%3CLINGO-SUB%20id%3D%22lingo-sub-1015858%22%20slang%3D%22en-US%22%3EUpcoming%20change%20to%20Audit%20logs%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1015858%22%20slang%3D%22en-US%22%3E%3CP%3EWe%E2%80%99re%20rolling%20out%20a%20unified%20audit%20log%20experience%2C%20centralizing%20Audit%20logs%20in%20Intune%20in%20one%20location.%20This%20is%20slated%20to%20roll%20out%20with%20the%20December%20update%20to%20the%20Intune%20service%20around%20mid-December.%20We%E2%80%99ll%20update%20our%20documentation%20when%20this%20change%20rolls%20out%20but%20here%E2%80%99s%20a%20sneak%20peek%20into%20how%20this%20will%20look%20in%20the%20console.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EIn%20the%20Microsoft%20Device%20Management%20or%20Microsoft%20Endpoint%20Manager%20console%2C%20Audit%20logs%20will%20now%20be%20consolidated%20in%20the%20Tenant%20administration%20blade.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F157782i7643CCA5EB75B6F1%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Audit%20logs%201.jpg%22%20title%3D%22Audit%20logs%201.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20will%20be%20able%20to%20see%20all%20audit%20logs%20at%20once%20or%20filter%20based%20on%20specific%20workload.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F157784i86A8BD136307AB9C%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Audit%20logs%20.png%22%20title%3D%22Audit%20logs%20.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EIn%20the%20Azure%20portal%2C%20you%20will%20see%20the%20same%20experience%20of%20consolidated%20logs%20under%20Intune%20%26gt%3B%20Monitoring%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F157788iE8B148D04CBA3C24%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Audit%20logs%204.jpg%22%20title%3D%22Audit%20logs%204.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3ELet%20us%20know%20what%20you%20think!%20We%E2%80%99ll%20update%20our%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Ffundamentals%2Fwhats-new%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%3C%2FA%3E%20page%20when%20this%20change%20rolls%20out.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1015858%22%20slang%3D%22en-US%22%3E%3CP%3EWe%E2%80%99re%20rolling%20out%20a%20unified%20audit%20log%20experience%2C%20centralizing%20Audit%20logs%20in%20Intune%20in%20one%20location.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1015858%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%20Customer%20Success%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1016882%22%20slang%3D%22en-US%22%3ERe%3A%20Upcoming%20change%20to%20Audit%20logs%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1016882%22%20slang%3D%22en-US%22%3E%3CP%3ECan%20these%20be%20exported%20to%20a%20storage%20account%20or%20log%20analytics%20like%20AzureAD%20logs%20can%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1029636%22%20slang%3D%22en-US%22%3ERe%3A%20Upcoming%20change%20to%20Audit%20logs%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1029636%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F2156%22%20target%3D%22_blank%22%3E%40Simon%20Payne%3C%2FA%3E%20they%20can%20indeed.%20Check%20out%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Ffundamentals%2Freview-logs-using-azure-monitor%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ethis%20doc%3C%2FA%3E%20for%20more%20info%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1055358%22%20slang%3D%22en-US%22%3ERe%3A%20Upcoming%20change%20to%20Audit%20logs%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1055358%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20what%20exactly%20is%20the%20benefit%20of%20adding%20the%20Intune%20logs%20in%20Azure%20Log%20Analytics%3F%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F438624%22%20target%3D%22_blank%22%3E%40cimurphy%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F2156%22%20target%3D%22_blank%22%3E%40Simon%20Payne%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1083721%22%20slang%3D%22en-US%22%3ERe%3A%20Upcoming%20change%20to%20Audit%20logs%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1083721%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F146090%22%20target%3D%22_blank%22%3E%40Labinot%20Jashanica%3C%2FA%3E%2C%20the%20built-in%20logs%20within%20Intune%20will%20provide%20enough%20information%20about%20your%20environment%2C%20however%20there%20may%20be%20times%20where%20you'd%20also%20like%20to%20extend%20logging%20capabilities.%20These%20will%20vary%20by%20environment%2C%20but%20am%20sharing%20a%20few%20that%20may%20help%20what%20this%20could%20be%20used%20for%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EArchive%20Intune%20logs%20to%20an%20Azure%20storage%20account%20to%20keep%20the%20data%2C%20or%20archive%20for%20a%20set%20time.%3C%2FLI%3E%0A%3CLI%3EStream%20Intune%20logs%20to%20an%20Azure%20event%20hub%20for%20analytics%20using%20popular%20Security%20Information%20and%20Event%20Management%20(SIEM)%20tools%2C%20such%20as%20Splunk%20and%20QRadar.%3C%2FLI%3E%0A%3CLI%3EIntegrate%20Intune%20logs%20with%20your%20own%20custom%20log%20solutions%20by%20streaming%20them%20to%20an%20event%20hub.%3C%2FLI%3E%0A%3CLI%3ESend%20Intune%20logs%20to%20Log%20Analytics%20to%20enable%20rich%20visualizations%2C%20monitoring%2C%20and%20alerting%20on%20the%20connected%20data.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EHope%20this%20helps!%3C%2FP%3E%3C%2FLINGO-BODY%3E

We’re rolling out a unified audit log experience, centralizing Audit logs in Intune in one location. This is slated to roll out with the December update to the Intune service around mid-December. We’ll update our documentation when this change rolls out but here’s a sneak peek into how this will look in the console.


In the Microsoft Device Management or Microsoft Endpoint Manager console, Audit logs will now be consolidated in the Tenant administration blade.

 

Audit logs 1.jpg

 

You will be able to see all audit logs at once or filter based on specific workload.

 

Audit logs .png

In the Azure portal, you will see the same experience of consolidated logs under Intune > Monitoring

 

Audit logs 4.jpg

Let us know what you think! We’ll update our What’s New page when this change rolls out.

4 Comments
Regular Visitor

Can these be exported to a storage account or log analytics like AzureAD logs can?

Microsoft

@Simon Payne they can indeed. Check out this doc for more info

Occasional Contributor

Hi, what exactly is the benefit of adding the Intune logs in Azure Log Analytics? @cimurphy @Simon Payne 

Hi @Labinot Jashanica, the built-in logs within Intune will provide enough information about your environment, however there may be times where you'd also like to extend logging capabilities. These will vary by environment, but am sharing a few that may help what this could be used for:

  • Archive Intune logs to an Azure storage account to keep the data, or archive for a set time.
  • Stream Intune logs to an Azure event hub for analytics using popular Security Information and Event Management (SIEM) tools, such as Splunk and QRadar.
  • Integrate Intune logs with your own custom log solutions by streaming them to an event hub.
  • Send Intune logs to Log Analytics to enable rich visualizations, monitoring, and alerting on the connected data.

Hope this helps!