You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/8-knowledge-check.yml
+4-4Lines changed: 4 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -22,13 +22,13 @@ quiz:
22
22
choices:
23
23
- content: "Microsoft Entra audit logs provide a comparison of budgeted Azure usage compared to actual."
24
24
isCorrect: false
25
-
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You'll see things like adding or removing users, apps, groups, roles, and policies."
25
+
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You see things like adding or removing users, apps, groups, roles, and policies."
26
26
- content: "Microsoft Entra audit logs provide records of system activities for compliance reporting."
27
27
isCorrect: true
28
28
explanation: "Correct. An audit log has a default list view that shows data like the date and time of the occurrence. Additional information includes the service that logged the occurrence, and the category of the activity. Finally, the name of the activity (what), the status of the activity (success or failure), the target, and the initiator/actor (who) of an activity."
29
29
- content: "Microsoft Entra audit logs allow customer to monitor activity when provisioning new services within Azure."
30
30
isCorrect: false
31
-
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You'll see things like adding or removing users, apps, groups, roles, and policies."
31
+
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You see things like adding or removing users, apps, groups, roles, and policies."
32
32
- content: "Can Azure export logging data to third-party SIEM (security information and event management) tools?"
33
33
choices:
34
34
- content: "Yes, Azure supports exporting log data to several common third-party SIEM tools."
@@ -39,7 +39,7 @@ quiz:
39
39
explanation: "Incorrect. Azure Sentinel is a Microsoft first-party SIEM tool, but we do support using other tools, such as Splunk, IBM QRadar, and ArcSight."
40
40
- content: "Yes, Splunk is the third party SIEM Azure can export to."
41
41
isCorrect: false
42
-
explanation: "Incorrect. While Splunk is one of the third-party SIEM tools we can export data to, it is not the only one. We also support other third-party SIEM tools, such as IBM QRadar and ArcSight."
42
+
explanation: "Incorrect. While Splunk is one of the third-party SIEM tools we can export data to, it isn't the only one. We also support other third-party SIEM tools, such as IBM QRadar and ArcSight."
43
43
- content: "John wants to configure email notifications to be sent from Microsoft Entra Domain Services (AD DS) when issues are detected. In Azure, where would notifications be configured?"
44
44
choices:
45
45
- content: "Azure Microsoft Portal - Microsoft Entra ID - Monitoring - Notifications - Add email recipient."
@@ -50,4 +50,4 @@ quiz:
50
50
explanation: "Correct. The health of a Microsoft Entra Domain Services (MEDS) managed domain is monitored by the Azure platform. The health status page in the Azure Microsoft Portal shows any alerts for the managed domain. To make sure issues are responded to in a timely manner, email notifications can be configured to report on health alerts as soon as they're detected in the Microsoft Entra Domain Services managed domain."
51
51
- content: "Azure Microsoft Portal - Notification Hubs - Microsoft Entra ID - Add email recipient."
52
52
isCorrect: false
53
-
explanation: "Incorrect. Azure Notification Hubs are to provide push notification to any platform (iOS, Android, Windows, and so on.) to share breaking news, promotional content, or other Azure App information to users."
53
+
explanation: "Incorrect. Azure Notification Hubs are to provide push notification to any platform to share breaking news, promotional content, or other Azure App information to users."
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/includes/3-review-monitor-azure-active-directory-audit-logs.md
+12-12Lines changed: 12 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ You can customize the list view by clicking **Columns** in the toolbar.
15
15
16
16
:::image type="content" source="../media/columns.png" alt-text="Screenshot of the Audit columns, so you can pick the specific data you need to see in your report.":::
17
17
18
-
This enables you to display additional fields or remove fields that are already displayed.
18
+
Custom columns enables you to display other fields or remove fields that are already displayed.
19
19
20
20
:::image type="content" source="../media/column-select.png" alt-text="Screenshot of the Remove fields dialog. Set up the reports to show and review just the data you need.":::
21
21
@@ -45,7 +45,7 @@ The **Service** filter allows you to select from a drop-down list of the followi
45
45
- Account Provisioning
46
46
- Application Proxy
47
47
- Authentication Methods
48
-
- B2C
48
+
-Business to Customer (B2C)
49
49
- Conditional Access
50
50
- Core Directory
51
51
- Entitlement Management
@@ -54,7 +54,7 @@ The **Service** filter allows you to select from a drop-down list of the followi
54
54
- Invited Users
55
55
- MIM Service
56
56
- MyApps
57
-
- PIM
57
+
-Privileged Identity Management (PIM)
58
58
- Self-service Group Management
59
59
- Self-service Password Management
60
60
- Terms of Use
@@ -86,7 +86,7 @@ The **Activity** filter is based on the category and activity resource type sele
86
86
87
87
You can get the list of all Audit Activities using the Graph API: `https://graph.windows.net/<tenantdomain>/activities/auditActivityTypesV2?api-version=beta`
88
88
89
-
The **Status** filter allows you to filter based on the status of an audit operation. The status can be one of the following:
89
+
The **Status** filter allows you to filter based on the status of an audit operation. The status can be one of the following values:
90
90
91
91
- All
92
92
- Success
@@ -96,7 +96,7 @@ The **Target** filter allows you to search for a particular target by the starti
96
96
97
97
The **Initiated by** filter enables you to define what an actor's name or a universal principal name (UPN) starts with. The name and UPN are case-sensitive.
98
98
99
-
The **Date range** filter enables to you to define a timeframe for the returned data.Possible values are:
99
+
The **Date range** filter enables to you to define a timeframe for the returned `data.Possible` values are:
100
100
101
101
- 7 days
102
102
- 24 hours
@@ -110,7 +110,7 @@ You can also choose to download the filtered data, up to 250,000 records, by sel
110
110
111
111
## Audit logs shortcuts
112
112
113
-
In addition to **Microsoft Entra ID**, the Azure portal provides you with two additional entry points to audit data:
113
+
In addition to **Microsoft Entra ID**, the Azure portal provides you with two other entry points to audit data:
114
114
115
115
- Users and groups
116
116
- Enterprise applications
@@ -119,14 +119,14 @@ In addition to **Microsoft Entra ID**, the Azure portal provides you with two ad
119
119
120
120
With user and group-based audit reports, you can get answers to questions such as:
121
121
122
-
- What types of updates have been applied to users?
122
+
- What types of updates were applied to users?
123
123
- How many users were changed?
124
124
- How many passwords were changed?
125
125
- What has an administrator done in a directory?
126
-
- What are the groups that have been added?
126
+
- What are the groups that were added?
127
127
- Are there groups with membership changes?
128
128
- Have the owners of a group been changed?
129
-
- What licenses have been assigned to a group or a user?
129
+
- What licenses were assigned to a group or a user?
130
130
131
131
If you want to review only auditing data that is related to users, you can find a filtered view under **Audit logs** in the **Monitoring** section of the **Users** tab. This entry point has **UserManagement** as preselected category.
132
132
@@ -140,8 +140,8 @@ If you want to review only auditing data that is related to groups, you can find
140
140
141
141
With application-based audit reports, you can get answers to questions such as:
142
142
143
-
- What applications have been added or updated?
144
-
- What applications have been removed?
143
+
- What applications were added or updated?
144
+
- What applications were removed?
145
145
- Has a service principal for an application changed?
146
146
- Have the names of applications been changed?
147
147
- Who gave consent to an application?
@@ -152,4 +152,4 @@ If you want to review audit data related to your applications, you can find a fi
152
152
153
153
## Microsoft 365 activity logs
154
154
155
-
You can view Microsoft 365 activity logs from the Microsoft 365 admin center. Even though Microsoft 365 activity and Microsoft Entra activity logs share a lot of the directory resources, only the Microsoft 365 admin center provides a full view of the Microsoft 365 activity logs. You can also access the Microsoft 365 activity logs programmatically by using the Office 365 Management APIs.
155
+
You can view Microsoft 365 activity logs from the Microsoft 365 admin center. Even though Microsoft 365 activity and Microsoft Entra activity logs share numerous directory resources, only the Microsoft 365 admin center provides a full view of the Microsoft 365 activity logs. You can also access the Microsoft 365 activity logs programmatically by using the Office 365 Management APIs.
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/monitor-maintain-azure-active-directory/includes/6-analyze-azure-active-directory-workbooks-reporting.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,8 +9,10 @@ With the usage and insights report, you can get an application-centric view of y
9
9
To access the data from the usage and insights report, you need:
10
10
11
11
- A Microsoft Entra tenant.
12
-
- A Microsoft Entra ID premium (P1/P2) license to view the sign-in data.
13
-
- A user in the Security Administrator, Security Reader or Report Reader roles. In addition, any user (non-admins) can access their own sign-ins.
12
+
- A Microsoft Entra ID P1 or P2 license.
13
+
- A user in the Security Administrator, Security Reader or Report Reader roles.
14
+
15
+
In addition, any user (non-admins) can access their own sign-ins.
0 commit comments