Skip to content

Commit be25ade

Browse files
Merge pull request #251519 from shlipsey3/reports-audit-activities-091423
reports-audit-activities-091423
2 parents 71508fc + 6017711 commit be25ade

File tree

1 file changed

+201
-11
lines changed

1 file changed

+201
-11
lines changed

articles/active-directory/reports-monitoring/reference-audit-activities.md

Lines changed: 201 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.topic: reference
1010
ms.workload: identity
1111
ms.subservice: report-monitor
12-
ms.date: 08/23/2023
12+
ms.date: 09/14/2023
1313
ms.author: sarahlipsey
1414
ms.reviewer: dhanyahk
1515

@@ -22,11 +22,50 @@ This article provides a comprehensive list of the audit categories and their rel
2222

2323
Audit log activities and categories change periodically. The tables are updated regularly, but may not be in sync with what is available in Azure AD. Provide us with feedback if you think there's a missing audit category or activity.
2424

25-
1. Sign in to the **Azure portal** using one of the [required roles](concept-audit-logs.md).
26-
1. Browse to **Azure Active Directory** > **Audit logs**.
25+
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Reports Reader](../roles/permissions-reference.md#reports-reader).
26+
1. Browse to **Identity** > **Monitoring & health** > **Audit logs**.
2727
1. Adjust the filters accordingly.
2828
1. Select a row from the resulting table to view the details.
2929

30+
## AAD Management UX
31+
32+
|Audit Category|Activity|
33+
|---|---|
34+
|AdministrativeUnit|Bulk add members to administrative unit - finished (bulk)|
35+
|AdministrativeUnit|Bulk remove members to administrative unit - finished (bulk)|
36+
|AdministrativeUnit|started (bulk)|
37+
|DeviceManagement|Bulk add authentication devices - finished (bulk)|
38+
|DeviceManagement|Download devices - finished (bulk)|
39+
|DeviceManagement|started (bulk)|
40+
|DirectoryManagement|Bulk download hardware tokens - finished (bulk)|
41+
|DirectoryManagement|Download registration and reset events - finished (bulk)|
42+
|DirectoryManagement|Download role assignments - finished (bulk)|
43+
|DirectoryManagement|Download service principals - finished (bulk)|
44+
|DirectoryManagement|Download user registration details - finished (bulk)|
45+
|DirectoryManagement|Download users - finished (bulk)|
46+
|DirectoryManagement|Export summary data - finished (bulk)|
47+
|DirectoryManagement|Export summary data new - finished (bulk)|
48+
|DirectoryManagement|started (bulk)|
49+
|GroupManagement|Bulk import group members - finished (bulk)|
50+
|GroupManagement|Bulk remove group members - finished (bulk)|
51+
|GroupManagement|Download group members - finished (bulk)|
52+
|GroupManagement|Download groups - finished (bulk)|
53+
|GroupManagement|started (bulk)|
54+
|Policy|Add blocked user|
55+
|Policy|Add bypass user|
56+
|Policy|Clear block on user|
57+
|Policy|Remove bypassed user|
58+
|Policy|Update Sign-In Risk Policy|
59+
|Policy|Update User RIsk and MFA Registration Policy|
60+
|UserManagement|Bulk create users - finished (bulk)|
61+
|UserManagement|Bulk delete users - finished (bulk)|
62+
|UserManagement|Bulk invite users - finished (bulk)|
63+
|UserManagement|Bulk restore deleted users - finished (bulk)|
64+
|UserManagement|Download users - finished (bulk)|
65+
|UserManagement|Bulk create users - finished (bulk)|
66+
|UserManagement|started (bulk)|
67+
68+
3069
## Access reviews
3170

