Microsoft Entra activity logs include audit logs, which is a comprehensive report on every logged event in Microsoft Entra ID. Changes to applications, groups, users, and licenses are all captured in the Microsoft Entra audit logs.
Two other activity logs are also available to help monitor the health of your tenant:
Sign-ins – Information about sign-ins and how your resources are used by your users.
Provisioning – Activities performed by the provisioning service, such as the creation of a group in ServiceNow or a user imported from Workday.
This article gives you an overview of the audit logs, such as the information they provide and what kinds of questions they can answer.
What can you do with audit logs?
Audit logs in Microsoft Entra ID provide access to system activity records, often needed for compliance. You can get answers to questions related to users, groups, and applications.
Users:
What types of changes were recently applied to users?
How many users were changed?
How many passwords were changed?
Groups:
What groups were recently added?
Have the owners of group been changed?
What licenses are to a group or a user?
Applications:
What applications were, updated, or removed?
Has a service principal for an application changed?
What custom attribute values were assigned to a user?
Athugasemd
Entries in the audit logs are system generated and can't be changed or deleted.
What do the logs show?
Audit logs display several valuable details on the activities in your tenant. For a full list of the available audit activities, see Audit activity reference. The Microsoft Entra admin center defaults to the Directory tab, which displays the following information:
You can view Microsoft 365 activity logs from the Microsoft 365 admin center. Even though Microsoft 365 activity and Microsoft Entra activity logs share many directory resources, only the Microsoft 365 admin center provides a full view of the Microsoft 365 activity logs.
You can also access the Microsoft 365 activity logs programmatically by using the Office 365 Management APIs.
Most standalone or bundled Microsoft 365 subscriptions have back-end dependencies on some subsystems within the Microsoft 365 datacenter boundary. The dependencies require some information write-back to keep directories in sync and essentially to help enable hassle-free onboarding in a subscription opt-in for Exchange Online. For these write-backs, audit log entries show actions taken by "Microsoft Substrate Management." These audit log entries refer to create/update/delete operations executed by Exchange Online to Microsoft Entra ID. The entries are informational and don't require any action.
Los registros de auditoría y diagnóstico de Microsoft Entra ID proporcionan una vista enriquecida de cómo los usuarios acceden a la solución de Azure. Obtenga información sobre cómo supervisar, solucionar problemas y analizar los datos de inicio de sesión.
Muestre las características de Microsoft Entra ID para modernizar las soluciones de identidad, implementar soluciones híbridas e implementar la gobernanza de identidades.