Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Reference for AuditLogs table in Azure Monitor Logs.
| Attribute | Value |
|---|---|
| Category | Azure Resources, Security |
| Basic Logs Eligible | ✗ No (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes (source) |
| Azure Monitor Tables Reference | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AADOperationType | string | Type of the operation. Possible values are Add Update Delete and Other. |
| AADTenantId | string | ID of the ADD tenant |
| ActivityDateTime | datetime | Date and time the activity was performed in UTC. |
| ActivityDisplayName | string | Activity name or the operation name. Examples include Create User and Add member to group. For full list see Azure AD activity list. |
| AdditionalDetails | dynamic | Indicates additional details on the activity. |
| Category | string | Currently Audit is the only supported value. |
| CorrelationId | string | Optional GUID that's passed by the client. Can help correlate client-side operations with server-side operations and is useful when tracking logs that span services. |
| DurationMs | long | Property is not used and can be ignored. |
| Id | string | GUID that uniquely identifies the activity. |
| Identity | string | Identity from the token that was presented when the request was made. The identity can be a user account system account or service principal. |
| InitiatedBy | dynamic | User or app initiated the activity. |
| Level | string | Message type. This is currently always Informational. |
| Location | string | Location of the datacenter. |
| LoggedByService | string | Service that initiated the activity (For example: Self-service Password Management Core Directory B2C Invited Users Microsoft Identity Manager Privileged Identity Management. |
| OperationName | string | Name of the operation. |
| OperationVersion | string | REST API version that's requested by the client. |
| Resource | string | |
| ResourceGroup | string | |
| ResourceId | string | |
| ResourceProvider | string | |
| Result | string | Result of the activity. Possible values are: success failure timeout unknownFutureValue. |
| ResultDescription | string | Additional description of the result. |
| ResultReason | string | Describes cause of failure or timeout results. |
| ResultSignature | string | Property is not used and can be ignored. |
| ResultType | string | Result of the operation. Possible values are Success and Failure. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| TargetResources | dynamic | Indicates information on which resource was changed due to the activity. Target Resource Type can be User Device Directory App Role Group Policy or Other. |
| TimeGenerated | datetime | Date and time the record was created. |
| Type | string | The name of the table |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Microsoft Entra ID |
In solution Business Email Compromise - Financial Fraud:
| Analytic Rule | Selection Criteria |
|---|---|
| Account Elevated to New Role | OperationName == "Add member to role completed (PIM activation)" |
| Authentication Method Changed for Privileged Account | ActivityDisplayName == "User registered security info"LoggedByService == "Authentication Methods" |
| Privileged Account Permissions Changed | OperationName has "Add eligible member" |
| User Added to Admin Role |
In solution Cloud Identity Threat Protection Essentials:
| Analytic Rule | Selection Criteria |
|---|---|
| Multi-Factor Authentication Disabled for a User | |
| New External User Granted Admin Role | AADOperationType in "Assign,AssignEligibleRole"ActivityDisplayName has_any "Add eligible member to role"OperationName in "Invite external user,Redeem external user invite"OperationName has "Invite external user"OperationName has "Redeem external user invite" |
In solution Microsoft Business Applications:
| Analytic Rule | Selection Criteria |
|---|---|
| Dataverse - Guest user exfiltration following Power Platform defense impairment | OperationName == "Update user" |
| Dataverse - New non-interactive identity granted access | OperationName == "Update application" |
| Power Apps - Bulk sharing of Power Apps to newly created guest users | OperationName == "Invite external user" |
| Power Platform - Account added to privileged Microsoft Entra roles | Identity != "MS-PIM"Identity != "MS-PIM-Fairfax" |
In solution Microsoft Entra ID:
| Analytic Rule | Selection Criteria |
|---|---|
| Account Created and Deleted in Short Timeframe | OperationName in "Add user,Delete user" |
| Account created or deleted by non-approved user | OperationName in "Add user,Delete user" |
| Admin promotion after Role Management Application Permission Grant | AADOperationType == "Assign"LoggedByService == "Core Directory"OperationName == "Add app role assignment to service principal" |
| Authentication Methods Changed for Privileged Account | |