3271
With [Azure AD Identity Governance access reviews](../governance/manage-user-access-with-access-reviews.md), you can ensure users have the appropriate access. Access review audit logs can tell you who initiated or ended an access review. These logs can also tell you if any access review settings were changed.
@@ -114,7 +153,7 @@ If you're utilizing [Application Proxy](../app-proxy/what-is-application-proxy.m
114153
|DirectoryManagement|Enable Desktop Sso|
115154
|DirectoryManagement|Enable Desktop Sso for a specific domain|
116155
|DirectoryManagement|Enable application proxy|
117-
|DirectoryManagement|Enable passthrough authentication
156+
|DirectoryManagement|Enable passthrough authentication|
118157
|ResourceManagement|Add connector Group|
119158
|ResourceManagement|Add a Connector to Connector Group|
120159
|ResourceManagement|Add application SSL certificate|
@@ -199,6 +238,12 @@ The Azure AD MFA audit logs can help you track trends in suspicious activity or
199238
|UserManagement|Suspicious activity reported|
200239
|UserManagement|User registered security info|
201240

241+
## B2B Auth
242+
243+
|Audit Category|Activity|
244+
|---|---|
245+
|UserManagement|Redeem extern user invite|
246+
202247
## B2C
203248

204249
This set of audit logs is related to [B2C](../../active-directory-b2c/overview.md). Due to the number of connected resources and potential external accounts, this service has a large set of categories and activities. Audit categories include ApplicationManagement, Authentication, Authorization, DirectoryManagement, IdentityProtection, KeyManagement, PolicyManagement, and ResourceManagement. Logs related to one-time passwords are found in the Other category.
@@ -310,7 +355,7 @@ This set of audit logs is related to [B2C](../../active-directory-b2c/overview.m
310355
|Authorization|Get custom policy|
311356
|Authorization|Get custom policy metadata|
312357
|Authorization|Get customAuthenticationExtension|
313-
|Authorization|Get customAuthenticationExtensions
358+
|Authorization|Get customAuthenticationExtensions|
314359
|Authorization|Get identity provider|
315360
|Authorization|Get identity provider types|
316361
|Authorization|Get identity providers|
@@ -350,7 +395,7 @@ This set of audit logs is related to [B2C](../../active-directory-b2c/overview.m
350395
|Authorization|Update a CIAM directory resource|
351396
|Authorization|Update a Guest Usages resource|
352397
|Authorization|Update age gating configuration|
353-
|Authorization|Update authentication flows policy
398+
|Authorization|Update authentication flows policy|
354399
|Authorization|Update authenticationEventListener|
355400
|Authorization|Update authenticationEventsFlow|
356401
|Authorization|Update authenticationEventsPolicy|
@@ -682,6 +727,25 @@ Logs captured in the Core Directory service cover a wide variety of scenarios. C
682727
|Label|Add label|
683728
|Label|Delete label|
684729
|Label|Update label|
730+
|MicrosoftSupportAccessManagement|Approval approved|
731+
|MicrosoftSupportAccessManagement|Approval removed|
732+
|MicrosoftSupportAccessManagement|Request approved|
733+
|MicrosoftSupportAccessManagement|Request canceled|
734+
|MicrosoftSupportAccessManagement|Request created|
735+
|MicrosoftSupportAccessManagement|Request created|
736+
|MicrosoftSupportAccessManagement|Request rejected|
737+
|MultiTenantOrg|Create a MultiTenantOrg|
738+
|MultiTenantOrg|Hard Delete MultiTenantOrg|
739+
|MultiTenantOrg|Update a MultiTenantOrg|
740+
|MultiTenantOrgIdentitySyncPolicyUpdate|Reset a multi tenant org identity sync policy template|
741+
|MultiTenantOrgIdentitySyncPolicyUpdate|Update a multi tenant org identity sync policy template|
742+
|MultiTenantOrgPartnerConfigurationTemplate|Reset a multi tenant org partner configuration template|
743+
|MultiTenantOrgPartnerConfigurationTemplate|Update a multi tenant org partner configuration template|
744+
|MultiTenantOrgTenant|Add MultiTenantOrg tenant|
745+
|MultiTenantOrgTenant|Delete MultiTenantOrg tenant|
746+
|MultiTenantOrgTenant|Hard Delete MultiTenantOrg tenant|
747+
|MultiTenantOrgTenant|Tenant joining MultiTenantOrg tenant|
748+
|MultiTenantOrgTenant|Update MultiTenantOrg tenant|
685749
|PendingExternalUserProfile|Create PendingExternalUserProfile|
686750
|PendingExternalUserProfile|Delete PendingExternalUserProfile|
687751
|PendingExternalUserProfile|Hard Delete PendingExternalUserProfile|
@@ -717,6 +781,7 @@ Logs captured in the Core Directory service cover a wide variety of scenarios. C
717781
|RoleManagement|Remove scoped member from role|
718782
|RoleManagement|Update role|
719783
|RoleManagement|Update role definition|
784+
|SourceOfAuthorityPolicy|Add SOA policy|
720785
|UserManagement|Add a deletion-marked app role assignment grant to group as part of link removal|
721786
|UserManagement|Add app role assignment to group|
722787
|UserManagement|Add user|
@@ -762,9 +827,11 @@ If you need to manage [Azure AD and Hybrid Azure AD joined devices](../devices/o
762827
|UserManagement|Add FIDO2 security key|
763828
|UserManagement|Add Windows Hello for Business credential|
764829
|UserManagement|Add passwordless phone sign-in credential|
765-
|UserManagement|Delete FIDO2 security key|
830+
|UserManagement|Add platform credential|
831+
|UserManagement|Delete FIDO2 security key(s)|
766832
|UserManagement|Delete Windows Hello for Business credential|
767833
|UserManagement|Delete passwordless phone sign-in credential|
834+
|UserManagement|Delete platform credential|
768835

