↳ GitHub sourceConnector

Microsoft Entra ID

Description

Gain insights into Microsoft Entra ID by connecting Audit and Sign-in logs to Microsoft Sentinel to gather insights around Microsoft Entra ID scenarios. You can learn about app usage, conditional access policies, legacy auth relate details using our Sign-in logs. You can get information on your Self Service Password Reset (SSPR) usage, Microsoft Entra ID Management activities like user, group, role, app management using our Audit logs table. For more information, see the [Microsoft Sentinel documentation](https://go.microsoft.com/fwlink/?linkid=2219715&wt.mc_id=sentinel_dataconnectordocs_content_cnl_csasci).
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions.
Workspace
Workspace
Diagnostic Settings
read and write permissions to AAD diagnostic settings.
/providers/microsoft.aadiam

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Microsoft Entra ID logs to Microsoft Sentinel
Select Microsoft Entra ID log types:
Sign-In Logs
Audit Logs
Non-Interactive User Sign-In Log
Service Principal Sign-In Logs
Managed Identity Sign-In Logs
Provisioning Logs
ADFS Sign-In Logs
User Risk Events
Risky Users
Network Access Traffic Logs
Risky Service Principals
Service Principal Risk Events

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
AzureActiveDirectory
Additional source files 2Solutions/Microsoft Entra ID/Data Connectors/template_AzureActiveDirectory.JSONsource ↗Solutions/Microsoft Entra ID/Data/Solution_AAD.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.