| Azure RBAC (Elevate Access) | ActivityDisplayName == "User has elevated their access to User Access Administrator for their Azure Resources" |
| Bulk Changes to Privileged Account Permissions | |
| Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed) | OperationName == "Update conditional access policy" |
| Conditional Access - A Conditional Access app exclusion has changed | OperationName == "Update conditional access policy" |
| Conditional Access - A Conditional Access policy was deleted | OperationName == "Delete conditional access policy" |
| Conditional Access - A Conditional Access policy was disabled | OperationName == "Update conditional access policy" |
| Conditional Access - A Conditional Access policy was put into report-only mode | OperationName == "Update conditional access policy" |
| Conditional Access - A Conditional Access policy was updated | OperationName == "Update conditional access policy" |
| Conditional Access - A Conditional Access user/group/role exclusion has changed | OperationName == "Update conditional access policy" |
| Conditional Access - A new Conditional Access policy was created | OperationName == "Add conditional access policy" |
| Conditional Access - Dynamic Group Exclusion Changes | OperationName == "Update group" |
| Credential added after admin consented to Application | OperationName in "Add service principal credentials,Consent to application" |
| Cross-tenant Access Settings Organization Added | OperationName has "Add a partner to cross-tenant access setting" |
| Cross-tenant Access Settings Organization Deleted | OperationName has "Delete partner specific cross-tenant access setting" |
| Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed | OperationName has "Update a partner cross-tenant access setting" |
| Cross-tenant Access Settings Organization Inbound Direct Settings Changed | OperationName has "Update a partner cross-tenant access setting" |
| Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed | OperationName has "Update a partner cross-tenant access setting" |
| Cross-tenant Access Settings Organization Outbound Direct Settings Changed | OperationName has "Update a partner cross-tenant access setting" |
| External guest invitation followed by Microsoft Entra ID PowerShell signin | OperationName == "Invite external user" |
| First access credential added to Application or Service Principal where no credential was present | OperationName has "Certificatessecrets management" |
| Guest accounts added in Entra ID Groups other than the ones specified | InitiatedBy has_any "CUSTOM DOMAIN NAME#"OperationName in "Add member to group,Add owner to group" |
| Mail.Read Permissions Granted to Application | ActivityDisplayName has "Consent to application"ActivityDisplayName has_any "Add delegated permission grant" |
| Microsoft Entra ID Role Management Permission Grant | LoggedByService == "Core Directory"OperationName in "Add app role assignment to service principal,Add delegated permission grant" |
| Modified domain federation trust settings | OperationName in "Set domain authentication,Set federation settings on domain" |
| Multiple admin membership removals from newly created admin. | |
| NRT Authentication Methods Changed for VIP Users | |
| NRT First access credential added to Application or Service Principal where no credential was present | OperationName has_any "Add service principal,Certificatessecrets management" |
| NRT Modified domain federation trust settings | OperationName in "Set domain authentication,Set federation settings on domain" |
| NRT New access credential added to Application or Service Principal | OperationName has_any "Add service principal,Certificatessecrets management" |
| NRT PIM Elevation Request Rejected | ActivityDisplayName == "Add member to role request denied (PIM activation)"ResultReason != "RoleAssignmentExists" |
| NRT Privileged Role Assigned Outside PIM | Identity != "MS-PIM"Identity != "MS-PIM-Fairfax"LoggedByService == "Core Directory"OperationName == "Add member to role"OperationName has "Add member to role outside of PIM" |
| NRT User added to Microsoft Entra ID Privileged Groups | |
| New User Assigned to Privileged Role | |
| New access credential added to Application or Service Principal | OperationName has_any "Add service principal,Certificatessecrets management" |
| New onmicrosoft domain added to tenant | AADOperationType == "Add"OperationName in "Add unverified domain,Add verified domain" |
| PIM Elevation Request Rejected | |
| Possible SignIn from Azure Backdoor | OperationName == "Add unverified domain" |
| Privileged Role Assigned Outside PIM | Identity != "MS-PIM"Identity != "MS-PIM-Fairfax"LoggedByService == "Core Directory"OperationName == "Add member to role"OperationName has "Add member to role outside of PIM" |
| Rare application consent | OperationName has "Consent to application" |
