Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: Authorization
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add v2 application permissions | Adds v2 (identity platform v2) application permissions to an app in an Azure AD B2C tenant. | N | N |
| Check whether the resource name is available | B2C checked whether a requested resource (tenant/directory) name is available before creation. | N | N |
| Create API connector | An API connector was created in Azure AD B2C for calling external REST endpoints in user flows. | N | N |
| Create authentication | An authenticationEventListener was created, binding an auth event to a custom extension that calls an external REST API at sign-in. | N | N |
| Create authentication | An authenticationEventsFlow (External ID sign-up or sign-in user flow) was created. | N | N |
| Create custom identity provider | Creation of a custom external identity provider (e.g. OpenID Connect/SAML) for sign-in in an Azure AD B2C tenant. | N | N |
| Create custom policy | Creation/upload of an Azure AD B2C Identity Experience Framework custom policy defining user journeys and trust-framework behavior. | N | N |
| Create custom | Creation of a customAuthenticationExtension: a REST callout invoked during authentication events (e.g. token issuance start). | N | N |
| Create Identity Provider | An external identity provider (federation) was created in the Azure AD B2C tenant. | Y | N |
| Create or update a B2 | An Azure AD B2C directory resource was created or updated. | N | N |
| Create or update a B2 | An Azure AD B2C directory tenant and its Azure resource were created or updated. | N | N |
| Create or update a CIAM directory tenant and resource | A CIAM (Microsoft Entra External ID) directory tenant and its Azure resource were created or updated. | N | N |
| Create or update a Guest Usages resource | A Guest Usages resource (subscription linkage for guest/external MAU billing) was created or updated. | N | N |
| Create or update localized resource | A localized (language-customization) resource was created or updated in Azure AD B2C. | N | N |
| Create policy key | Creation of an Azure AD B2C policy key (keyset cryptographic material) used to sign/encrypt tokens or establish service trust. | N | N |
| Create starter pack | Creation of an Azure AD B2C custom policy (Identity Experience Framework) starter pack. | N | N |
| Create user attribute | Creation of a custom user attribute (extension attribute) in an Azure AD B2C tenant. | N | N |
| Create user flow | Creation of an Azure AD B2C user flow (built-in sign-up/sign-in, profile-edit, or password-reset experience). | N | N |
| Create v2 application | Registration of a v2 (Microsoft identity platform) application in an Azure AD B2C tenant. | N | N |
| Delete API connector | An Azure AD B2C API connector (external REST callout in a user flow) was deleted. | N | N |
| Delete authentication | An authenticationEventListener binding a custom authentication extension to an event was deleted. | N | N |
| Delete authentication | An authenticationEventsFlow (user-flow / multi-event policy) was deleted. | N | N |
| Delete B2 | A resource object within an Azure AD B2C directory was deleted. | N | N |
| Delete B2 | An Azure AD B2C tenant was deleted by an administrator of that tenant. | N | N |
| Delete CIAM directory resource | A directory resource was deleted in a CIAM (Entra External ID / Azure AD B2C) customer tenant. | N | N |
| Delete custom policy | An Azure AD B2C custom policy (Identity Experience Framework / TrustFramework) was deleted. | N | N |
| Delete custom | Deletion of a custom authentication extension (REST API extension invoked during an Entra External ID / B2C authentication flow). | N | N |
| Delete Guest Usages resource | Deletion of the Guest Usages billing-link resource connecting a B2C / External ID tenant to its MAU billing subscription. | N | N |
| Delete Identity Provider | Deletion of an external identity provider configuration (e.g. a social or Apple provider) in B2C / External ID. | N | N |
| Delete localized resource | Deletes an Azure AD B2C localized resource (language-specific UI strings) used by a user flow or custom policy. | N | N |
| Delete policy key | Deletion of an Azure AD B2C policy key (IEF signing/encryption/secret key container). | N | N |
| Delete user attribute | Deletes a custom user attribute (schema extension) in an Azure AD B2C tenant. | N | N |
