0,"open_issues_count":0,"forks_count":3,"subscribers_count":4,"default_branch":"main","last_synced_at":"2025-01-21T07:27:25.720Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jsa2.png","metadata":{"files":{"readme":"readme.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-01-11T10:18:53.000Z","updated_at":"2021-01-12T10:25:18.000Z","dependencies_parsed_at":null,"dependency_job_id":"934b329d-ac4c-4087-8ed6-db2bd3b24cfc","html_url":"https://github.com/jsa2/AADLegacyFork","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsa2%2FAADLegacyFork","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsa2%2FAADLegacyFork/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsa2%2FAADLegacyFork/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsa2%2FAADLegacyFork/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jsa2","download_url":"https://codeload.github.com/jsa2/AADLegacyFork/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243589255,"owners_count":20315467,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-20T08:39:45.291Z","updated_at":"2025-10-25T01:34:18.431Z","avatar_url":"https://github.com/jsa2.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"## Azure AD Workbook fork for combining interactive and non-interactive logs \nThis is fork of the existing Azure AD workbook for Legacy Auth Sign-ins. This fork combines  non-interactive and sign-in logs for legacy authentication\n\n```json\n\"fromTemplateId\": \"community-Workbooks/Azure Active Directory/SignInsUsingLegacyAuth\",\n    \"$schema\": \"https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json\"\n```\n- Compared to the original book, the 'Interuptions count'  metric is removed, if needed this metric can be added to the workbook with very little work \n- If you are interested about the combination of two log types, I wrote about that [here](https://securecloud.blog/2021/01/11/log-analytics-normalizing-different-data-types-for-analytics/)\n\n\n- [Azure AD Workbook fork for combining interactive and non-interactive logs](#azure-ad-workbook-fork-for-combining-interactive-and-non-interactive-logs)\n- [Preview](#preview)\n- [Warning](#warning)\n- [Pre-requisites](#pre-requisites)\n- [Deployment](#deployment)\n  - [Edit the included workbook.json](#edit-the-included-workbookjson)\n  - [Azure Monitor Workbooks -  create new workbook](#azure-monitor-workbooks----create-new-workbook)\n  - [Azure Monitor Workbooks - select the \u003c/\u003e code editor](#azure-monitor-workbooks---select-the--code-editor)\n  - [Azure Monitor Workbooks - View the template](#azure-monitor-workbooks---view-the-template)\n## Preview\nUpdated workbook includes new sign-in types, and displays source in \"Sign in details\"\n![img](img/top.png)\n\n## Warning\nMinimal description and context provided.\n\nRecommended reading:\nhttps://docs.microsoft.com/en-us/azure/azure-monitor/log-query/log-query-overview\nhttps://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-all-sign-ins\n\n\n## Pre-requisites\n- Azure AD and Azure Subscription\n- Export AADNonInteractiveUserSignInLogs \u0026 SigninLogs are exported to existing Log Analytics Workspace\n  \n## Deployment\n\n### Edit the included workbook.json\n- in workbook.json replace the following values with the log analytics workspaces you have exported the logs to (Starting from line 485)\n```json\n \"defaultResourceIds\": [\n      \"/subscriptions/3539c2a2-cd25-48c6-b295-14e59334ef1c/resourceGroups/rg-m365758644/providers/Microsoft.OperationalInsights/workspaces/m365x758644\",\n    ],\n    \"fallbackResourceIds\": [\n      \"/subscriptions/3539c2a2-cd25-48c6-b295-14e59334ef1c/resourceGroups/rg-m365758644/providers/Microsoft.OperationalInsights/workspaces/m365x758644\",\n    ],\n``` \n### Azure Monitor Workbooks -  create new workbook\n![img](img/monitor-new.png)\n### Azure Monitor Workbooks - select the \u003c/\u003e code editor\n![img](img/monitor-new-2.png)\n- paste contents of workbook.json to code editor, and click apply\n  - \"Ensure 'Gallery Template' is selected (should be default)\n  \n![img](img/monitor-new-3.png)\n### Azure Monitor Workbooks - View the template\n![img](img/monitor-new-4.png)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsa2%2Faadlegacyfork","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjsa2%2Faadlegacyfork","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsa2%2Faadlegacyfork/lists"}