Monitor and maintain Microsoft Entra ID

Advanced
Administrator
Identity and Access Administrator
Security Engineer
Azure
Microsoft Entra
Microsoft Entra ID Governance
Microsoft Entra ID

Audit and diagnostic logs within Microsoft Entra ID provide a rich view into how users are accessing your Azure solution. Learn to monitor, troubleshoot, and analyze sign-in data.

Learning objectives

By the end of this module, you'll be able to:

  • Analyze and investigate sign in logs to troubleshoot access issues
  • Review and monitor Microsoft Entra audit logs
  • Enable and integrate Microsoft Entra diagnostic logs with Log Analytics / Azure Sentinel
  • Export sign in and audit logs to a third-party SIEM (security information and event management)
  • Review Microsoft Entra activity by using Log Analytics / Azure Sentinel, excluding KQL (Kusto Query Language) use
  • Analyze Microsoft Entra workbooks / reporting
  • Configure notifications

Prerequisites

None