You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过高级狩猎查询(KQL)识别Azure AD证书认证登录及数据来源

关于Azure AD证书认证登录的KQL查询及日志位置
  • 可以通过高级狩猎的KQL查询判断用户是否使用证书身份认证登录。
  • 这类登录数据会出现在AAdSignInEventsBeta表中,同时也会在标准日志表SigninLogs里记录。

基础KQL查询示例

AAdSignInEventsBeta
| extend CertAuthMethod = AuthenticationDetails[0].authenticationMethod
| where CertAuthMethod == "X509Certificate"
| project TimeGenerated, UserPrincipalName, IPAddress, CertAuthMethod, AppDisplayName, Status

关键字段说明

  • AuthenticationDetails.authenticationMethod:当该字段值为X509Certificate时,即可判定对应登录事件使用了证书身份认证。
  • 可结合Status字段筛选成功/失败的登录记录,或通过UserPrincipalName、IPAddress缩小查询范围。

提取证书详细信息的进阶查询

如果需要获取证书颁发者、序列号等额外信息,可以解析AdditionalFields字段:

AAdSignInEventsBeta
| where AuthenticationDetails has_any ('X509Certificate')
| extend CertDetails = parse_json(AdditionalFields)
| where isnotempty(CertDetails.CertificateAuthenticationDetails)
| project 
    TimeGenerated, 
    UserPrincipalName, 
    IPAddress, 
    CertDetails.CertificateAuthenticationDetails.Issuer,
    CertDetails.CertificateAuthenticationDetails.SerialNumber

内容的提问来源于stack exchange,提问作者user14913641

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 22:25:40