A cloud-based identity and access management service for securing user authentication and resource access
The issue you're experiencing with not being able to see logs for a particular user in Microsoft Entra ID over a 7-day or 1-month period could be related to several factors:
- Log Retention Policies: Microsoft Entra ID has specific retention policies for logs based on the type of logs and the license you have. For example, audit logs are retained for 7 days for the Microsoft Entra ID Free plan and 30 days for the P1 and P2 plans. If your logs are older than the retention period, they will not be available for viewing.
- Filtering Options: When you attempt to view logs, ensure that the filters you are applying (such as user, date range, etc.) are correctly set. If the filters are too restrictive or incorrectly configured, it may result in no logs being displayed.
- Log Types: Different types of logs (audit logs, sign-in logs, etc.) have different retention periods and may not include all activities. Ensure you are looking at the right type of log that contains the activities you expect to see.
- Exporting Logs: If you need to retain logs for longer periods, consider exporting them through the diagnostic settings feature, which allows you to maintain records beyond the default retention times.
To troubleshoot this issue further, verify your license type, check the filtering settings, and consider exporting logs if necessary.
References: