Skip to content

Commit 8a9492b

Browse files
committed
Add a prerequisite for streaming logs to Sentinel
1 parent f1caac7 commit 8a9492b

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

articles/sentinel/connect-azure-active-directory.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,11 @@ ms.author: guywild
1515

1616
[Microsoft Entra ID](/entra/fundamentals/what-is-entra) logs provide comprehensive information about users, applications, and networks accessing your Entra tenant. This article explains the types of logs you can collect using the Microsoft Entra ID data connector, how to enable the connector to send data to Microsoft Sentinel, and how to find your data in Microsoft Sentinel.
1717

18+
19+
## Prerequisites
20+
21+
A Microsoft Entra Workload ID Premium license is required to stream **AADRiskyServicePrincipals** and **AADServicePrincipalRiskEvents** logs to Microsoft Sentinel.
22+
1823
## Microsoft Entra ID data connector data types
1924

2025
This table lists the logs you can send from Microsoft Entra ID to Microsoft Sentinel using the Microsoft Entra ID data connector. Sentinel stores these logs in the Log Analytics workspace linked to your Microsoft Sentinel workspace.

0 commit comments

Comments
 (0)