Skip to content

Commit 9f05dd7

Browse files
authored
Merge pull request #221496 from MicrosoftDocs/main
12/14 AM Publish
2 parents f512a0e + ebfb971 commit 9f05dd7

File tree

97 files changed

+767
-348
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

97 files changed

+767
-348
lines changed

.openpublishing.redirection.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,10 @@
11
{
22
"redirections": [
3+
{
4+
"source_path_from_root": "/articles/backup/backup-create-rs-vault.md",
5+
"redirect_url": "/azure/backup/backup-create-recovery-services-vault",
6+
"redirect_document_id": false
7+
},
38
{
49
"source_path_from_root": "/articles/storage/queues/storage-quickstart-queues-dotnet-legacy.md",
510
"redirect_url": "/azure/storage/queues/storage-quickstart-queues-dotnet",

articles/active-directory/reports-monitoring/howto-download-logs.md

Lines changed: 35 additions & 54 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.topic: how-to
1010
ms.workload: identity
1111
ms.subservice: report-monitor
12-
ms.date: 10/31/2022
12+
ms.date: 12/14/2022
1313
ms.author: sarahlipsey
1414
ms.reviewer: besiler
1515

@@ -20,75 +20,56 @@ ms.collection: M365-identity-device-management
2020

2121
The Azure Active Directory (Azure AD) portal gives you access to three types of activity logs:
2222

23-
- **[Sign-ins](concept-sign-ins.md)** Information about sign-ins and how your resources are used by your users.
24-
- **[Audit](concept-audit-logs.md)** Information about changes applied to your tenant such as users and group management or updates applied to your tenant’s resources.
25-
- **[Provisioning](concept-provisioning-logs.md)**Activities performed by the provisioning service, such as the creation of a group in ServiceNow or a user imported from Workday.
23+
- **[Sign-ins](concept-sign-ins.md)**: Information about sign-ins and how your resources are used by your users.
24+
- **[Audit](concept-audit-logs.md)**: Information about changes applied to your tenant such as users and group management or updates applied to your tenant’s resources.
25+
- **[Provisioning](concept-provisioning-logs.md)**: Activities performed by a provisioning service, such as the creation of a group in ServiceNow or a user imported from Workday.
2626

27-
Azure AD stores the data in these logs for a limited amount of time. As an IT administrator, you can download your activity logs to have a long-term backup.
27+
Azure AD stores the data in these logs for a limited amount of time. As an IT administrator, you can download your activity logs to have a long-term backup. This article explains how to download activity logs in Azure AD.
2828

29-
This article explains how to download activity logs in Azure AD.
29+
## Prerequisites
3030

31-
## What you should know
31+
The option to download the data of an activity log is available in all editions of Azure AD. You can also download activity logs using Microsoft Graph; however, downloading logs programmatically requires a premium license.
3232

33-
- In the Azure AD portal, you can find several entry points to the activity logs. For example, the **Activity** section on the [Users](https://portal.azure.com/#blade/Microsoft_AAD_IAM/UsersManagementMenuBlade/MsGraphUsers) or [groups](https://portal.azure.com/#blade/Microsoft_AAD_IAM/GroupsManagementMenuBlade/AllGroups) page. However, there is only one location that provides you with an initially unfiltered view of the logs: the **Monitoring** section on the [Azure AD](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Overview) page.
34-
35-
- Azure AD stores activity logs only for a specific period. For more information, see [How long does Azure AD store reporting data?](reference-reports-data-retention.md)
33+
The following roles provide read access to audit logs. Always use the least privileged role, according to Microsoft [Zero Trust guidance](/security/zero-trust/zero-trust-overview).
34+
- Reports Reader
35+
- Security Reader
36+
- Security Administrator
37+
- Global Reader (sign-in logs only)
38+
- Global Administrator
3639

37-
- By downloading the logs, you can control for how long logs are stored.
40+
## Log download details
3841

39-
- Your download is based on the filter you have set.
42+
Azure AD stores activity logs for a specific period. For more information, see [How long does Azure AD store reporting data?](reference-reports-data-retention.md) By downloading the logs, you can control how long logs are stored.
4043

4144
- Azure AD supports the following formats for your download:
42-
4345
- **CSV**
44-
4546
- **JSON**
47+
- Timestamps in the downloaded files are based on UTC.
48+
- For large data sets (> 250,000 records), you should use the [reporting API](/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0) to download the data.
4649

47-
- The timestamps in the downloaded files are always based on UTC.
48-
49-
- For large data sets (> 250 000 records), you should use the reporting API to download the data.
50-
51-
52-
## What license do you need?
53-
54-
The option to download the data of an activity log is available in all editions of Azure AD.
55-
56-
You can also download activity logs using Microsoft Graph; however, downloading logs grammatically requires a premium incense.
57-
58-
59-
## Who can do it?
60-
61-
While the global administrator works, you should use an account with lower privileges to perform this task. To access the audit logs, the following roles work:
62-
63-
- Reports Reader
64-
- Global Reader
65-
- Security Administrator
66-
- Security Reader
67-
68-
69-
## How to do it
70-
71-
72-
**To download an activity log:**
50+
## How to download activity logs
7351

74-
1. Navigate to the activity log view you care about:
75-
76-
- [The sign-ins log](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/SignIns)
77-
78-
- [The audit log](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/SignIns)
79-
80-
- [The provisioning log](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/ProvisioningEvents)
81-
52+
You can access the activity logs from the **Monitoring** section of Azure AD or from the **Users** page of Azure AD. If you view the audit logs from the **Users** page, the filter category will be set to **UserManagement**. Similarly, if you view the audit logs from the **Groups** page, the filter category will be set to **GroupManagement**. Regardless of how you access the activity logs, your download is based on the filter you've set.
8253

83-
2. **Add** the required filter.
54+
1. Navigate to the activity log you need to download.
55+
1. Adjust the filter for your needs.
56+
1. Select **Download**.
57+
- For audit and sign-in logs, a window appears where you'll select the download format (CSV or JSON).
58+
- For provisioning logs, you'll select the download format (CSV of JSON) from the Download button.
59+
- You can change the File Name of the download.
60+
- Select the **Download** button.
61+
1. The download processes and sends the file to your default download location.
8462

85-
![Add filter](./media/\howto-download-logs/add-filter.png)
63+
The following screenshot shows the download window from the audit and sign-in log download process.
64+
![Screenshot of the audit log download process.](./media/howto-download-logs/audit-log-download.png)
8665

87-
3. **Download** the data.
66+
The following screenshot shows menu options for the provisioning log download process.
67+
![Screenshot of the provisioning log download button options.](./media/howto-download-logs/provisioning-logs-download.png)
8868

89-
![Download log](./media/\howto-download-logs/download-log.png)
69+
If your tenant has enabled the [sign-in logs preview](concept-all-sign-ins.md), more options are available after selecting **Download**. The sign-in logs preview include interactive and non-interactive user sign-ins, service principal sign-ins, and managed identity sign-ins.
70+
![Screenshot of the download options for the sign-in logs preview.](media/howto-download-logs/sign-in-preview-download-options.png)
9071

9172
## Next steps
9273

93-
- [Sign-ins logs in Azure AD](concept-sign-ins.md)
94-
- [Audit logs in Azure AD](concept-audit-logs.md)
74+
- [Integrate Azure AD logs with Azure Monitor](howto-integrate-activity-logs-with-log-analytics.md)
75+
- [Access Azure AD logs using the Graph API](quickstart-access-log-with-graph-api.md)
79.4 KB
Loading
25.3 KB
Loading
37.2 KB
Loading

0 commit comments

Comments
 (0)