Skip to content

Commit d695c02

Browse files
authored
pull base content,head:MicrosoftDocs:main,into:wwlpublishsync
2 parents 836e11e + d56ebba commit d695c02

File tree

48 files changed

+278
-284
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

48 files changed

+278
-284
lines changed

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/1-introduction.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.introduction
33
title: Introduction
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Introduction
68
description: "Introduction"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/2-analyze-investigate-sign-logs-to-troubleshoot-access-issues.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.analyze-investigate-sign-logs-to-troubleshoot-access-issues
33
title: Analyze and investigate sign-in logs to troubleshoot access issues
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Analyze and investigate sign-in logs to troubleshoot access issues
68
description: "Analyze and investigate sign-in logs to troubleshoot access issues"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/3-review-monitor-azure-active-directory-audit-logs.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.review-monitory-azure-ad-audit-logs
33
title: Review and monitor Microsoft Entra audit logs
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Review and monitor Microsoft Entra audit logs
68
description: "Review and monitor Microsoft Entra audit logs"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/4-connect-data-from-azure-active-directory-to-azure-sentinel.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.connect-data-from-azure-ad-to-azure-sentinel
33
title: 'Exercise connect data from Microsoft Entra ID to Microsoft Sentinel '
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Exercise connect data from Microsoft Entra ID to Microsoft Sentinel
68
description: "Exercise connect data from Microsoft Entra ID to Microsoft Sentinel"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/5-export-logs-to-third-party-security-information.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.export-sign-audit-logs-to-third-party-siem
33
title: Export logs to third-party security information and event management system
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Export logs to third-party security information and event management system
68
description: "Export logs to third-party security information and event management system"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/6-analyze-azure-active-directory-workbooks-reporting.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.analyze-azure-ad-workbooks-reporting
33
title: Analyze Microsoft Entra workbooks and reporting
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Analyze Microsoft Entra workbooks and reporting
68
description: "Analyze Microsoft Entra workbooks and reporting"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/7-monitor-security-posture-identity-secure-score.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.monitor-security-posture-identity-secure-score
33
title: Monitor security posture with Identity Secure Score
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Monitor security posture with Identity Secure Score
68
description: "Monitor security posture with Identity Secure Score"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/8-knowledge-check.yml

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.knowledge-check
33
title: Module assessment
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Module assessment
68
description: "Knowledge check"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit
@@ -20,13 +22,13 @@ quiz:
2022
choices:
2123
- content: "Microsoft Entra audit logs provide a comparison of budgeted Azure usage compared to actual."
2224
isCorrect: false
23-
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You'll see things like adding or removing users, apps, groups, roles, and policies."
25+
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You see things like adding or removing users, apps, groups, roles, and policies."
2426
- content: "Microsoft Entra audit logs provide records of system activities for compliance reporting."
2527
isCorrect: true
2628
explanation: "Correct. An audit log has a default list view that shows data like the date and time of the occurrence. Additional information includes the service that logged the occurrence, and the category of the activity. Finally, the name of the activity (what), the status of the activity (success or failure), the target, and the initiator/actor (who) of an activity."
2729
- content: "Microsoft Entra audit logs allow customer to monitor activity when provisioning new services within Azure."
2830
isCorrect: false
29-
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You'll see things like adding or removing users, apps, groups, roles, and policies."
31+
explanation: "Incorrect. Audit logs provide traceability through logs for all changes made by various features within Microsoft Entra ID. Examples of audit logs include changes made to any resources within Microsoft Entra ID. You see things like adding or removing users, apps, groups, roles, and policies."
3032
- content: "Can Azure export logging data to third-party SIEM (security information and event management) tools?"
3133
choices:
3234
- content: "Yes, Azure supports exporting log data to several common third-party SIEM tools."
@@ -37,7 +39,7 @@ quiz:
3739
explanation: "Incorrect. Azure Sentinel is a Microsoft first-party SIEM tool, but we do support using other tools, such as Splunk, IBM QRadar, and ArcSight."
3840
- content: "Yes, Splunk is the third party SIEM Azure can export to."
3941
isCorrect: false
40-
explanation: "Incorrect. While Splunk is one of the third-party SIEM tools we can export data to, it is not the only one. We also support other third-party SIEM tools, such as IBM QRadar and ArcSight."
42+
explanation: "Incorrect. While Splunk is one of the third-party SIEM tools we can export data to, it isn't the only one. We also support other third-party SIEM tools, such as IBM QRadar and ArcSight."
4143
- content: "John wants to configure email notifications to be sent from Microsoft Entra Domain Services (AD DS) when issues are detected. In Azure, where would notifications be configured?"
4244
choices:
4345
- content: "Azure Microsoft Portal - Microsoft Entra ID - Monitoring - Notifications - Add email recipient."
@@ -48,4 +50,4 @@ quiz:
4850
explanation: "Correct. The health of a Microsoft Entra Domain Services (MEDS) managed domain is monitored by the Azure platform. The health status page in the Azure Microsoft Portal shows any alerts for the managed domain. To make sure issues are responded to in a timely manner, email notifications can be configured to report on health alerts as soon as they're detected in the Microsoft Entra Domain Services managed domain."
4951
- content: "Azure Microsoft Portal - Notification Hubs - Microsoft Entra ID - Add email recipient."
5052
isCorrect: false
51-
explanation: "Incorrect. Azure Notification Hubs are to provide push notification to any platform (iOS, Android, Windows, and so on.) to share breaking news, promotional content, or other Azure App information to users."
53+
explanation: "Incorrect. Azure Notification Hubs are to provide push notification to any platform to share breaking news, promotional content, or other Azure App information to users."

