Summary

Completed

Your organization recently began integrating its identities with Microsoft Entra ID. Your security team wants improved security reporting and monitoring to help reduce incidents.

Your role is to demonstrate to the team the reporting capabilities of Microsoft Entra ID, to ensure that proper monitoring is in place and the team is alerted when security events occur.

By using sign-in and activity logs, Azure Monitor can provide alerts about unusual or unexpected user behavior. With Azure Monitor and a Log Analytics workspace, you can build custom dashboards that display metrics and essential data about user activity and security in Microsoft Entra ID.

Without alerts and a single, at-a-glance, dashboard view of your team's Microsoft Entra estate, the team might have no warning about unexpected incidents until it's too late.

In this module, you've learned how to build that dashboard view. You helped prevent data loss by creating alerts for unexpected incidents.

Learn more

To learn more about events in Microsoft Entra ID, see the following articles: