@@ -9,7 +9,7 @@ ms.service: active-directory
9
9
ms.topic : reference
10
10
ms.workload : identity
11
11
ms.subservice : report-monitor
12
- ms.date : 08/23 /2023
12
+ ms.date : 09/14 /2023
13
13
ms.author : sarahlipsey
14
14
ms.reviewer : dhanyahk
15
15
@@ -22,11 +22,50 @@ This article provides a comprehensive list of the audit categories and their rel
22
22
23
23
Audit log activities and categories change periodically. The tables are updated regularly, but may not be in sync with what is available in Azure AD. Provide us with feedback if you think there's a missing audit category or activity.
24
24
25
- 1 . Sign in to the ** Azure portal ** using one of the [ required roles ] ( concept-audit-logs .md) .
26
- 1 . Browse to ** Azure Active Directory ** > ** Audit logs** .
25
+ 1 . Sign in to the [ Microsoft Entra admin center ] ( https://entra.microsoft.com ) as at least a [ Reports Reader ] ( ../roles/permissions-reference .md#reports-reader ) .
26
+ 1 . Browse to ** Identity ** > ** Monitoring & health ** > ** Audit logs** .
27
27
1 . Adjust the filters accordingly.
28
28
1 . Select a row from the resulting table to view the details.
29
29
30
+ ## AAD Management UX
31
+
32
+ | Audit Category| Activity|
33
+ | ---| ---|
34
+ | AdministrativeUnit| Bulk add members to administrative unit - finished (bulk)|
35
+ | AdministrativeUnit| Bulk remove members to administrative unit - finished (bulk)|
36
+ | AdministrativeUnit| started (bulk)|
37
+ | DeviceManagement| Bulk add authentication devices - finished (bulk)|
38
+ | DeviceManagement| Download devices - finished (bulk)|
39
+ | DeviceManagement| started (bulk)|
40
+ | DirectoryManagement| Bulk download hardware tokens - finished (bulk)|
41
+ | DirectoryManagement| Download registration and reset events - finished (bulk)|
42
+ | DirectoryManagement| Download role assignments - finished (bulk)|
43
+ | DirectoryManagement| Download service principals - finished (bulk)|
44
+ | DirectoryManagement| Download user registration details - finished (bulk)|
45
+ | DirectoryManagement| Download users - finished (bulk)|
46
+ | DirectoryManagement| Export summary data - finished (bulk)|
47
+ | DirectoryManagement| Export summary data new - finished (bulk)|
48
+ | DirectoryManagement| started (bulk)|
49
+ | GroupManagement| Bulk import group members - finished (bulk)|
50
+ | GroupManagement| Bulk remove group members - finished (bulk)|
51
+ | GroupManagement| Download group members - finished (bulk)|
52
+ | GroupManagement| Download groups - finished (bulk)|
53
+ | GroupManagement| started (bulk)|
54
+ | Policy| Add blocked user|
55
+ | Policy| Add bypass user|
56
+ | Policy| Clear block on user|
57
+ | Policy| Remove bypassed user|
58
+ | Policy| Update Sign-In Risk Policy|
59
+ | Policy| Update User RIsk and MFA Registration Policy|
60
+ | UserManagement| Bulk create users - finished (bulk)|
61
+ | UserManagement| Bulk delete users - finished (bulk)|
62
+ | UserManagement| Bulk invite users - finished (bulk)|
63
+ | UserManagement| Bulk restore deleted users - finished (bulk)|
64
+ | UserManagement| Download users - finished (bulk)|
65
+ | UserManagement| Bulk create users - finished (bulk)|
66
+ | UserManagement| started (bulk)|
67
+
68
+
30
69
## Access reviews
31
70
32
71
With [ Azure AD Identity Governance access reviews] ( ../governance/manage-user-access-with-access-reviews.md ) , you can ensure users have the appropriate access. Access review audit logs can tell you who initiated or ended an access review. These logs can also tell you if any access review settings were changed.
@@ -114,7 +153,7 @@ If you're utilizing [Application Proxy](../app-proxy/what-is-application-proxy.m
114
153
| DirectoryManagement| Enable Desktop Sso|
115
154
| DirectoryManagement| Enable Desktop Sso for a specific domain|
116
155
| DirectoryManagement| Enable application proxy|
117
- |DirectoryManagement|Enable passthrough authentication
156
+ | DirectoryManagement| Enable passthrough authentication|
118
157
| ResourceManagement| Add connector Group|
119
158
| ResourceManagement| Add a Connector to Connector Group|
120
159
| ResourceManagement| Add application SSL certificate|
@@ -199,6 +238,12 @@ The Azure AD MFA audit logs can help you track trends in suspicious activity or
199
238
| UserManagement| Suspicious activity reported|
200
239
| UserManagement| User registered security info|
201
240
241
+ ## B2B Auth
242
+
243
+ | Audit Category| Activity|
244
+ | ---| ---|
245
+ | UserManagement| Redeem extern user invite|
246
+
202
247
## B2C
203
248
204
249
This set of audit logs is related to [ B2C] ( ../../active-directory-b2c/overview.md ) . Due to the number of connected resources and potential external accounts, this service has a large set of categories and activities. Audit categories include ApplicationManagement, Authentication, Authorization, DirectoryManagement, IdentityProtection, KeyManagement, PolicyManagement, and ResourceManagement. Logs related to one-time passwords are found in the Other category.
@@ -310,7 +355,7 @@ This set of audit logs is related to [B2C](../../active-directory-b2c/overview.m
310
355
| Authorization| Get custom policy|
311
356
| Authorization| Get custom policy metadata|
312
357
| Authorization| Get customAuthenticationExtension|
313
- |Authorization|Get customAuthenticationExtensions
358
+ | Authorization| Get customAuthenticationExtensions|
314
359
| Authorization| Get identity provider|
315
360
| Authorization| Get identity provider types|
316
361
| Authorization| Get identity providers|
@@ -350,7 +395,7 @@ This set of audit logs is related to [B2C](../../active-directory-b2c/overview.m
350
395
| Authorization| Update a CIAM directory resource|
351
396
| Authorization| Update a Guest Usages resource|
352
397
| Authorization| Update age gating configuration|
353
- |Authorization|Update authentication flows policy
398
+ | Authorization| Update authentication flows policy|
354
399
| Authorization| Update authenticationEventListener|
355
400
| Authorization| Update authenticationEventsFlow|
356
401
| Authorization| Update authenticationEventsPolicy|
@@ -682,6 +727,25 @@ Logs captured in the Core Directory service cover a wide variety of scenarios. C
682
727
| Label| Add label|
683
728
| Label| Delete label|
684
729
| Label| Update label|
730
+ | MicrosoftSupportAccessManagement| Approval approved|
731
+ | MicrosoftSupportAccessManagement| Approval removed|
732
+ | MicrosoftSupportAccessManagement| Request approved|
733
+ | MicrosoftSupportAccessManagement| Request canceled|
734
+ | MicrosoftSupportAccessManagement| Request created|
735
+ | MicrosoftSupportAccessManagement| Request created|
736
+ | MicrosoftSupportAccessManagement| Request rejected|
737
+ | MultiTenantOrg| Create a MultiTenantOrg|
738
+ | MultiTenantOrg| Hard Delete MultiTenantOrg|
739
+ | MultiTenantOrg| Update a MultiTenantOrg|
740
+ | MultiTenantOrgIdentitySyncPolicyUpdate| Reset a multi tenant org identity sync policy template|
741
+ | MultiTenantOrgIdentitySyncPolicyUpdate| Update a multi tenant org identity sync policy template|
742
+ | MultiTenantOrgPartnerConfigurationTemplate| Reset a multi tenant org partner configuration template|
743
+ | MultiTenantOrgPartnerConfigurationTemplate| Update a multi tenant org partner configuration template|
744
+ | MultiTenantOrgTenant| Add MultiTenantOrg tenant|
745
+ | MultiTenantOrgTenant| Delete MultiTenantOrg tenant|
746
+ | MultiTenantOrgTenant| Hard Delete MultiTenantOrg tenant|
747
+ | MultiTenantOrgTenant| Tenant joining MultiTenantOrg tenant|
748
+ | MultiTenantOrgTenant| Update MultiTenantOrg tenant|
685
749
| PendingExternalUserProfile| Create PendingExternalUserProfile|
686
750
| PendingExternalUserProfile| Delete PendingExternalUserProfile|
687
751
| PendingExternalUserProfile| Hard Delete PendingExternalUserProfile|
@@ -717,6 +781,7 @@ Logs captured in the Core Directory service cover a wide variety of scenarios. C
717
781
| RoleManagement| Remove scoped member from role|
718
782
| RoleManagement| Update role|
719
783
| RoleManagement| Update role definition|
784
+ | SourceOfAuthorityPolicy| Add SOA policy|
720
785
| UserManagement| Add a deletion-marked app role assignment grant to group as part of link removal|
721
786
| UserManagement| Add app role assignment to group|
722
787
| UserManagement| Add user|
@@ -762,9 +827,11 @@ If you need to manage [Azure AD and Hybrid Azure AD joined devices](../devices/o
762
827
| UserManagement| Add FIDO2 security key|
763
828
| UserManagement| Add Windows Hello for Business credential|
764
829
| UserManagement| Add passwordless phone sign-in credential|
765
- | UserManagement| Delete FIDO2 security key|
830
+ | UserManagement| Add platform credential|
831
+ | UserManagement| Delete FIDO2 security key(s)|
766
832
| UserManagement| Delete Windows Hello for Business credential|
767
833
| UserManagement| Delete passwordless phone sign-in credential|
834
+ | UserManagement| Delete platform credential|
768
835
769
836
## Entitlement Management
770
837
@@ -830,6 +897,29 @@ If you're using Entitlement Management to streamline how you assign members of A
830
897
| EntitlementManagement| User requests to extend access package assignment|
831
898
| EntitlementManagement| User requests to remove access package assignment|
832
899
900
+ ## Global Secure Access (preview)
901
+
902
+ If you're using Microsoft Entra Internet Access or Microsoft Entra Private Access to acquire and secure network traffic to your corporate resources, these logs can help identify when changes were made to your network policies. These logs capture changes to traffic forwarding policies and remote networks, such as branch office locations. For more information, see [ What is Global Secure Access] ( ../../global-secure-access/overview-what-is-global-secure-access.md ) .
903
+
904
+ | Audit Category| Activity|
905
+ | ---| ---|
906
+ | ObjectManagement| Onboarding Process Started|
907
+ | ObjectManagement| Update Adaptive Access Policy|
908
+ | ObjectManagement| Update Enriched Audit Logs Settings|
909
+ | PolicyManagement| Create Branch|
910
+ | PolicyManagement| Create Filtering Policy|
911
+ | PolicyManagement| Create Filtering Policy Profile|
912
+ | PolicyManagement| Delete Filtering Policy|
913
+ | PolicyManagement| Delete Filtering Policy Profile|
914
+ | PolicyManagement| Create Forwarding Policy|
915
+ | PolicyManagement| Update Branch|
916
+ | PolicyManagement| Update Filtering Policy|
917
+ | PolicyManagement| Update Filtering Policy Profile|
918
+ | PolicyManagement| Update Filtering Profile|
919
+ | PolicyManagement| Update Forwarding Options Policy|
920
+ | PolicyManagement| Update Forwarding Policy|
921
+ | PolicyManagement| Update Forwarding Profile|
922
+
833
923
## Hybrid Authentication
834
924
835
925
| Audit Category| Activity|
@@ -841,6 +931,7 @@ If you're using Entitlement Management to streamline how you assign members of A
841
931
842
932
| Audit Category| Activity|
843
933
| ---| ---|
934
+ | IdentityProtection| Update IdentityProtectionPolicy|
844
935
| IdentityProtection| Update NotificationSettings|
845
936
| Other| ConfirmAccountCompromised|
846
937
| Other| ConfirmCompromised|
@@ -944,7 +1035,10 @@ Many of the activities captured in the PIM audit logs are similar, so take note
944
1035
| ApplicationManagement| Add member to role in PIM completed (timebound)|
945
1036
