Edit

Supported logs for Microsoft.AAD/DomainServices

The following table lists the types of logs available for the Microsoft.AAD/DomainServices resource type.

For a list of supported metrics, see Supported metrics - Microsoft.AAD/DomainServices

Category Costs to export Log table Supports basic log plan Supports ingestion-time transformation Example queries
AccountLogon No AADDomainServicesAccountLogon No Yes Queries
AccountManagement No AADDomainServicesAccountManagement No Yes Queries
DetailTracking No No No
DirectoryServiceAccess No AADDomainServicesDirectoryServiceAccess No Yes Queries
DNSServerAuditsDynamicUpdates - Preview Yes AADDomainServicesDNSAuditsDynamicUpdates

DNS server audit events enable change tracking on the DNS server. This table contains operational audit events for dynamic updates.

Yes Yes
DNSServerAuditsGeneral - Preview Yes AADDomainServicesDNSAuditsGeneral

DNS server audit events enable change tracking on the DNS server. An audit event is logged each time server, zone, or resource record settings are changed. This includes operational events such as zone transfers, and DNSSEC zone signing and unsigning. This table captures audit events that are not from dynamic updates.

Yes Yes
LogonLogoff No AADDomainServicesLogonLogoff No Yes Queries
ObjectAccess No No No
PolicyChange No AADDomainServicesPolicyChange No Yes Queries
PrivilegeUse No AADDomainServicesPrivilegeUse No Yes Queries
SystemSecurity No No No

Next Steps