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/9-summary-resources.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
uid: learn.wwl.monitor-maintain-azure-active-directory.summary-resources
33
title: Summary and resources
44
metadata:
5+
adobe-target: true
6+
prefetch-feature-rollout: true
57
title: Summary and resources
68
description: "Summary and resources"
7-
ms.date: 12/23/2024
9+
ms.date: 04/22/2025
810
author: wwlpublish
911
ms.author: roberts
1012
ms.topic: unit

learn-pr/wwl-sci/monitor-maintain-azure-active-directory/includes/1-introduction.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,23 +2,23 @@ Microsoft Entra ID audit and diagnostic logs provide a rich view into how users
22

33
In this module, you will:
44

5-
- Learn about sign-in, audit, and diagnostic logs.
6-
- Learn about managing sign-in through a third-party security information and event management (SIEM) tool.
7-
- Learn about reporting.
8-
- Explore the identity secure score.
5+
- Learn about sign-in, audit, and diagnostic logs.
6+
- Learn about managing sign-in through a third-party security information and event management (SIEM) tool.
7+
- Learn about reporting.
8+
- Explore the identity secure score.
99

1010
## Learning objectives
1111

1212
By the end of this module you should be able to:
1313

14-
- Analyze and investigate sign-in logs to troubleshoot access issues.
15-
- Review and monitor Microsoft Entra audit logs.
16-
- Enable and integrate Microsoft Entra diagnostic logs with Log Analytics / Microsoft Sentinel.
17-
- Export sign-in and audit logs to a third-party SIEM tool.
18-
- Review Microsoft Entra activity by using Log Analytics / Microsoft Sentinel, excluding KQL use.
19-
- Analyze Microsoft Entra workbooks/reporting.
20-
- Monitor security posture with identity secure score.
21-
- Configure notifications.
14+
- Analyze and investigate sign-in logs to troubleshoot access issues.
15+
- Review and monitor Microsoft Entra audit logs.
16+
- Enable and integrate Microsoft Entra diagnostic logs with Log Analytics / Microsoft Sentinel.
17+
- Export sign-in and audit logs to a third-party SIEM tool.
18+
- Review Microsoft Entra activity by using Log Analytics / Microsoft Sentinel, excluding KQL use.
19+
- Analyze Microsoft Entra workbooks/reporting.
20+
- Monitor security posture with identity secure score.
21+
- Configure notifications.
2222

2323
## Prerequisites
2424

0 commit comments

Comments
 (0)