Description
Gain insights into Microsoft Entra ID by connecting Audit and Sign-in logs to Microsoft Sentinel to gather insights around Microsoft Entra ID scenarios. You can learn about app usage, conditional access policies, legacy auth relate details using our Sign-in logs. You can get information on your Self Service Password Reset (SSPR) usage, Microsoft Entra ID Management activities like user, group, role, app management using our Audit logs table. For more information, see the [Microsoft Sentinel documentation](https://go.microsoft.com/fwlink/?linkid=2219715&wt.mc_id=sentinel_dataconnectordocs_content_cnl_csasci).
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions.
Workspace
Workspace
Diagnostic Settings
read and write permissions to AAD diagnostic settings.
/providers/microsoft.aadiam
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect Microsoft Entra ID logs to Microsoft Sentinel
Select Microsoft Entra ID log types:
Sign-In Logs
Audit Logs
Non-Interactive User Sign-In Log
Service Principal Sign-In Logs
Managed Identity Sign-In Logs
Provisioning Logs
ADFS Sign-In Logs
User Risk Events
Risky Users
Network Access Traffic Logs
Risky Service Principals
Service Principal Risk Events
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
7ca9800↗- Source identifier
AzureActiveDirectory
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC