circle-exclamation
Documentation is updated to support Bsure version 2. Select version 1 in the menu if you are still running that version.

circle-questionFrequently Asked Questions

Common questions and answers

How do I get assistance?

Please see our support pagearrow-up-right

Which permissions are required for installation?

Entra ID

The Global Administratorarrow-up-right plays a vital role during the installation of the Bsure Datacollector. You will require a highly privileged user account due to the restrictions that Microsoft has imposed on the assignment of MS Graph Roles to applicationsarrow-up-right. Although the Privileged Role Administratorarrow-up-right may also be used, we've skipped that in the prior steps. This decision was influenced by the familiarity of most customers with the Global Administrator Role

Azure Subscription

When installing the Bsure Datacollector, the Azure Resource Manager has to assign permissions to certain identities. The task of assigning permissions within an Azure Subscription is reserved for the Owner Rolearrow-up-right. Additionally, access to the actual resources within the subscription is required, rendering the User Access Administratorarrow-up-right insufficient for this purpose

Can we add last logon info from on-premises AD?

Bsure Insights show users last successful sign-in date in Entra ID. Our app does not have information about when users last logged on to your on-premises Active Directory.

Hybrid customers may have users synced to Entra ID, showing as inactive in Bsure Insights, because they have not signed in to any Microsoft cloud resources recently. But they can still be active in your local AD.

To bring the last logon information from AD in to Bsure Insights, you have to add this information to a user attribute that is being synced to Entra ID.

Our recommended approach:

  • Run a PowerShell script against your local AD to write Last Logon date to an unused Extension Attribute.

  • Schedule the script to run daily, using Task Scheduler or an automation tool of your choice.

Script example:

You have to adapt this script to your local environment. Change the OU path, and change extensionattribute2 to the extension attribute you choose.

circle-info

This script writes LastLogonTimestamp in format YYYY-MM-DD to the selected ExtensionAttribute. The ExtensionAttribute properties are in string format in Bsure Insights.

NB! LastLogonTimestamp in ActiveDirectory may have up to 14 days delay. Read more about the difference between LastLogon, LastLogonTimestamp and LastLogonDate in Active Directory herearrow-up-right.

How can we delete the Managed Application?

To find the Managed Application Center, enter "Managed Application Center" into the search bar at the top of the page on https://portal.azure.comarrow-up-right. Then, select the "Managed Application Center" option from the search results.

Navigate to "All Applications" and find the application you installed. The name of the application will be the same as the one you selected during the installation process. Click on the application name to access the Managed Application.

Click on the "Delete" button and confirm your action to initiate the deletion process.

Last sign-in date for users used in Bsure Insights

Last sign-in date for users is defined as the date of the user's most recent successful interactive or non-interactive sign-in. It is the property lastSuccessfulSignInDateTimearrow-up-right from Entra ID.

In Entra ID you will see date and time for "Last interactive sign-in" and "Last non-interactive sign-in":

These dates represent the latest sign-in attempt regardless if it was successful or not. An unsuccessful user sign-in from a browser in e.g. a conditional access blocked country would update the "Last interactive sign-in" on that specific user, ref

In Bsure Insights we set a blank sign-in date if Microsoft graph returns a blank value for the property lastSuccessfulSignInDateTimearrow-up-right.

According to Microsoft they started populating this field December 1. 2023, but it seems like lastSuccessfulSignInDateTimearrow-up-right was populated from early November 2023arrow-up-right.

It is not possible to provide a "last sign-in" date for users not signed in since then, and in Bsure Insights reports they will have a blank "Last sign-in", since we simply don't know when or if they ever signed in successfully.

Sign-in logs: What information is collected and how it's stored in Bsure Insights

Bsure Insights data collector store the latest successful unique sign-in, unique combination of appId, location_countryOrRegion and userid. It also stores when sign-in event happened, and resourcename, resourceid, applicationname and sign-in type (interactive or non-interactive) related to that unique sign-in event.

Meaning we only store the latest successful sign-in a specific user made to a specific app from a specific country.

Add your own custom domain name / change URL

Bsure will add this capability in the customer app later. If you would like to rename the the url to a more friendly one, like bsure.yourorg.com, now, please contact us at [email protected]envelope

Process takes approximately 15 minutes. You would need access to your DNS hosting "yourorg.com" and Entra ID as an Application Owner or higher.

We will then schedule a meeting for 30 minutes to configure your wanted custom domain name.

Task
Responsible

Add custom domain name to customerapp

Bsure

Configure DNS

You

Add certificate and binding

Bsure

Change env variable on customerapp

Bsure

Change redirect url on app registration

You

Last updated

Was this helpful?