| Suspicious Entra ID Joined Device Update | OperationName == "Update device" |
| Suspicious Service Principal creation activity | OperationName == "Remove service principal"OperationName has_all "Update application" |
| Suspicious Sign In Followed by MFA Modification | |
| Suspicious application consent for offline access | LoggedByService == "Core Directory"OperationName in "Add OAuth2PermissionGrant,Add delegated permission grant,Add service principal,Consent to application"TargetResources has "offline" |
| Suspicious application consent similar to O365 Attack Toolkit | LoggedByService == "Core Directory"OperationName in "Add OAuth2PermissionGrant,Add delegated permission grant,Add service principal,Consent to application" |
| Suspicious application consent similar to PwnAuth | LoggedByService == "Core Directory"OperationName in "Add OAuth2PermissionGrant,Add delegated permission grant,Add service principal,Consent to application"TargetResources has "offline" |
| User Assigned New Privileged Role | AADOperationType in "Assign,AssignEligibleRole,CreateRequestGrantedRole,CreateRequestPermanentEligibleRole,CreateRequestPermanentGrantedRole"ActivityDisplayName has_any "Add eligible member to role" |
| User added to Microsoft Entra ID Privileged Groups | |
| full_access_as_app Granted To Application | LoggedByService == "Core Directory"OperationName == "Consent to application"TargetResources has "full_access_as_app" |
In solution SecurityThreatEssentialSolution:
| Analytic Rule | Selection Criteria |
|---|---|
| Threat Essentials - Multiple admin membership removals from newly created admin. | |
| Threat Essentials - NRT User added to Microsoft Entra ID Privileged Groups | LoggedByService == "Core Directory" |
| Threat Essentials - User Assigned Privileged Role | AADOperationType in "Assign,AssignEligibleRole"ActivityDisplayName has_any "Add eligible member to role" |
In solution Threat Intelligence:
| Analytic Rule | Selection Criteria |
|---|---|
| TI Map URL Entity to AuditLogs |
In solution Threat Intelligence (NEW):
| Analytic Rule | Selection Criteria |
|---|---|
| TI Map URL Entity to AuditLogs |
In solution eDCRule:
| Analytic Rule | Selection Criteria |
|---|---|
| [Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions | AADOperationType == "Assign"LoggedByService == "Core Directory"OperationName == "Add app role assignment to service principal" |
| [Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles | LoggedByService == "Core Directory"OperationName in "Add app role assignment to service principal,Add delegated permission grant" |
| [Entra ID] Authentication Method Changed for Privileged Account | |
| [Entra ID] Domain Federation Trust Settings Modified | OperationName in "Set domain authentication,Set federation settings on domain" |
| [Entra ID] Mass Privileged Role Change Activity Detected | ActivityDisplayName has_any "Add eligible member to role" |
| [Entra ID] Privilege Elevation Request Denied | ActivityDisplayName == "Add member to role request denied (PIM activation)"ResultReason != "RoleAssignmentExists" |
| [Entra ID] Privileged Role Assigned to User | AADOperationType in "Assign,AssignEligibleRole,CreateRequestGrantedRole,CreateRequestPermanentEligibleRole,CreateRequestPermanentGrantedRole"ActivityDisplayName has_any "Add eligible member to role" |
| [Entra ID] Privileged Role Assigned to a New User |
Standalone Content:
| Analytic Rule | Selection Criteria |
|---|---|
| Account created from non-approved sources | OperationName == "Add User" |
| Addition of a Temporary Access Pass to a Privileged Account | OperationName == "Admin registered security info"ResultReason == "Admin registered temporary access pass method for user" |
| Application ID URI Changed | OperationName has_any "Update Application,Update Service principal"TargetResources has "AppIdentifierUri" |
| Application Redirect URL Update | OperationName == "Update Application"TargetResources has "AppAddress" |
| Changes to Application Logout URL | OperationName has_any "Update Application,Update Service principal" |
| Changes to Application Ownership | OperationName == "Add owner to application" |
| Changes to PIM Settings | OperationName == "Update role setting in PIM" |
| Conditional Access Policy Modified by New User | OperationName has "conditional access policy" |
| Detect PIM Alert Disabling activity | ActivityDisplayName has "Disable PIM Alert"LoggedByService == "PIM" |
| Detecting Impossible travel with mailbox permission tampering & Privilege Escalation attempt | AADOperationType == "CreateRequestEligibleRole"ActivityDisplayName == "Add eligible member to role in PIM requested (timebound)"TargetResources has_any "-PRIV" |
| End-user consent stopped due to risk-based consent | OperationName has "Consent to application" |
| Guest Users Invited to Tenant by New Inviters | OperationName == "Invite external user" |
| Multiple Password Reset by user | |
| Service Principal Assigned App Role With Sensitive Access | OperationName == "Add app role assignment to service principal" |
| Service Principal Assigned Privileged Role | OperationName has_all "member to role" |
| Suspicious Login from deleted guest account | OperationName == "Delete user" |
| Suspicious linking of existing user to external User | OperationName == "Update user" |
| Suspicious modification of Global Administrator user properties | OperationName == "Update user" |
| URL Added to Application from Unknown Domain | OperationName == "Update Application" |
| User Account Created Using Incorrect Naming Format | OperationName == "Add user" |
| User State changed from Guest to Member | OperationName == "Update user" |
| User account created without expected attributes defined | OperationName == "Add user" |
In solution Business Email Compromise - Financial Fraud:
| Hunting Query | Selection Criteria |
|---|---|
| Risky Sign-in with new MFA method | |
| User detection added to privilege groups based in Watchlist | ActivityDisplayName has_any "Add eligible member to role"LoggedByService in "Core Directory,PIM" |
In solution Cloud Identity Threat Protection Essentials:
| Hunting Query | Selection Criteria |
|---|---|
| Application Granted EWS Permissions | OperationName has "Add app role assignment to service principal" |
| Interactive STS refresh token modifications | OperationName has "StsRefreshTokenValidFrom" |
| User Granted Access and Grants Access to Other Users |
In solution Hybrid Attack - Cloud & Identity:
| Hunting Query | Selection Criteria |
|---|---|
| Federated Identity Provider Added to Tenant | OperationName in "Set domain authentication,Set federation settings on domain" |
| MFA Method Added on Risky Account | OperationName in "Admin deleted security info,Admin registered security info,Admin updated security info,User changed default security info,User deleted security info,User registered security info,User updated security info" |
| Secret Added to Dormant Service Principal | OperationName == "Add service principal credentials" |
| Service principal credential change followed by novel SP sign-in | |
| Suspicious OAuth App Consent Granting Sensitive Permissions | OperationName in "Add app role assignment to service principal,Add delegated permission grant,Consent to application" |
| Suspicious sign-in followed by auth method or role change |
In solution Microsoft Business Applications:
| Hunting Query | Selection Criteria |
|---|---|
| Power Apps - Anomalous bulk sharing of Power App to newly created guest users |
In solution UEBA Essentials:
| Hunting Query | Selection Criteria |
|---|---|
| Anomalous Entra High-Privilege Role Modification | OperationName == "Update user" |
| Anomalous High-Privileged Role Assignment | OperationName == "Add member to role" |
Standalone Content:
GitHub Only:
| Hunting Query | Selection Criteria |
|---|---|
| Account Added to Privileged PIM Group | AADOperationType == "CreateRequestEligibleRole"ActivityDisplayName == "Add eligible member to role in PIM requested (timebound)"TargetResources has_any "-PRIV" |
| Account MFA Modifications | OperationName in "Admin deleted security info,Admin registered security info,Admin updated security info,User changed default security info,User deleted security info,User registered all required security info,User registered security info,User started security info registration" |
| Approved Access Packages Details | OperationName in "Approve access package assignment request,Request approved,User requests access package assignment" |
| BitLocker Key Retrieval | OperationName == "Read BitLocker key" |
| Critical user management operations followed by disabling of System Restore from admin account | |
| Dormant User Update MFA and Logs In | OperationName == "User registered security info" |
| Dormant User Update MFA and Logs In - UEBA | OperationName == "User registered security info"ResultType == "0" |
| High Risk Sign In Around Authentication Method Added or Device Registration | OperationName in "Register device,User registered security info" |
| Invited Guest User but not redeemed Invite for longer period. | OperationName in "Invite external user,Redeem external user invite" |
| Multiple Entra ID Admins Removed | Identity !has "MS-PIM"OperationName in "Remove eligible member from role,Remove member from role" |
| OAuth Application Required Resource Access Update | ActivityDisplayName has_any "Update application" |
| Privileged Account Password Changes | OperationName has_any "password,security info" |
| Risky Sign-in with Device Registration | OperationName == "Add registered owner to device" |
| SQL Alert Correlation with CommonSecurityLogs and AuditLogs | LoggedByService == "Core Directory" |
| Storage Account Key Enumeration | LoggedByService == "Core Directory" |
| Storage Alerts Correlation with CommonSecurityLogs & AuditLogs | LoggedByService == "Core Directory" |
| Successful Sign-In From Non-Compliant Device with bulk download activity | OperationName has_any "Download group members,Download groups,Download user registeration details,Download users" |
| Unfamiliar Signin Correlation with AzurePortal Signin Attempts and AuditLogs |
In solution AzureSecurityBenchmark:
| Workbook | Selection Criteria |
|---|---|
| AzureSecurityBenchmark |
In solution ContinuousDiagnostics&Mitigation:
| Workbook | Selection Criteria |
|---|---|
| ContinuousDiagnostics&Mitigation |
In solution CybersecurityMaturityModelCertification(CMMC)2.0:
| Workbook | Selection Criteria |
|---|---|
| CybersecurityMaturityModelCertification_CMMCV2 |
In solution DPDP Compliance:
| Workbook | Selection Criteria |
|---|---|
| DPDPCompliance |
In solution GDPR Compliance & Data Security:
| Workbook | Selection Criteria |
|---|---|
| GDPRComplianceAndDataSecurity |
In solution Hybrid Attack - Cloud & Identity:
| Workbook | Selection Criteria |
|---|---|
| HybridAttack-Cloud&Identity |
In solution Lumen Defender Threat Feed:
| Workbook | Selection Criteria |
|---|---|
| Lumen-Threat-Feed-Overview |
In solution MaturityModelForEventLogManagementM2131:
| Workbook | Selection Criteria |
|---|---|
| MaturityModelForEventLogManagement_M2131 |
In solution Microsoft Entra ID:
| Workbook | Selection Criteria |
|---|---|
| AzureActiveDirectoryAuditLogs | SourceSystem == "Azure AD" |
| ConditionalAccessSISM |
In solution MicrosoftPurviewInsiderRiskManagement:
| Workbook | Selection Criteria |
|---|---|
| InsiderRiskManagement |
In solution NISTSP80053:
| Workbook | Selection Criteria |
|---|---|
| NISTSP80053 |
In solution SOC Handbook: AdditionalDetails contains "fraud"
| Workbook |
|---|
| InvestigationInsights |
In solution SOX IT Compliance:
| Workbook | Selection Criteria |
|---|---|
| SOXITCompliance |
In solution ZeroTrust(TIC3.0):
| Workbook | Selection Criteria |
|---|---|
| ZeroTrustTIC3 |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| AzureActiveDirectoryAuditLogs | SourceSystem == "Azure AD" |
| AzureLogCoverage | |
| AzureThreatResearchMatrixWorkbook | ActivityDisplayName == "User has elevated their access to User Access Administrator for their Azure Resources"TargetResources has_any "Guest" |
| ConditionalAccessTrendsandChanges | OperationName in "Add conditional access policy,Add member to group,Delete conditional access policy,Update conditional access policy"OperationName contains "group" |
| DoDZeroTrustWorkbook | AdditionalDetails != "MFA requirement satisfied by claim in the token"AdditionalDetails != "MFA requirement skipped due to remembered device" |
| InvestigationInsights | AdditionalDetails contains "fraud" |
| MicrosoftSecurityLicenseUtilization | |
| MicrosoftSentinelDeploymentandMigrationTracker | |
| SentinelWorkspaceReconTools | |
| SolarWindsPostCompromiseHunting | ActivityDisplayName in "Add delegated permission grant,Consent to application" |
| User_Analytics_Workbook | ActivityDisplayName == "Add member to role" |
| ZeroTrustStrategyWorkbook | AdditionalDetails != "MFA requirement satisfied by claim in the token"AdditionalDetails != "MFA requirement skipped due to remembered device" |
This table collects data from the following Azure resource types:
microsoft.azureadgraph/tenantsmicrosoft.graph/tenantsReferences by type: 0 connectors, 135 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
OperationName == "Update conditional access policy" |
- | 7 | - | - | 7 |
OperationName == "Update user" |
- | 6 | - | - | 6 |
OperationName in "Set domain authentication,Set federation settings on domain" |
- | 4 | - | - | 4 |
OperationName has "Update a partner cross-tenant access setting" |
- | 4 | - | - | 4 |
LoggedByService == "Core Directory" |
- | 4 | - | - | 4 |
OperationName == "Invite external user" |
- | 3 | - | - | 3 |
OperationName has_any "Add service principal,Certificatessecrets management" |
- | 3 | - | - | 3 |
OperationName == "Consent to application" |
- | 3 | - | - | 3 |
AADOperationType == "Assign"LoggedByService == "Core Directory"OperationName == "Add app role assignment to service principal" |
- | 2 | - | - | 2 |
LoggedByService == "Core Directory"OperationName in "Add app role assignment to service principal,Add delegated permission grant" |
- | 2 | - | - | 2 |
ActivityDisplayName == "Add member to role request denied (PIM activation)"ResultReason != "RoleAssignmentExists" |
- | 2 | - | - | 2 |
AADOperationType in "Assign,AssignEligibleRole,CreateRequestGrantedRole,CreateRequestPermanentEligibleRole,CreateRequestPermanentGrantedRole"ActivityDisplayName has_any "Add eligible member to role" |
- | 2 | - | - | 2 |
OperationName == "Update application" |
- | 2 | - | - | 2 |
OperationName in "Add user,Delete user" |
- | 2 | - | - | 2 |
