Record directory changes in Microsoft Entra, covering users, groups, applications, policies and other objects. Free tenants keep them for 7 days and P1 or P2 tenants for 30, and diagnostic settings can send them elsewhere for longer.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Audit logs in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
Related terms
- Auditing
Azure SQL capability that sends database audit logs to Log Analytics, Event Hubs or a storage account; that account is allowed to be in a different region.
- Azure SQL auditing
Azure SQL feature that sends audit logs to Event Hubs, a Log Analytics workspace (the only KQL-queryable option) or a storage account, which in the portal must be in the server's region and can't be premium FileStorage or legacy BlobStorage.
- Free data sources
Sentinel doesn't charge to ingest some data: Office 365 audit logs, Azure Activity, SentinelHealth and alerts from Microsoft Defender products are examples.
- Intune audit logs
A log, found under Tenant administration > Audit logs, of each create, update, delete, assignment and remote action carried out in Intune. It cannot be turned off and entries are retained for two years.
- Organization Configuration
You need this Microsoft Purview role in order to set up or modify retention policies for audit logs.
- pgAudit
Extension for PostgreSQL that produces audit logs in Azure Database for PostgreSQL. Unlike Defender plan alerts, any alerting on its output has to be set up separately.
- RequestResponse log
Log category on Azure OpenAI resources that records each request with its latency and status code. Administrative operations go to Audit logs, and detailed inference traces to Trace logs.
- View-Only Audit Logs
A role in Microsoft Purview, also found in Exchange Online, that allows searching and exporting the unified audit log (Fabric activities included) without permission to alter audit settings. Switching auditing on or off needs the Audit Logs role instead.