Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
13,543 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have recently starting receiving a 400 error on my Splunk Add-on for Microsoft Azure signIns input for https://graph.microsoft.us/v1.0/auditLogs/signIns. Are there any new known issues with reaching the signIns endpoint for graph.microsoft.us? I am not having any issues with the commercial endpoint for signIns.
There's no issues with pulling the directoryAudit input for https://graph.microsoft.us/v1.0/auditLogs/directoryAudits. All basic troubleshooting steps have been taken.
Hello @Anthony Dehn ,
From the description I could understand that you are getting no response (400) while querying the sign-in logs with .US endpoint.
I tried to test this in my lab with (Splunk cloud) commercial endpoints and found no issues. I would like to check the behavior in your environment. I could see two different endpoints being called for audit and signins.
I would like to understand the following:
Hello @Anthony Dehn ,
Hope you got a chance to see my response above. Would appreciate your response on queries above to drill down the issue.