| ApplicationManagement| Add member to role in PIM requested (timebound)|
946
1037
| ApplicationManagement| Approve request - direct role assignment|
1038
+ | ApplicationManagement| PIM activation request expired|
1039
+ | ApplicationManagement| PIM policy removed|
947
1040
| ApplicationManagement| Remove member from role in PIM completed (timebound)|
1041
+ | ApplicationManagement| Remove request|
948
1042
| ApplicationManagement| Role definition created|
949
1043
| ApplicationManagement| Update role setting in PIM|
950
1044
| GroupManagement| Add eligible member to role in PIM canceled (renew)|
@@ -968,10 +1062,13 @@ Many of the activities captured in the PIM audit logs are similar, so take note
968
1062
| GroupManagement| Add member to role request approved (PIM activation)|
969
1063
| GroupManagement| Add member to role request denied (PIM activation)|
970
1064
| GroupManagement| Add member to role requested (PIM activation)|
1065
+ | GroupManagement| Cancel request|
1066
+ | GroupManagement| Cancel request for role removal|
971
1067
| GroupManagement| Cancel request for role update|
972
1068
| GroupManagement| Offboarded resource from PIM|
973
1069
| GroupManagement| Onboarded resource to PIM|
974
1070
| GroupManagement| PIM activation request expired|
1071
+ | GroupManagement| PIM policy removed|
975
1072
| GroupManagement| Process request|
976
1073
| GroupManagement| Process role removal request|
977
1074
| GroupManagement| Remove eligible member from role in PIM completed (permanent)|
@@ -987,6 +1084,12 @@ Many of the activities captured in the PIM audit logs are similar, so take note
987
1084
| GroupManagement| Remove member from role requested (PIM deactivate)|
988
1085
| GroupManagement| Remove permanent direct role assignment|
989
1086
| GroupManagement| Remove permanent eligible role assignment|
1087
+ | GroupManagement| Remove request|
1088
+ | GroupManagement| Resource updated|
1089
+ | GroupManagement| Restore eligible member from role in PIM comleted|
1090
+ | GroupManagement| Restore member from role|
1091
+ | GroupManagement| Restore member from role in PIM completed|
1092
+ | GroupManagement| Restore permanent direct role assignment|
990
1093
| GroupManagement| Update eligible member in PIM canceled (extend)|
991
1094
| GroupManagement| Update eligible member in PIM requested (extend)|
992
1095
| GroupManagement| Update member in PIM approved by admin (extend/renew)|
@@ -1017,13 +1120,15 @@ Many of the activities captured in the PIM audit logs are similar, so take note
1017
1120
| ResourceManagement| Add member to role request denied (PIM activation)|
1018
1121
| ResourceManagement| Add member to role requested (PIM activation)|
1019
1122
| ResourceManagement| Cancel request|
1123
+ | ResourceManagement| Cancel request for role removal|
1020
1124
| ResourceManagement| Cancel request for role update|
1021
1125
| ResourceManagement| Deactivate PIM alert|
1022
1126
| ResourceManagement| Disable PIM alert|
1023
1127
| ResourceManagement| Enable PIM alert|
1024
1128
| ResourceManagement| Offboarded resource from PIM|
1025
1129
| ResourceManagement| Onboarded resource from PIM|
1026
1130
| ResourceManagement| PIM activation request expired|
1131
+ | ResourceManagement| PIM policy removed|
1027
1132
| ResourceManagement| Process request|
1028
1133
| ResourceManagement| Process role removal request|
1029
1134
| ResourceManagement| Process role update request|
@@ -1040,7 +1145,14 @@ Many of the activities captured in the PIM audit logs are similar, so take note
1040
1145
| ResourceManagement| Remove member from role requested (PIM deactivate)|
1041
1146
| ResourceManagement| Remove permanent direct role assignment|
1042
1147
| ResourceManagement| Remove permanent eligible role assignment|
1148
+ | ResourceManagement| Remove request|
1043
1149
| ResourceManagement| Resolve PIM alert|
1150
+ | ResourceManagement| Resource updated|
1151
+ | ResourceManagement| Restore eligible member from role in PIM completed|
1152
+ | ResourceManagement| Restore member from role|
1153
+ | ResourceManagement| Restore member from role in PIM completed|
1154
+ | ResourceManagement| Restore permanent direct role assignment|
1155
+ | ResourceManagement| Restore permanent eligible role assignment|
1044
1156
| ResourceManagement| Tenant offboarded from PIM|
1045
1157
| ResourceManagement| Triggered PIM alert|
1046
1158
| ResourceManagement| Update eligible member in PIM canceled (extend)|
@@ -1072,14 +1184,15 @@ Many of the activities captured in the PIM audit logs are similar, so take note
1072
1184
| RoleManagement| Add member to role request approved (PIM activation)|
1073
1185
| RoleManagement| Add member to role request denied (PIM activation)|
1074
1186
| RoleManagement| Add member to role requested (PIM activation)|
1075
- | RoleManagement| Cancel request|
1187
+ | RoleManagement| Cancel request for role removal |
1076
1188
| RoleManagement| Cancel request for role update|
1077
1189
| RoleManagement| Deactivate PIM alert|
1078
1190
| RoleManagement| Disable PIM alert|
1079
1191
| RoleManagement| Enable PIM alert|
1080
1192
| RoleManagement| Offboarded resource from PIM|
1081
1193
| RoleManagement| Onboarded resource from PIM|
1082
1194
| RoleManagement| PIM activation request expired|
1195
+ | RoleManagement| PIM policy removed|
1083
1196
| RoleManagement| Process request|
1084
1197
| RoleManagement| Process role removal request|
1085
1198
| RoleManagement| Process role update request|
@@ -1097,7 +1210,13 @@ Many of the activities captured in the PIM audit logs are similar, so take note
1097
1210
| RoleManagement| Remove member from role requested (PIM deactivate)|
1098
1211
| RoleManagement| Remove permanent direct role assignment|
1099
1212
| RoleManagement| Remove permanent eligible role assignment|
1213
+ | RoleManagement| Remove request|
1100
1214
| RoleManagement| Resolve PIM alert|
1215
+ | RoleManagement| Restore eligible member from role in PIM completed|
1216
+ | RoleManagement| Restore member from role|
1217
+ | RoleManagement| Restore member from role in PIM completed|
1218
+ | RoleManagement| Restore permanent direct role assignment|
1219
+ | RoleManagement| Restore permanent eligible role assignment|
1101
1220
| RoleManagement| Tenant offboarded from PIM|
1102
1221
| RoleManagement| Triggered PIM alert|
1103
1222
| RoleManagement| Update PIM alert setting|
@@ -1115,17 +1234,68 @@ Users in your tenant can manage many aspects of their group memberships on their
1115
1234
1116
1235
| Audit Category| Activity|
1117
1236
| ---| ---|
1237
+ |GroupManagement|ApprovalNotification_Create
1238
+ |
1239
+ | GroupManagement| Autorenew group|
1240
+ | GroupManagement| Approval_Act|
1241
+ | GroupManagement| Approval_Get|
1242
+ | GroupManagement| Approval_GetAll|
1243
+ | GroupManagement| Approvals_ActOnApproval|
1244
+ | GroupManagement| Approvals_Post|
1118
1245
| GroupManagement| Approve a pending request to join a group|
1119
1246
| GroupManagement| Autorenew group|
1120
1247
| GroupManagement| Cancel a pending request to join a group|
1121
1248
| GroupManagement| Create lifecycle management policy|
1122
1249
| GroupManagement| Delete a pending request to join a group|
1123
1250
| GroupManagement| Delete lifecycle management policy|
1251
+ | GroupManagement| Device_Create|
1252
+ | GroupManagement| Device_Delete|
1253
+ | GroupManagement| Device_Get|
1254
+ | GroupManagement| Device_GetAll|
1255
+ | GroupManagement| Features_GetFeaturesAsync|
1256
+ | GroupManagement| Features_IsFeatureEnabledAsync|
1257
+ | GroupManagement| Features_UpdateFeaturesAsync|
1258
+ | GroupManagement| GroupLifecyclePolicies_Get|
1259
+ | GroupManagement| GroupLifecyclePolicies_addGroup|
1260
+ | GroupManagement| GroupLifecyclePolicies_removeGroup|
1261
+ | GroupManagement| Group_AddMember|
1262