769836
## Entitlement Management
770837

@@ -830,6 +897,29 @@ If you're using Entitlement Management to streamline how you assign members of A
830897
|EntitlementManagement|User requests to extend access package assignment|
831898
|EntitlementManagement|User requests to remove access package assignment|
832899

900+
## Global Secure Access (preview)
901+
902+
If you're using Microsoft Entra Internet Access or Microsoft Entra Private Access to acquire and secure network traffic to your corporate resources, these logs can help identify when changes were made to your network policies. These logs capture changes to traffic forwarding policies and remote networks, such as branch office locations. For more information, see [What is Global Secure Access](../../global-secure-access/overview-what-is-global-secure-access.md).
903+
904+
|Audit Category|Activity|
905+
|---|---|
906+
|ObjectManagement|Onboarding Process Started|
907+
|ObjectManagement|Update Adaptive Access Policy|
908+
|ObjectManagement|Update Enriched Audit Logs Settings|
909+
|PolicyManagement|Create Branch|
910+
|PolicyManagement|Create Filtering Policy|
911+
|PolicyManagement|Create Filtering Policy Profile|
912+
|PolicyManagement|Delete Filtering Policy|
913+
|PolicyManagement|Delete Filtering Policy Profile|
914+
|PolicyManagement|Create Forwarding Policy|
915+
|PolicyManagement|Update Branch|
916+
|PolicyManagement|Update Filtering Policy|
917+
|PolicyManagement|Update Filtering Policy Profile|
918+
|PolicyManagement|Update Filtering Profile|
919+
|PolicyManagement|Update Forwarding Options Policy|
920+
|PolicyManagement|Update Forwarding Policy|
921+
|PolicyManagement|Update Forwarding Profile|
922+
833923
## Hybrid Authentication
834924

835925
|Audit Category|Activity|
@@ -841,6 +931,7 @@ If you're using Entitlement Management to streamline how you assign members of A
841931