LoggedByService == "Core Directory"OperationName in "Add OAuth2PermissionGrant,Add delegated permission grant,Add service principal,Consent to application"TargetResources has "offline" |
- | 2 | - | - | 2 |
Identity != "MS-PIM"Identity != "MS-PIM-Fairfax"LoggedByService == "Core Directory"OperationName == "Add member to role"OperationName has "Add member to role outside of PIM" |
- | 2 | - | - | 2 |
OperationName has "Consent to application" |
- | 2 | - | - | 2 |
OperationName == "Add app role assignment to service principal" |
- | 2 | - | - | 2 |
OperationName == "Add user" |
- | 2 | - | - | 2 |
AADOperationType == "CreateRequestEligibleRole"ActivityDisplayName == "Add eligible member to role in PIM requested (timebound)"TargetResources has_any "-PRIV" |
- | 2 | - | - | 2 |
OperationName == "Add service principal credentials" |
- | 2 | - | - | 2 |
OperationName == "Add member to role." |
- | 2 | - | - | 2 |
OperationName == "Add member to role completed (PIM activation)" |
- | 1 | - | - | 1 |
ActivityDisplayName == "User registered security info"LoggedByService == "Authentication Methods" |
- | 1 | - | - | 1 |
OperationName has "Add eligible member" |
- | 1 | - | - | 1 |
AADOperationType in "Assign,AssignEligibleRole"ActivityDisplayName has_any "Add eligible member to role"OperationName in "Invite external user,Redeem external user invite"OperationName has "Invite external user"OperationName has "Redeem external user invite" |
- | 1 | - | - | 1 |
ActivityDisplayName has_any "Add eligible member to role" |
- | 1 | - | - | 1 |
Identity != "MS-PIM"Identity != "MS-PIM-Fairfax" |
- | 1 | - | - | 1 |
ActivityDisplayName == "User has elevated their access to User Access Administrator for their Azure Resources" |
- | 1 | - | - | 1 |
OperationName == "Delete conditional access policy" |
- | 1 | - | - | 1 |
OperationName == "Add conditional access policy" |
- | 1 | - | - | 1 |
OperationName == "Update group" |
- | 1 | - | - | 1 |
OperationName in "Add service principal credentials,Consent to application" |
- | 1 | - | - | 1 |
OperationName has "Add a partner to cross-tenant access setting" |
- | 1 | - | - | 1 |
OperationName has "Delete partner specific cross-tenant access setting" |
- | 1 | - | - | 1 |
LoggedByService == "Core Directory"OperationName == "Consent to application"TargetResources has "full_access_as_app" |
- | 1 | - | - | 1 |
OperationName has "Certificatessecrets management" |
- | 1 | - | - | 1 |
InitiatedBy has_any "CUSTOM DOMAIN NAME#"OperationName in "Add member to group,Add owner to group" |
- | 1 | - | - | 1 |
ActivityDisplayName has "Consent to application"ActivityDisplayName has_any "Add delegated permission grant" |
- | 1 | - | - | 1 |
LoggedByService == "Core Directory"OperationName in "Add OAuth2PermissionGrant,Add delegated permission grant,Add service principal,Consent to application" |
- | 1 | - | - | 1 |
AADOperationType == "Add"OperationName in "Add unverified domain,Add verified domain" |
- | 1 | - | - | 1 |
OperationName == "Add unverified domain" |
- | 1 | - | - | 1 |
OperationName == "Update device" |
- | 1 | - | - | 1 |
OperationName == "Remove service principal"OperationName has_all "Update application" |
- | 1 | - | - | 1 |
AADOperationType in "Assign,AssignEligibleRole"ActivityDisplayName has_any "Add eligible member to role" |
- | 1 | - | - | 1 |
OperationName == "Admin registered security info"ResultReason == "Admin registered temporary access pass method for user" |
- | 1 | - | - | 1 |
OperationName has_any "Update Application,Update Service principal"TargetResources has "AppIdentifierUri" |
- | 1 | - | - | 1 |
OperationName == "Update Application"TargetResources has "AppAddress" |
- | 1 | - | - | 1 |
OperationName has_any "Update Application,Update Service principal" |
- | 1 | - | - | 1 |
OperationName == "Add owner to application" |
- | 1 | - | - | 1 |
OperationName == "Update role setting in PIM" |
- | 1 | - | - | 1 |
OperationName has "conditional access policy" |
- | 1 | - | - | 1 |
OperationName has_all "member to role" |
- | 1 | - | - | 1 |
OperationName == "Update Application" |
- | 1 | - | - | 1 |
OperationName == "Add User" |
- | 1 | - | - | 1 |
OperationName == "Delete user" |
- | 1 | - | - | 1 |
ActivityDisplayName has "Disable PIM Alert"LoggedByService == "PIM" |
- | 1 | - | - | 1 |
ActivityDisplayName has_any "Add eligible member to role"LoggedByService in "Core Directory,PIM" |
- | 1 | - | - | 1 |
OperationName has "Add app role assignment to service principal" |
- | 1 | - | - | 1 |
OperationName has "StsRefreshTokenValidFrom" |
- | 1 | - | - | 1 |
OperationName in "Add app role assignment to service principal,Add delegated permission grant,Consent to application" |
- | 1 | - | - | 1 |
OperationName in "Admin deleted security info,Admin registered security info,Admin updated security info,User changed default security info,User deleted security info,User registered security info,User updated security info" |