+ | GroupManagement| Group_AddOwner|
1263
+ | GroupManagement| Group_BatchValidateDynamicMembership|
1264
+ | GroupManagement| Group_Create|
1265
+ | GroupManagement| Group_Delete|
1266
+ | GroupManagement| Group_Get|
1267
+ | GroupManagement| Group_GetAll|
1268
+ | GroupManagement| Group_GetDynamicGroupProperties|
1269
+ | GroupManagement| Group_GetDynamicMembershipDeviceAttributes|
1270
+ | GroupManagement| Group_GetDynamicMembershipOperators|
1271
+ | GroupManagement| Group_GetDynamicMembershipUserBaseAttributes|
1272
+ | GroupManagement| Group_GetExpiryNotificationDate|
1273
+ | GroupManagement| Group_GetMembers|
1274
+ | GroupManagement| Group_GetOwners|
1275
+ | GroupManagement| Group_RemoveMember|
1276
+ | GroupManagement| Group_RemoveOwner|
1277
+ | GroupManagement| Group_Restore|
1278
+ | GroupManagement| Group_Update|
1279
+ | GroupManagement| Group_ValidateDynamicMembership|
1280
+ | GroupManagement| GroupsODataV4_Get|
1281
+ | GroupManagement| GroupsODataV4_GetgroupLifecyclePolicies|
1282
+ | GroupManagement| GroupsODataV4_evaluateDynamicMembership|
1283
+ | GroupManagement| Groups_CreateLink|
1284
+ | GroupManagement| Groups_Get|
1285
+ | GroupManagement| LcmPolicy_Get|
1286
+ | GroupManagement| LcmPolicy_RenewGroup|
1124
1287
| GroupManagement| Reject a pending request to join a group|
1125
1288
| GroupManagement| Renew group|
1126
1289
| GroupManagement| Request to join a group|
1127
- | GroupManagement| Set dynamic group properties |
1290
+ | GroupManagement| Settings_GetSettingsAsync |
1128
1291
| GroupManagement| Update lifecycle management policy|
1292
+ | GroupManagement| User_Create|
1293
+ | GroupManagement| User_Delete|
1294
+ | GroupManagement| User_Get|
1295
+ | GroupManagement| User_GetAll|
1296
+ | GroupManagement| User_GetMemberOf|
1297
+ | GroupManagement| User_GetOwnedObjects|
1298
+ | Other| ApprovalNotification_Create|
1129
1299
| UserManagement| Updated ConvergedUXV2 feature value|
1130
1300
| UserManagement| Updated MyApps feature value|
1131
1301
| UserManagement| Update MyStaff feature value|
@@ -1148,8 +1318,6 @@ The Self-service password management logs provide insight into changes made to p
1148
1318
| UserManagement| Security info saved for self-service password reset|
1149
1319
| UserManagement| Self-service password reset flow activity progress|
1150
1320
| UserManagement| Unlock user account (self-service)|
1151
- | UserManagement| User completed security info registration for self-service password reset|
1152
- | UserManagement| User started security info registration for self-service password reset|
1153
1321
1154
1322
## Terms of use
1155
1323
@@ -1161,6 +1329,28 @@ The Self-service password management logs provide insight into changes made to p
1161
1329
| Policy| Delete Consent|
1162
1330
| Policy| Delete Terms Of Use|
1163
1331
| Policy| Edit Terms Of Use|
1332
+ | Policy| Publish Terms Of Use|
1333
+
1334
+ ## Verified ID
1335
+
1336
+ | Audit Category| Activity|
1337
+ | ---| ---|
1338
+ | ResourceManagement| Create authority|
1339
+ | ResourceManagement| Create contract|
1340
+ | ResourceManagement| Create issuance policy|
1341
+ | ResourceManagement| Delete issuance policy|
1342
+ | ResourceManagement| Process POST /authorities/: issuerId /didInfo/signingKeys/rotate request|
1343
+ | ResourceManagement| Process POST /authorities/: issuerId /didInfo/signingKeys/synchronizeWithDidDocument request|
1344
+ | ResourceManagement| Revoke credential|
1345
+ | ResourceManagement| Rotate signing key|
1346
+ | ResourceManagement| Tenant onboarding|
1347
+ | ResourceManagement| Tenant opt-out|
1348
+ | ResourceManagement| Update MyAccount settings|
1349
+ | ResourceManagement| Update authority|
1350
+ | ResourceManagement| Update contract|
1351
+ | ResourceManagement| Update issuance policy|
1352
+ | ResourceManagement| Update linked domains|
1353
+
1164
1354
1165
1355
## Next steps
1166
1356
0 commit comments