Forum Discussion
Deleted
Mar 27, 2025Missing details in Azure Activity Logs – MICROSOFT.SECURITYINSIGHTS/ENTITIES/ACTION
The Azure Activity Logs are crucial for tracking access and actions within Sentinel. However, I’m encountering a significant lack of documentation and clarity regarding some specific operation types....
AndrewBlumhardt
Microsoft
Mar 31, 2025I recommend using Microsoft Copilot or ChatGPT. Both can be very useful when researching obscure or legacy topics. I suspect these entries are because a Sentinel user interacted with an entity profile in some way. You might also try speaking with a listed user and trying to recreate the activity.
Deleted
Mar 31, 2025Thanks. Unfortunately, I’ve already completed all of these steps, but the data is still strangely missing.
I submitted a suggestion in a pull request to Microsoft about it. One interesting thing is that I can see the same activities, but I’m not able to reproduce them manually. I can see all other types of operations triggered by manual actions—just not these ones. It seems like they might be generated automatically…