Use audit logs to track and monitor events in Microsoft Intune
Article
In Microsoft Intune, there are audit logs that include a record of activities that generate a change. For example, the create, update (edit), delete, assign, and remote actions all create audit events.
Administrators can review the audit logs to track and monitor events for most Intune workloads. Auditing is enabled for all customers. It can't be disabled.
Who can access the data?
Users with the following permissions can review audit logs:
Administrators assigned to an Intune role with Audit data - Read permissions. For a list of built-in Intune roles that have this permission, go to Built-in role permissions for Microsoft Intune.
View the audit logs
You can review audit logs in the monitoring group for each Intune workload, like compliance or Conditional Access.
Audit logs and operational logs can also be routed to Azure Monitor. In the Intune admin center, select Tenant administration > Audit logs > Export:
When you export, a .csv file is created and saved locally, possibly in C:\Users\UserName\AppData\Local\Temp\MicrosoftEdgeDownloads\GUID.
When looking at the .csv file:
Initiated by (actor) includes information on who ran the task, and where it was run.
For example, if you run the activity in Intune in the Azure portal, then Application always lists Microsoft Intune portal extension, and the Application ID always uses the same GUID.
The Target(s) section lists multiple targets and the properties that were changed.