New Blog Post | How to Enable Two New Logs to Monitor Azure Active Directory in Microsoft Sentinel

Microsoft

AshleyMartin_0-1646154228179.png

How to Enable Two New Logs to Monitor for Azure Active Directory in Microsoft Sentinel – Azure Cloud...

There are three new logs available for Azure Active Directory, but only two are currently populating data. Once enabled they will generate the following new tables:

 

AADServicePrincipalRiskEvents – Logs generated by identity protection for Azure AD service principal risk events.

 

AADRiskyServicePrincipals – Logs generated by identity protection for Azure AD risky service principals.

 

NetworkAccessTrafficLogs  details still being surfaced  check back

 

1 Reply