| Delete user flow | Deletes an Azure AD B2C user flow (sign-up/sign-in/profile policy). | N | N |
| Delete v2 application | Deletes a v2 (Microsoft identity platform) application registration in Azure AD B2C. | N | N |
| Delete v2 application permission grant | Deletes an OAuth2 permission grant for a v2 application in Azure AD B2C. | N | N |
| Generate key | A new Azure AD B2C policy key (token signing or encryption key) was generated in a policy keyset. | N | N |
| Get active key metadata from policy key | The metadata of the active key within an Azure AD B2C policy keyset was read (read-only). | N | N |
| Get age gating configuration | The Azure AD B2C age gating configuration (minor identification and access settings) was read. | N | N |
| Get API connector | A single Azure AD B2C API connector configuration (REST endpoint used by a user flow) was read. | N | N |
| Get API connectors | The collection of Azure AD B2C API connectors (REST endpoints called by user flows) was listed. | N | N |
| Get authentication flows policy | The authenticationFlowsPolicy (tenant self-service sign-up setting) was read. | N | N |
| Get authentication | A single authenticationEventListener (custom-extension trigger for an auth event) was read. | N | N |
| Get authentication | A single authenticationEventsFlow (multi-event user-flow policy) was read. | N | N |
| Get authentication | The collection of authenticationEventsFlow objects (user-flow policies) was listed. | N | N |
| Get available output claims | A caller read the available output claims (token claims) configured in the Azure AD B2C directory. | N | N |
| Get B2 | A single Azure AD B2C directory resource (e.g. a policy or identity provider) was read. | N | N |
| Get B2 | B2C directory resources within an Azure resource group were listed. | N | N |
| Get B2 | B2C directory resources across an Azure subscription were listed. | N | N |
| Get B2 | All B2C tenants where the caller is an administrator were enumerated. | N | N |
| Get CIAM directory resource | A single CIAM (Entra External ID) directory resource was read. | N | N |
| Get CIAM directory resources in a resource group | CIAM (Entra External ID) directory resources within an Azure resource group were listed. | N | N |
| Get CIAM directory resources in a subscription | CIAM (Entra External ID) directory resources across an Azure subscription were listed. | N | N |
| Get configured custom identity providers | The custom identity providers configured in the Azure AD B2C directory were read. | N | N |
| Get configured identity providers | The identity providers configured in the Azure AD B2C directory were read. | N | N |
| Get configured local identity providers | Reads the local (email/username/phone) identity providers configured in an Azure AD B2C tenant. | N | N |
| Get custom domains | Reads the custom domains configured for an Azure AD B2C tenant's sign-in pages. | N | N |
| Get custom identity provider | Reads a configured custom (external) identity provider in an Azure AD B2C tenant. | N | N |
| Get custom policies | Lists the custom (Identity Experience Framework) policies defined in an Azure AD B2C tenant. | N | N |
| Get custom policy | Reads a single Azure AD B2C custom policy (Identity Experience Framework). | N | N |
| Get custom policy metadata | Reads the metadata of an Azure AD B2C custom policy. | N | N |
| Get custom | Reads a custom authentication extension (external REST callout used during authentication). | N | N |
| Get custom | Lists the custom authentication extensions (external REST callouts) configured in the tenant. | N | N |
| Get Guest Usages resources | Read of the B2C Guest Usages resources (guestUsages) linking a tenant to a subscription for MAU billing of guest/B2B usage. | N | N |
| Get Guest Usages resources in a subscription | Read of B2C Guest Usages resources (guestUsages) under a specific subscription: tenant-to-subscription MAU billing links. | N | N |
| Get Identity Provider | Read of a single configured identity provider (social/external IdP) in the B2C tenant. | N | N |
| Get identity provider types | Read of the identity provider types available for configuration in B2C (Google, Facebook, OIDC, SAML, etc.). | N | N |
| Get Identity Providers | Read of all identity providers configured in the B2C tenant (federation enumeration). | Y | N |
| Get list of tenants | Read of the list of Azure AD B2C tenants (e.g., those associated with a subscription). | N | N |
| Get localized resource | Read of a B2C localized resource (LocalizedResources language-customization for user flows / custom policies). | N | N |
| Get On | Read of the custom auth extension for the OnAttributeCollectionStart event (start of sign-up attribute collection). | N | N |
| Get On | Read of the custom auth extension for the OnAttributeCollectionSubmit event (after sign-up attribute submit). | N | N |
| Get On | Read of the custom auth extension for the OnPageRenderStart event in a B2C / External Identities tenant. | N | N |
| Get operation status for an async operation | Read of the status of an asynchronous B2C operation (Authorization-category status poll). | N | N |
| Get operations of Microsoft. | Read of the available operations exposed by the Microsoft.AzureActiveDirectory (Azure AD B2C) resource provider. | N | N |
| Get policy key | Read of a single B2C policy key (signing/encryption secret or certificate) from an IEF key container. | N | N |
| Get policy keys | Read of the list of B2C policy keys / key containers configured in the tenant. | N | N |
| Get resource properties of a tenant | Read of a B2C tenant's resource properties. | N | N |
| Get supported cultures | Retrieval of the supported cultures (languages/locales) available for B2C user-flow localization. | N | N |
| Get supported identity providers | Retrieval of the identity providers supported for configuration in the B2C tenant. | N | N |
| Get supported page contracts | Retrieval of the supported B2C page layout versions ('page contracts') for pages such as selfasserted. | N | N |
| Get tenant details | Retrieval of a B2C tenant's detail attributes. | N | N |
| Get tenant domains | Retrieval of the list of domains associated with the B2C tenant. | N | N |
| Get the authentication | Retrieval of the authenticationEventsPolicy holding the tenant's custom authentication extension event listeners. | N | N |
| Get user attribute | Read of a single Azure AD B2C user attribute definition (Authorization-category B2C read). | N | N |
| Get user attributes | Read of the list of Azure AD B2C user attribute definitions (Authorization-category B2C read). | N | N |
| Get user flow | Read of a single Azure AD B2C user flow (sign-up/sign-in policy). | N | N |
| Get user flows | Read of the list of Azure AD B2C user flows (sign-up/sign-in policies). | N | N |
| Get v1 and v2 applications | Read of the combined list of v1 and v2 application registrations in an Azure AD B2C tenant. | N | N |
| Get v1 applications | Read of the list of legacy (v1) application registrations in an Azure AD B2C tenant. | N | N |
| Get v2 application | Read of a single v2 (Microsoft identity platform) application registration in an Azure AD B2C tenant. | N | N |
| Initialize tenant | Initialization of an Azure AD B2C tenant; exact semantics undocumented and inferred from the name. | N | N |
| Move resources | A move operation on Azure AD B2C resources (B2C Authorization activity category). | N | N |
| Restore policy key | An Azure AD B2C Identity Experience Framework policy key (token-signing/encryption secret container) was restored. | N | N |
| Retrieve v2 application permissions grants | A read/enumeration of application permission grants in the Azure AD B2C tenant. | N | N |
| Retrieve v2 application service principals | A read/enumeration of application service principals in the Azure AD B2C tenant. | N | N |
| Update a B2 | An Azure AD B2C directory resource (the B2C tenant's linked Azure resource) was updated. | N | N |
| Update a CIAM directory resource | A Microsoft Entra External ID (CIAM) directory resource was updated. | N | N |
| Update a Guest Usages resource | A 'Guest Usages' external-identity usage/billing resource was updated. | N | N |
| Update age gating configuration | Modification of the Azure AD B2C age gating configuration (identifies minors and controls their access). | N | N |
| Update API connector | Modification of an Azure AD B2C API connector (external REST endpoint called during user flows). | N | N |
| Update authentication flows policy | Records a change to the authentication flows policy controlling whether self-service sign-up is enabled. | N | N |
| Update authentication | Records a change to an authentication event listener that binds custom logic to a point in the authentication flow. | N | N |
| Update authentication | Records a change to an authentication events flow (external-identities self-service sign-up user flow). | N | N |
| Update authentication | Records a change to the authentication events policy defining authentication-experience events and their listeners. | N | N |
| Update authorization policy | Records a change to the tenant authorization policy (default user permissions, guest access, and user consent settings). | Y | Y |
| Update custom identity provider | An Azure AD B2C custom (external OIDC/SAML) identity provider was updated. | N | N |
| Update custom policy | An Azure AD B2C custom policy (Identity Experience Framework) was updated. | N | N |
| Update custom | A custom authentication extension (REST API callout in the auth flow) was updated. | N | N |
| Update Identity Provider | Modification of an external/federated identity provider configuration in an Azure AD B2C tenant. | N | N |
| Update local identity provider | Change to the local-account identity provider (email/username/phone sign-in) in an Azure AD B2C tenant. | N | N |
| Update On | A custom authentication extension for the OnAttributeCollectionStart (pre-attribute-collection) event was updated. | N | N |
| Update On | A custom authentication extension for the OnAttributeCollectionSubmit (post-attribute-submit) event was updated. | N | N |
| Update On | A custom authentication extension for the OnPageRenderStart (page-render) event was updated. | N | N |
| Update policy key | A B2C policy key (Identity Experience Framework signing/encryption key) was updated. | N | N |
| Update subscription status | An Azure AD B2C subscription status value was updated. | N | N |
| Update tenant metadata | An Azure AD B2C tenant metadata value was updated. | N | N |
| Update user attribute | An Azure AD B2C user attribute (built-in profile attribute or custom directory-extension property) was modified. | N | N |
| Update user flow | An Azure AD B2C user flow (sign-up/sign-in/profile-edit/password-reset policy) was modified. | N | N |
| Upload certificate to policy key | A certificate/PKCS12 key was uploaded into an Azure AD B2C policy key (token-signing/IdP/REST trust material). | N | N |
| Upload key to policy key | Admin uploaded a certificate/PKCS12 (asymmetric) key into an Azure AD B2C policy keyset. | N | N |
| Upload secret into policy key | Admin stored a manually defined secret (symmetric key) into an Azure AD B2C policy keyset. | N | N |
| User authorization for application access | User authorized to access an on-premises app published through Entra application proxy. | N | N |
| Validate custom | Validation of a custom authentication extension's auth config (how Entra authenticates to the extension's REST API endpoint). | N | N |
| Validate move resources | Authorization pre-check validating whether a set of resources may be moved before the move proceeds. | N | N |
| Verify if tenant is B2 | Check of whether the target tenant is an Azure AD B2C tenant (a tenant-type determination). | N | N |
Add v2 application permissions
#Description
Records the addition of v2 (Microsoft identity platform v2) application permissions to an application in an Azure AD B2C tenant. Application-permission grants broaden an app's access, so they are relevant to monitoring for over-privileged or malicious applications.
References #
Check whether the resource name is available
#Description
Microsoft Entra B2C checked whether a requested resource name (such as a tenant or directory name) is available. This is a name-availability lookup performed while creating or updating a B2C directory resource.
References #
Create API connector
#Description
Records the creation of an API connector in Azure AD B2C, which calls an external REST endpoint at defined steps of a sign-up (or sign-in) user flow and exchanges user information as claims in an HTTP POST. A malicious or altered connector could exfiltrate user claims or manipulate the sign-up flow.
References #
Create authenticationEventListener
#Description
An authenticationEventListener was created, binding an authentication event such as token issuance or attribute collection to a custom authentication extension that calls an external REST API during sign-in. Because the listener runs inside the authentication flow, a rogue or compromised listener could influence claims or exfiltrate authentication context data.
References #
Create authenticationEventsFlow
#Description
An authenticationEventsFlow was created, defining a Microsoft Entra External ID self-service sign-up or sign-in user flow that orchestrates built-in authentication events and can invoke custom authentication extensions.
