Azure Sentinel - Azure Active Directroy Data connector does not display sign-in logs

VegAas 1 Reputation point
2022-04-26T07:24:24.267+00:00

Hi.
In february 2022 I set up Microsoft Senitel with Azure Active Directory and everything worked fine. All logs from the connector synced. In march it suddenly stopped working, now I only get AuditLogs. The only changes I have made is the change from E3 + Premium P1 -> Business Premium license. I have attempted to assign back a P1 license with no changes. The tenant have around 120 active users, so there is a lot of sign in activity.
196502-image.png

Logs is enabled and the user I am logged into have global admin access.
PS C:\windows\system32> Get-AdminAuditLogConfig | FL UnifiedAuditLogIngestionEnabled
UnifiedAuditLogIngestionEnabled : True

Need help to point me in the right directon here. I have also looked at this
https://learn.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
986 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Andrew Blumhardt 9,496 Reputation points Microsoft Employee
    2022-04-26T18:05:39.873+00:00

    You might try disconnecting and reconnecting. Also, you might try verifying the diagnostic setting manually:

    https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-log-analytics#send-logs-to-azure-monitor

    0 comments No comments

  2. VegAas 1 Reputation point
    2022-04-27T12:38:14.373+00:00

    Not showing anything here. I do not see a option to remove the connector and enable it again. I have attempted to remove and add sign in logs multiple times.

    196930-image.png

    0 comments No comments

  3. Alistair Ross 7,101 Reputation points Microsoft Employee
    2022-04-27T13:55:42.807+00:00

    Hi @VegAas ,

    You are correct when you say there isn't the option to remove the connector. This is a built in connector and "unchecking" logs is effectively removing it. When you check these boxes, such as Sign-In Logs and click Apply changes, this updates a diagnostic setting on the same Azure AD Tenant that Microsoft Sentinel resides in, providing you have the correct permissions to do so.

    All the details to send the logs to Sentinel manually can be found in the link @Andrew Blumhardt shared howto-integrate-activity-logs-with-log-analytics. This method is also needed if you are setting the logs up across tenants, using Azure Lighthouse, as the built in connector doesn't support this. Though keep in mind, some features, such as UEBA do not support lighthouse and therefore you won't see factual information such as a users manager / location etc if the AD user resides in a different tenant.

    Once you've done this and are sending data to Sentinel, the connector will show as enabled, as it is only monitoring the ingestion of data into the relevant table.

    0 comments No comments

  4. Andrew Blumhardt 9,496 Reputation points Microsoft Employee
    2022-04-27T13:59:08.977+00:00

    I assume all the connector is doing is setting the diagnostics to the same workspace. I cannot see my settings due to lab restrictions (not a GA). I would just set it manually if needed. This could also raise an error that could help in explaining the issue.

    0 comments No comments