
Sep 17, 2024
1.0.0
ThreatQ Versions >= 5.25.0
ThreatQ Action for Microsoft Entra
Overview
The Microsoft Entra integration allows a ThreatQ user to interact with the Microsoft cloud-based identity and access management service. This can be used to control access to external Microsoft resources and applications.
The integration provides the following action:
- Microsoft Entra Conditional Access Policy - creates or updates a Microsoft Entra Conditional Access Policy that blocks access to applications based on network locations.
The action is compatible with the following indicator types:
- IP Address
- IPv6 Address
- CIDR Block
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.