References #
Create custom identity provider
#Description
A custom external identity provider was created in an Azure AD B2C tenant, such as a generic OpenID Connect or SAML provider that lets customers sign in with an external account. It establishes a new federated sign-in path into the B2C tenant.
References #
Create custom policy
#Description
An Azure AD B2C custom policy was created (uploaded), an Identity Experience Framework XML configuration that defines user journeys and trust-framework behavior for the B2C tenant. Custom policies fully control authentication flows, so changes are sensitive to sign-in integrity.
References #
Create customAuthenticationExtension
#Description
A customAuthenticationExtension was created via Microsoft Graph, configuring a REST API callout to an external service during authentication events such as token issuance start or attribute collection. It defines an external endpoint and its authentication that participates in the sign-in/token pipeline, introducing an external code path into authentication.
References #
Create Identity Provider
#Description
An external identity provider was created in the Azure AD B2C tenant, configuring federation (for example social, OAuth/OpenID Connect, or SAML) for customer sign-in. A new federation path changes which credentials can authenticate users and is relevant to authentication-backdoor monitoring.
Example Audit Log Entry #
{
"AADOperationType": "Create",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:05.099485Z",
"ActivityDisplayName": "Create Identity Provider",
"AdditionalDetails": [
{
"key": "targetTenant",
"value": "00000000-0000-0000-0000-000000000000"
},
{
"key": "targetEntityType",
"value": "None"
},
{
"key": "actorIdentityType",
"value": "UPN"
},
{
"key": "RequiredPermissions",
"value": "Delegated_IdentityProviderReadWrite, Application_IdentityProviderReadWrite"
},
{
"key": "RequestId",
"value": "02f73b30-eaa7-4824-9da8-3f9a4ec084d2"
}
],
"Category": "Authorization",
"CorrelationId": "02f73b30-eaa7-4824-9da8-3f9a4ec084d2",
"DurationMs": "0",
"Id": "B2C_02f73b30-eaa7-4824-9da8-3f9a4ec084d2_11111111-1111-1111-1111-111111111111_134293368650994850",
"Identity": "adminuser@example.onmicrosoft.com",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": "adminuser@example.onmicrosoft.com",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "B2C",
"OperationName": "Create Identity Provider",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "failure",
"ResultDescription": "Access denied. Client app does not have required app permissions.",
"ResultReason": "Access denied. Client app does not have required app permissions.",
"ResultSignature": "None",
"TargetResources": [
{
"id": null,
"displayName": "00000000-0000-0000-0000-000000000000",
"type": "Other",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Create or update a B2C directory resource
#Description
An Azure AD B2C directory resource was created or updated: the Azure resource that represents a B2C tenant and links it to an Azure subscription for billing.
References #
Create or update a B2C directory tenant and resource
#Description
An Azure AD B2C directory tenant and its associated Azure resource were created or updated, recording provisioning or reconfiguration of a B2C tenant together with its subscription-linked resource.
References #
Create or update a CIAM directory tenant and resource
#Description
A CIAM (customer identity, Microsoft Entra External ID for customers) directory tenant and its associated Azure resource were created or updated. CIAM is Microsoft's customer identity access management offering, the successor model to Azure AD B2C.
References #
Create or update a Guest Usages resource
#Description
A Guest Usages resource was created or updated: the Azure resource that links a Microsoft Entra tenant to an Azure subscription for monthly active users (MAU) billing of guest and external users.
References #
Create or update localized resource
#Description
A localized resource was created or updated in the Azure AD B2C tenant, the language-customization content (translated user-flow or custom-policy UI strings) used to localize the sign-in and sign-up experience. This is the same action as 'Create or update a localized resource'; the differing audit category reflects the Entra category field, not a different operation.
References #
Create policy key
#Description
Records the creation of an Azure AD B2C policy key, a cryptographic key (a symmetric secret or an asymmetric certificate/key) stored in a keyset container in the Identity Experience Framework and used to establish trust between services or to sign or encrypt tokens. Unexpected policy-key creation can indicate tampering with B2C custom-policy trust material.