842932
|Audit Category|Activity|
843933
|---|---|
934+
|IdentityProtection|Update IdentityProtectionPolicy|
844935
|IdentityProtection|Update NotificationSettings|
845936
|Other|ConfirmAccountCompromised|
846937
|Other|ConfirmCompromised|
@@ -944,7 +1035,10 @@ Many of the activities captured in the PIM audit logs are similar, so take note
9441035
|ApplicationManagement|Add member to role in PIM completed (timebound)|
9451036
|ApplicationManagement|Add member to role in PIM requested (timebound)|
9461037
|ApplicationManagement|Approve request - direct role assignment|
1038+
|ApplicationManagement|PIM activation request expired|
1039+
|ApplicationManagement|PIM policy removed|
9471040
|ApplicationManagement|Remove member from role in PIM completed (timebound)|
1041+
|ApplicationManagement|Remove request|
9481042
|ApplicationManagement|Role definition created|
9491043
|ApplicationManagement|Update role setting in PIM|
9501044
|GroupManagement|Add eligible member to role in PIM canceled (renew)|
@@ -968,10 +1062,13 @@ Many of the activities captured in the PIM audit logs are similar, so take note
9681062
|GroupManagement|Add member to role request approved (PIM activation)|
9691063
|GroupManagement|Add member to role request denied (PIM activation)|
9701064
|GroupManagement|Add member to role requested (PIM activation)|
1065+
|GroupManagement|Cancel request|
1066+
|GroupManagement|Cancel request for role removal|
9711067
|GroupManagement|Cancel request for role update|
9721068
|GroupManagement|Offboarded resource from PIM|
9731069
|GroupManagement|Onboarded resource to PIM|
9741070
|GroupManagement|PIM activation request expired|
1071+
|GroupManagement|PIM policy removed|
9751072
|GroupManagement|Process request|
9761073
|GroupManagement|Process role removal request|
9771074
|GroupManagement|Remove eligible member from role in PIM completed (permanent)|
@@ -987,6 +1084,12 @@ Many of the activities captured in the PIM audit logs are similar, so take note
9871084
|GroupManagement|Remove member from role requested (PIM deactivate)|
9881085
|GroupManagement|Remove permanent direct role assignment|
9891086
|GroupManagement|Remove permanent eligible role assignment|
1087+
|GroupManagement|Remove request|
1088+
|GroupManagement|Resource updated|
1089+
|GroupManagement|Restore eligible member from role in PIM comleted|
1090+
|GroupManagement|Restore member from role|
1091+
|GroupManagement|Restore member from role in PIM completed|
1092+
|GroupManagement|Restore permanent direct role assignment|
9901093
|GroupManagement|Update eligible member in PIM canceled (extend)|
9911094
|GroupManagement|Update eligible member in PIM requested (extend)|
9921095
|GroupManagement|Update member in PIM approved by admin (extend/renew)|
@@ -1017,13 +1120,15 @@ Many of the activities captured in the PIM audit logs are similar, so take note
10171120
|ResourceManagement|Add member to role request denied (PIM activation)|
10181121
|ResourceManagement|Add member to role requested (PIM activation)|
10191122
|ResourceManagement|Cancel request|
1123+
|ResourceManagement|Cancel request for role removal|
10201124
|ResourceManagement|Cancel request for role update|
10211125
|ResourceManagement|Deactivate PIM alert|
10221126
|ResourceManagement|Disable PIM alert|
10231127
|ResourceManagement|Enable PIM alert|
10241128
|ResourceManagement|Offboarded resource from PIM|
10251129
|ResourceManagement|Onboarded resource from PIM|
10261130
|ResourceManagement|PIM activation request expired|
1131+
|ResourceManagement|PIM policy removed|
10271132
|ResourceManagement|Process request|
10281133
|ResourceManagement|Process role removal request|
10291134
|ResourceManagement|Process role update request|
@@ -1040,7 +1145,14 @@ Many of the activities captured in the PIM audit logs are similar, so take note
10401145
|ResourceManagement|Remove member from role requested (PIM deactivate)|
10411146
|ResourceManagement|Remove permanent direct role assignment|
10421147
|ResourceManagement|Remove permanent eligible role assignment|
1148+
|ResourceManagement|Remove request|
10431149
|ResourceManagement|Resolve PIM alert|
1150+
|ResourceManagement|Resource updated|
1151+
|ResourceManagement|Restore eligible member from role in PIM completed|
1152+
|ResourceManagement|Restore member from role|
1153+
|ResourceManagement|Restore member from role in PIM completed|
1154+
|ResourceManagement|Restore permanent direct role assignment|
1155+
|ResourceManagement|Restore permanent eligible role assignment|
10441156
|ResourceManagement|Tenant offboarded from PIM|
10451157
|ResourceManagement|Triggered PIM alert|
10461158
|ResourceManagement|Update eligible member in PIM canceled (extend)|
@@ -1072,14 +1184,15 @@ Many of the activities captured in the PIM audit logs are similar, so take note
10721184
|RoleManagement|Add member to role request approved (PIM activation)|
10731185
|RoleManagement|Add member to role request denied (PIM activation)|
10741186
|RoleManagement|Add member to role requested (PIM activation)|
1075-
|RoleManagement|Cancel request|
1187+
|RoleManagement|Cancel request for role removal|
10761188
|RoleManagement|Cancel request for role update|
10771189
|RoleManagement|Deactivate PIM alert|
10781190
|RoleManagement|Disable PIM alert|
10791191
|RoleManagement|Enable PIM alert|
10801192
|RoleManagement|Offboarded resource from PIM|
10811193
|RoleManagement|Onboarded resource from PIM|
10821194
|RoleManagement|PIM activation request expired|
1195+
|RoleManagement|PIM policy removed|
10831196
|RoleManagement|Process request|
10841197
|RoleManagement|Process role removal request|
10851198
|RoleManagement|Process role update request|
@@ -1097,7 +1210,13 @@ Many of the activities captured in the PIM audit logs are similar, so take note
10971210
|RoleManagement|Remove member from role requested (PIM deactivate)|
10981211
|RoleManagement|Remove permanent direct role assignment|
10991212
|RoleManagement|Remove permanent eligible role assignment|
1213+
|RoleManagement|Remove request|
11001214
|RoleManagement|Resolve PIM alert|
1215+
|RoleManagement|Restore eligible member from role in PIM completed|
1216+
|RoleManagement|Restore member from role|
1217+
|RoleManagement|Restore member from role in PIM completed|
1218+
|RoleManagement|Restore permanent direct role assignment|
1219+
|RoleManagement|Restore permanent eligible role assignment|
11011220
|RoleManagement|Tenant offboarded from PIM|
11021221
|RoleManagement|Triggered PIM alert|
11031222
|RoleManagement|Update PIM alert setting|
@@ -1115,17 +1234,68 @@ Users in your tenant can manage many aspects of their group memberships on their
11151234