- | 1 | - | - | 1 |
OperationName == "Add member to role" |
- | 1 | - | - | 1 |
OperationName in "Admin deleted security info,Admin registered security info,Admin updated security info,User changed default security info,User deleted security info,User registered all required security info,User registered security info,User started security info registration" |
- | 1 | - | - | 1 |
OperationName in "Add application,Update application" |
- | 1 | - | - | 1 |
ActivityDisplayName has_any "Update application" |
- | 1 | - | - | 1 |
OperationName in "Approve access package assignment request,Request approved,User requests access package assignment" |
- | 1 | - | - | 1 |
OperationName == "Read BitLocker key" |
- | 1 | - | - | 1 |
OperationName in "Add member to group,Add member to role,Add member to role.,Add owner to group,Remove member from group,Remove member from role,Remove member from role.,Remove owner from group"OperationName has "Add"OperationName has "owner" |
- | 1 | - | - | 1 |
OperationName in "Delete conditional access policy,Update conditional access policy" |
- | 1 | - | - | 1 |
OperationName == "Consent to application"OperationName != "Consent to application" |
- | 1 | - | - | 1 |
OperationName == "Set domain authentication" |
- | 1 | - | - | 1 |
OperationName in "Add member to role,Add member to role.,Add service principal credentials,Update application - Certificatessecrets management" |
- | 1 | - | - | 1 |
OperationName in "Add group,Add member to group,Add owner to group" |
- | 1 | - | - | 1 |
OperationName in "Add named location,Delete named location,Update named location" |
- | 1 | - | - | 1 |
OperationName in "Add app role assignment to service principal,Add service principal,Consent to application" |
- | 1 | - | - | 1 |
OperationName in "Invite external user,Redeem external user invite" |
- | 1 | - | - | 1 |
OperationName in "Reset user password,Reset user password." |
- | 1 | - | - | 1 |
OperationName in "Add member to role,Add member to role.,Add user" |
- | 1 | - | - | 1 |
OperationName == "Add group" |
- | 1 | - | - | 1 |
OperationName in "Add service principal credentials,Update application - Certificatessecrets management" |
- | 1 | - | - | 1 |
OperationName == "Update service principal" |
- | 1 | - | - | 1 |
OperationName == "Add owner to service principal" |
- | 1 | - | - | 1 |
OperationName in "Admin registered security info,Create Temporary Access Pass method for user,Update user" |
- | 1 | - | - | 1 |
OperationName == "User registered security info"ResultType == "0" |
- | 1 | - | - | 1 |
OperationName == "User registered security info" |
- | 1 | - | - | 1 |
OperationName in "Register device,User registered security info" |
- | 1 | - | - | 1 |
OperationName in "Disable Strong Authentication,User deleted security info" |
- | 1 | - | - | 1 |
OperationName has_any "Download group members,Download groups,Download user registeration details,Download users" |
- | 1 | - | - | 1 |
OperationName in "Add member to role,Add member to role." |
- | 1 | - | - | 1 |
OperationName has_any "password,security info" |
- | 1 | - | - | 1 |
Identity !has "MS-PIM"OperationName in "Remove eligible member from role,Remove member from role" |
- | 1 | - | - | 1 |
OperationName == "Add registered owner to device" |
- | 1 | - | - | 1 |
SourceSystem == "Azure AD" |
- | 1 | - | - | 1 |
AdditionalDetails contains "fraud" |
- | 1 | - | - | 1 |
| Total | 0 | 135 | 0 | 0 | 135 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Assign |
- | 6 | - | - | 6 |
AssignEligibleRole |
- | 4 | - | - | 4 |
CreateRequestGrantedRole |
- | 2 | - | - | 2 |
CreateRequestPermanentEligibleRole |
- | 2 | - | - | 2 |
CreateRequestPermanentGrantedRole |
- | 2 | - | - | 2 |
CreateRequestEligibleRole |
- | 2 | - | - | 2 |
Add |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has_any Add eligible member to role |
- | 6 | - | - | 6 |
Add member to role request denied (PIM activation) |
- | 2 | - | - | 2 |
Add eligible member to role in PIM requested (timebound) |
- | 2 | - | - | 2 |
User registered security info |
- | 1 | - | - | 1 |
User has elevated their access to User Access Administrator for their Azure Resources |
- | 1 | - | - | 1 |
has Consent to application |
- | 1 | - | - | 1 |
has_any Add delegated permission grant |
- | 1 | - | - | 1 |
has Disable PIM Alert |
- | 1 | - | - | 1 |
has_any Update application |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
contains fraud |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= MS-PIM |
- | 3 | - | - | 3 |
!= MS-PIM-Fairfax |
- | 3 | - | - | 3 |
!has MS-PIM |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has_any CUSTOM DOMAIN NAME# |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Core Directory |
- | 15 | - | - | 15 |
PIM |
- | 2 | - | - | 2 |
Authentication Methods |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Consent to application |
- | 11 | - | - | 11 |
