Forum Discussion

AshleyMartin's avatar
AshleyMartin
Former Employee
Mar 01, 2022

New Blog Post | How to Enable Two New Logs to Monitor Azure Active Directory in Microsoft Sentinel

How to Enable Two New Logs to Monitor for Azure Active Directory in Microsoft Sentinel – Azure Cloud & AI Domain Blog (azurecloudai.blog)

There are three new logs available for Azure Active Directory, but only two are currently populating data. Once enabled they will generate the following new tables:

 

AADServicePrincipalRiskEvents – Logs generated by identity protection for Azure AD service principal risk events.

 

AADRiskyServicePrincipals – Logs generated by identity protection for Azure AD risky service principals.

 

NetworkAccessTrafficLogs  details still being surfaced  check back