Monitor Entra ID high-risk users with Microsoft Graph, TheHive and Slack

Go to Workflow
0 views
Built by Muhammad Bin Zohaib Muhammad Bin Zohaib
Created on September 28, 2026

Description

Quick Overview
This workflow polls Microsoft Entra ID Protection for new high-risk risk detections, aggregates them per user, enriches them with risky-user and recent sign-in context from Microsoft Graph, then creates or updates matching alerts in TheHive and posts a summary to a Slack security channel.

How it works
Runs every 30 minutes on a schedule.
Queries Microsoft Graph Identity Protection for risk detections with risk level set to high from the last 20 minutes, following @odata.nextLink pagination.
Groups detections by user and aggregates key context such as detection types, risk states, IP addresses, locations, and first/last detection timestamps.
Retrieves additional user context from Microsoft Graph by fetching the risky user record and the user’s five most recent sign-in events.
Correlates deterministic signals (for example privileged roles, multiple countries, confirmed compromise state, or non-compliant devices) to classify severity and build a detailed incident description.
Queries TheHive for existing open alerts of type entra-id-risk and either updates the matching alert (by sourceRef) or creates a new alert with observables.
Posts a formatted alert summary and TheHive reference to a chosen Slack channel.

Setup
Create a Microsoft Entra ID (Microsoft Graph) OAuth2 credential with permissions for IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, and AuditLog.Read.All.
Add a TheHive 5 credential with permission to query, create, and update alerts, and ensure your TheHive instance is reachable from n8n.
Add a Slack OAuth2 credential and select the security/SOC channel to post notifications to.
Review and adjust the lookback filter (currently last 20 minutes) and schedule interval (every 30 minutes) to match your monitoring requirements.

Nodes Used (4)

Code
n8n-nodes-base.code
HTTP Request
n8n-nodes-base.httpRequest
Slack
n8n-nodes-base.slack
TheHive 5
n8n-nodes-base.theHiveProject