Skip to content

[Rule Tuning] Align Microsoft Graph Email Access /me Path Predicate#6335

Open
raylee-hawkins wants to merge 1 commit into
elastic:mainfrom
raylee-hawkins:fix-graph-email-me-path-gate
Open

[Rule Tuning] Align Microsoft Graph Email Access /me Path Predicate#6335
raylee-hawkins wants to merge 1 commit into
elastic:mainfrom
raylee-hawkins:fix-graph-email-me-path-gate

Conversation

@raylee-hawkins

@raylee-hawkins raylee-hawkins commented Jun 27, 2026

Copy link
Copy Markdown

Summary

  • Aligns the Microsoft Graph email access rule's /me path predicate with the /me/... mail paths referenced in the rule description and investigation guidance.
  • Updates the predicate from /v1.0/me/*cc to /v1.0/me/*.
  • Keeps the existing mail / messages / inbox constraints in place.
  • Does not add data sources or change rule logic beyond this path predicate tuning.

Validation

Local validation passed:

  • python -m detection_rules validate-rule rules/integrations/azure/collection_graph_email_access_by_unusual_public_client_via_graph.toml
  • python -m detection_rules test - 232 passed, 19 skipped

Scope

  • One TOML rule only.
  • No runtime signal claim.
  • No production or customer claim.

Related

@botelastic botelastic Bot added Domain: Cloud Integration: Azure azure related rules labels Jun 27, 2026
@raylee-hawkins raylee-hawkins changed the title [Rule Tuning] Fix Microsoft Graph Email Access /me Path Predicate [Rule Tuning] Align Microsoft Graph Email Access /me Path Predicate Jun 27, 2026
@raylee-hawkins

Copy link
Copy Markdown
Author

Looks like the Add PR Guidelines Comment workflow failed because the PR does not currently have one of the guideline labels the workflow expects.

This PR is a rule tuning change. Could a maintainer apply the Rule: Tuning label so the guideline requirement is satisfied?

Local validation is listed in the PR summary.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant