Forum Discussion
AshleyMartin
Mar 01, 2022Former Employee
New Blog Post | How to Enable Two New Logs to Monitor Azure Active Directory in Microsoft Sentinel
There are three new logs available for Azure Active Directory, but only two are currently populating data. Once enabled they will generate the following new tables:
AADServicePrincipalRiskEvents – Logs generated by identity protection for Azure AD service principal risk events.
AADRiskyServicePrincipals – Logs generated by identity protection for Azure AD risky service principals.
NetworkAccessTrafficLogs – details still being surfaced – check back
1 Reply
- Marek_BelanIron Contributor
AshleyMartin what is NetworkAccessTrafficLogs for?