Add app role assignment to service principal |
- | 8 | - | - | 8 |
Update conditional access policy |
- | 8 | - | - | 8 |
Update user |
- | 7 | - | - | 7 |
Add member to role |
- | 7 | - | - | 7 |
Add delegated permission grant |
- | 6 | - | - | 6 |
Add member to role. |
- | 6 | - | - | 6 |
Invite external user |
- | 5 | - | - | 5 |
Set domain authentication |
- | 5 | - | - | 5 |
Add user |
- | 5 | - | - | 5 |
Add service principal credentials |
- | 5 | - | - | 5 |
User registered security info |
- | 5 | - | - | 5 |
Set federation settings on domain |
- | 4 | - | - | 4 |
has Update a partner cross-tenant access setting |
- | 4 | - | - | 4 |
Add service principal |
- | 4 | - | - | 4 |
Admin registered security info |
- | 4 | - | - | 4 |
Update application |
- | 3 | - | - | 3 |
Delete user |
- | 3 | - | - | 3 |
Add member to group |
- | 3 | - | - | 3 |
Add owner to group |
- | 3 | - | - | 3 |
Add OAuth2PermissionGrant |
- | 3 | - | - | 3 |
has_any Add service principal |
- | 3 | - | - | 3 |
has_any Certificates |
- | 3 | - | - | 3 |
User deleted security info |
- | 3 | - | - | 3 |
Redeem external user invite |
- | 2 | - | - | 2 |
Delete conditional access policy |
- | 2 | - | - | 2 |
Add unverified domain |
- | 2 | - | - | 2 |
has Add member to role outside of PIM |
- | 2 | - | - | 2 |
has Consent to application |
- | 2 | - | - | 2 |
has_any Update Application |
- | 2 | - | - | 2 |
has_any Update Service principal |
- | 2 | - | - | 2 |
Update Application |
- | 2 | - | - | 2 |
Admin deleted security info |
- | 2 | - | - | 2 |
Admin updated security info |
- | 2 | - | - | 2 |
User changed default security info |
- | 2 | - | - | 2 |
Remove member from role |
- | 2 | - | - | 2 |
Update application - Certificates |
- | 2 | - | - | 2 |
Add group |
- | 2 | - | - | 2 |
Add member to role completed (PIM activation) |
- | 1 | - | - | 1 |
has Add eligible member |
- | 1 | - | - | 1 |
has Invite external user |
- | 1 | - | - | 1 |
has Redeem external user invite |
- | 1 | - | - | 1 |
Add conditional access policy |
- | 1 | - | - | 1 |
Update group |
- | 1 | - | - | 1 |
has Add a partner to cross-tenant access setting |
- | 1 | - | - | 1 |
has Delete partner specific cross-tenant access setting |
- | 1 | - | - | 1 |
has Certificates |
- | 1 | - | - | 1 |
Add verified domain |
- | 1 | - | - | 1 |
Update device |
- | 1 | - | - | 1 |
Remove service principal |
- | 1 | - | - | 1 |
has_all Update application |
- | 1 | - | - | 1 |
Add owner to application |
- | 1 | - | - | 1 |
Update role setting in PIM |
- | 1 | - | - | 1 |
has conditional access policy |
- | 1 | - | - | 1 |
has_all member to role |
- | 1 | - | - | 1 |
Add User |
- | 1 | - | - | 1 |
has Add app role assignment to service principal |
- | 1 | - | - | 1 |
has StsRefreshTokenValidFrom |
- | 1 | - | - | 1 |
User updated security info |
- | 1 | - | - | 1 |
User registered all required security info |
- | 1 | - | - | 1 |
User started security info registration |
- | 1 | - | - | 1 |
Add application |
- | 1 | - | - | 1 |
Approve access package assignment request |
- | 1 | - | - | 1 |
Request approved |
- | 1 | - | - | 1 |
User requests access package assignment |
- | 1 | - | - | 1 |
Read BitLocker key |
- | 1 | - | - | 1 |
Remove member from group |
- | 1 | - | - | 1 |
Remove member from role. |
- | 1 | - | - | 1 |
Remove owner from group |
- | 1 | - | - | 1 |
has Add |
- | 1 | - | - | 1 |
has owner |
- | 1 | - | - | 1 |
!= Consent to application |
- | 1 | - | - | 1 |
Add named location |
- | 1 | - | - | 1 |
Delete named location |
- | 1 | - | - | 1 |
Update named location |
- | 1 | - | - | 1 |
Reset user password |
- | 1 | - | - | 1 |
Reset user password. |
- | 1 | - | - | 1 |
Update service principal |
- | 1 | - | - | 1 |
Add owner to service principal |
- | 1 | - | - | 1 |
Create Temporary Access Pass method for user |
- | 1 | - | - | 1 |
Register device |
- | 1 | - | - | 1 |
Disable Strong Authentication |
- | 1 | - | - | 1 |
has_any Download group members |
- | 1 | - | - | 1 |
has_any Download groups |
- | 1 | - | - | 1 |
has_any Download user registeration details |
- | 1 | - | - | 1 |
has_any Download users |
- | 1 | - | - | 1 |
has_any password |
- | 1 | - | - | 1 |
has_any security info |
- | 1 | - | - | 1 |
Remove eligible member from role |
- | 1 | - | - | 1 |
Add registered owner to device |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= RoleAssignmentExists |
- | 2 | - | - | 2 |
Admin registered temporary access pass method for user |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
0 |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Azure AD |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has offline |
- | 2 | - | - | 2 |
has_any -PRIV |
- | 2 | - | - | 2 |
has full_access_as_app |
- | 1 | - | - | 1 |
has AppIdentifierUri |
- | 1 | - | - | 1 |
has AppAddress |
- | 1 | - | - | 1 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