How to configure security monitoring and alerting for user management

Manuel 0 Reputation points
2024-03-12T10:47:26.2266667+00:00

I am trying to create the following alerts:

User added Triggered when a new user has been added.
User removed Triggered when a any user has been removed.
User privilege changes Triggered by any configuration change of any user.

I already tried to do this via the Audit Logs within the Identity section but the retention time is only 1 month there:

User's image

So my question is:

  1. can I somehow increase the retention time?
  2. can I somehow create a Monitor for these events and use this as a workaround for the 1 month retention time?
Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,645 questions
Microsoft Security Microsoft Identity Manager
{count} votes

1 answer

Sort by: Most helpful
  1. SwathiDhanwada-MSFT 18,996 Reputation points Moderator
    2024-03-13T05:10:58.6733333+00:00

    @Manuel Log storage within Microsoft Entra varies by report type and license type.

    User's image

    You can retain the audit and sign-in activity data for longer than the default retention period using Azure Monitor. For more information, see Integrate Microsoft Entra logs with Azure Monitor logs.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.