Configuring and reviewing reports
With reporting data now flowing into Azure Monitor and Log Analytics, you can review auditing and logging data to gain insights into how your tenant and directory services are being used.
To review this data, you’ll need to have access to the Log Analytics workspace where Azure Monitor is sending data, as well as one of the following roles:
- Global Admin
- Reports Reader
- Security Admin
- Security Reader
With that, let’s start looking at logs!
Azure AD logs and reports
Azure AD provides several default reports that can be used to identify issues quickly. The core reports are the Audit, Sign-in, and Provisioning logs.
Audit logs
The audit logs are a collection of system activity records for a wide variety of events. These categories can be seen in the following table:
AdministrativeUnit |
Agreement |
ApplicationManagement... |