11161235
|Audit Category|Activity|
11171236
|---|---|
1237+
|GroupManagement|ApprovalNotification_Create
1238+
|
1239+
|GroupManagement|Autorenew group|
1240+
|GroupManagement|Approval_Act|
1241+
|GroupManagement|Approval_Get|
1242+
|GroupManagement|Approval_GetAll|
1243+
|GroupManagement|Approvals_ActOnApproval|
1244+
|GroupManagement|Approvals_Post|
11181245
|GroupManagement|Approve a pending request to join a group|
11191246
|GroupManagement|Autorenew group|
11201247
|GroupManagement|Cancel a pending request to join a group|
11211248
|GroupManagement|Create lifecycle management policy|
11221249
|GroupManagement|Delete a pending request to join a group|
11231250
|GroupManagement|Delete lifecycle management policy|
1251+
|GroupManagement|Device_Create|
1252+
|GroupManagement|Device_Delete|
1253+
|GroupManagement|Device_Get|
1254+
|GroupManagement|Device_GetAll|
1255+
|GroupManagement|Features_GetFeaturesAsync|
1256+
|GroupManagement|Features_IsFeatureEnabledAsync|
1257+
|GroupManagement|Features_UpdateFeaturesAsync|
1258+
|GroupManagement|GroupLifecyclePolicies_Get|
1259+
|GroupManagement|GroupLifecyclePolicies_addGroup|
1260+
|GroupManagement|GroupLifecyclePolicies_removeGroup|
1261+
|GroupManagement|Group_AddMember|
1262+
|GroupManagement|Group_AddOwner|
1263+
|GroupManagement|Group_BatchValidateDynamicMembership|
1264+
|GroupManagement|Group_Create|
1265+
|GroupManagement|Group_Delete|
1266+
|GroupManagement|Group_Get|
1267+
|GroupManagement|Group_GetAll|
1268+
|GroupManagement|Group_GetDynamicGroupProperties|
1269+
|GroupManagement|Group_GetDynamicMembershipDeviceAttributes|
1270+
|GroupManagement|Group_GetDynamicMembershipOperators|
1271+
|GroupManagement|Group_GetDynamicMembershipUserBaseAttributes|
1272+
|GroupManagement|Group_GetExpiryNotificationDate|
1273+
|GroupManagement|Group_GetMembers|
1274+
|GroupManagement|Group_GetOwners|
1275+
|GroupManagement|Group_RemoveMember|
1276+
|GroupManagement|Group_RemoveOwner|
1277+
|GroupManagement|Group_Restore|
1278+
|GroupManagement|Group_Update|
1279+
|GroupManagement|Group_ValidateDynamicMembership|
1280+
|GroupManagement|GroupsODataV4_Get|
1281+
|GroupManagement|GroupsODataV4_GetgroupLifecyclePolicies|
1282+
|GroupManagement|GroupsODataV4_evaluateDynamicMembership|
1283+
|GroupManagement|Groups_CreateLink|
1284+
|GroupManagement|Groups_Get|
1285+
|GroupManagement|LcmPolicy_Get|
1286+
|GroupManagement|LcmPolicy_RenewGroup|
11241287
|GroupManagement|Reject a pending request to join a group|
11251288
|GroupManagement|Renew group|
11261289
|GroupManagement|Request to join a group|
1127-
|GroupManagement|Set dynamic group properties|
1290+
|GroupManagement|Settings_GetSettingsAsync|
11281291
|GroupManagement|Update lifecycle management policy|
1292+
|GroupManagement|User_Create|
1293+
|GroupManagement|User_Delete|
1294+
|GroupManagement|User_Get|
1295+
|GroupManagement|User_GetAll|
1296+
|GroupManagement|User_GetMemberOf|
1297+
|GroupManagement|User_GetOwnedObjects|
1298+
|Other|ApprovalNotification_Create|
11291299
|UserManagement|Updated ConvergedUXV2 feature value|
11301300
|UserManagement|Updated MyApps feature value|
11311301
|UserManagement|Update MyStaff feature value|
@@ -1148,8 +1318,6 @@ The Self-service password management logs provide insight into changes made to p
11481318
|UserManagement|Security info saved for self-service password reset|
11491319
|UserManagement|Self-service password reset flow activity progress|
11501320
|UserManagement|Unlock user account (self-service)|
1151-
|UserManagement|User completed security info registration for self-service password reset|
1152-
|UserManagement|User started security info registration for self-service password reset|
11531321

