Managing identity reporting capabilities
Azure Active Directory contains a series of reports that can be used to gain insight into various activities around the user. These reports are broken down into three categories:
- Anomalous Activity: This reports potentially suspicious activity that could be an indicator of a security incident
- Activity Logs: This provides reports on various activities that are taking place within the directory, such as password management or self-service identity activities
- Integrated Applications: This provides statistics regarding which applications are being used
The following figure represents the Azure AD reporting architecture and informs us of the different interfaces and capabilities:

Azure Active Directory Audit Report events
With Azure AD Audit Reports, you can identify the following possible causes:
- User is sharing their password
- User is using a remote desktop to launch a web browser for sign in
- User is using a VPN or going through a proxy in another region
- A...