A table in advanced hunting holding authentication events from Microsoft online services (via Defender for Cloud Apps) and on-premises AD (via Defender for Identity). It only covers sign-ins that have already happened.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains IdentityLogonEvents in context, with comparison tables and the common traps.
Terms in this definition
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- Online management group
Workloads that may talk directly to or from the internet, or that need no virtual network at all, go in this management group. It is a sibling of Corp and Local beneath Landing zones.
- Defender for Identity
Microsoft Defender service that detects attacks on identities, using sensors on on-premises Active Directory servers plus signals from Microsoft Entra ID and other identity providers; it does no access reviews or identity governance.
Related terms
- DeviceLogonEvents
Records sign-ins and similar authentication activity on endpoints for advanced hunting queries. Activity seen by Active Directory and cloud services lives in IdentityLogonEvents instead.