Skip to content

SigninAnomalyMetadata

Metadata for a sign-in anomaly violation. The subject is the target that had the sign-in failure spike, and the actors are the identities attributed to the changes behind the anomaly.

Fields

Field Type Description
actors [SigninAnomalyActor!]! Identities attributed to the target changes behind this sign-in anomaly.
creationTime DateTime The time the target was created. Empty when this information is unavailable.
detectedOn DateTime The time the sign-in anomaly was first detected.
displayName String! Display name of the target.
domainFid String! Rubrik's identifier for the domain or tenant the target belongs to. This is the value the remediation APIs expect as the resource ID when reverting the conditional access policy changes behind this sign-in anomaly; the violation's own resource ID is the conditional access policy ID and does not resolve there. Distinct from the domain unique ID, which is the identity provider's own identifier for the same domain or tenant.
domainName String! The domain or tenant the target belongs to.
domainUniqueId String! Stable identifier of the domain or tenant the target belongs to.
idpType IdpType! Identity provider of the target. Always Microsoft Entra ID for sign-in anomaly detection.
lastSeen DateTime The time of the most recent observation of the sign-in anomaly.
principalType ViolationPrincipalType! Type of the target principal.
uniqueId String! Stable unique identifier of the target.