11541322
## Terms of use
11551323

@@ -1161,6 +1329,28 @@ The Self-service password management logs provide insight into changes made to p
11611329
|Policy|Delete Consent|
11621330
|Policy|Delete Terms Of Use|
11631331
|Policy|Edit Terms Of Use|
1332+
|Policy|Publish Terms Of Use|
1333+
1334+
## Verified ID
1335+
1336+
|Audit Category|Activity|
1337+
|---|---|
1338+
|ResourceManagement|Create authority|
1339+
|ResourceManagement|Create contract|
1340+
|ResourceManagement|Create issuance policy|
1341+
|ResourceManagement|Delete issuance policy|
1342+
|ResourceManagement|Process POST /authorities/:issuerId/didInfo/signingKeys/rotate request|
1343+
|ResourceManagement|Process POST /authorities/:issuerId/didInfo/signingKeys/synchronizeWithDidDocument request|
1344+
|ResourceManagement|Revoke credential|
1345+
|ResourceManagement|Rotate signing key|
1346+
|ResourceManagement|Tenant onboarding|
1347+
|ResourceManagement|Tenant opt-out|
1348+
|ResourceManagement|Update MyAccount settings|
1349+
|ResourceManagement|Update authority|
1350+
|ResourceManagement|Update contract|
1351+
|ResourceManagement|Update issuance policy|
1352+
|ResourceManagement|Update linked domains|
1353+
11641354

11651355
## Next steps
11661356

0 commit comments

Comments
 (0)