References #
Create starter pack
#Description
Records the creation of an Azure AD B2C custom policy starter pack: the base set of Identity Experience Framework custom policy files (such as TrustFrameworkBase and TrustFrameworkExtensions) that bootstrap sign-up/sign-in user journeys in the B2C tenant.
References #
Create user attribute
#Description
Records the creation of a custom user attribute (directory extension attribute) in an Azure AD B2C tenant, which can then be collected as a claim in user flows or custom policies and read/written via the Microsoft Graph API.
References #
Create user flow
#Description
Records the creation of an Azure AD B2C user flow: a built-in, configurable identity experience (such as sign-up/sign-in, profile editing, or password reset) that defines how end users authenticate against the B2C tenant.
References #
Create v2 application
#Description
Records the registration of an application (app registration) in an Azure AD B2C tenant using the v2 Microsoft identity platform app model. A new application registration establishes a security principal that can request tokens and permissions, so creation events are worth reviewing.
References #
Delete API connector
#Description
An Azure AD B2C API connector was deleted. API connectors call an external REST endpoint at defined steps of a user flow (for example to validate or enrich data during sign-up), so deleting one removes that external validation or enrichment integration.
References #
Delete authenticationEventlistener
#Description
Records the deletion of an authenticationEventListener, the object that binds a custom authentication extension (an HTTP callout to an external REST API) to a specific authentication event for one or more applications. Removing a listener stops that custom logic from running during sign-in, which could disable a security control or alter token/claims behavior.
References #
Delete authenticationEventsFlow
#Description
Records the deletion of an authenticationEventsFlow, the multi-event policy (user flow) that holds handler configuration for authentication events such as self-service sign-up and attribute collection in Entra External ID / B2C. Deleting it removes the user-flow definition governing how external users sign up and authenticate.
References #
Delete B2C directory resource
#Description
Records the deletion of a resource object within an Azure AD B2C directory, such as a user flow, identity provider, application, or user. Such deletions are part of routine B2C directory management; removing all of a tenant's resources is also a prerequisite before the B2C tenant itself can be deleted.
References #
Delete B2C Tenant where the caller is an administrator
#Description
Records the deletion of an Azure AD B2C tenant by a caller holding administrator (Global Administrator) rights over that tenant. Tenant deletion permanently destroys the B2C directory and requires all tenant resources to be removed first.
References #
Delete CIAM directory resource
#Description
A directory resource was deleted within a customer identity and access management (CIAM) context, emitted by the B2C / Microsoft Entra External ID logging service for a customer (external) tenant. CIAM is Microsoft's consumer- and business-customer-facing identity platform built on Entra External ID.
References #
Delete custom policy
#Description
An Azure AD B2C custom policy was deleted. Custom policies are Identity Experience Framework (TrustFramework) XML configurations that define user journeys and authentication behavior for a B2C tenant.
References #
Delete customAuthenticationExtension
#Description
A custom authentication extension was deleted. Custom authentication extensions are event-listener / REST API extensions that Microsoft Entra (including External ID and Azure AD B2C) invokes at specific points in an authentication flow, for example to add claims at token issuance or to validate attributes during sign-up, so removing one alters a tenant's authentication pipeline.
References #
Delete Guest Usages resource
#Description
A Guest Usages resource was deleted. Guest Usages is the linked-subscription billing resource that connects a Microsoft Entra External ID or Azure AD B2C tenant to the Azure subscription used for monthly active user (MAU) billing of external and guest identities. Deleting it removes the billing link only, not the tenant, its users, or its applications.
References #
Delete Identity Provider
#Description
An external identity provider configuration was deleted in Azure AD B2C or Microsoft Entra External ID. The Microsoft Graph delete identityProvider operation removes a configured provider, such as a social identity provider (for example Google or Facebook) or, in Azure AD B2C, an Apple identity provider. Removing an identity provider stops users from signing in through it.
References #
Delete localized resource
#Description
Records deletion of a localized resource in Azure AD B2C, the language-specific UI strings and collections that a user flow or custom policy loads to support multiple locales. Removing it affects localized sign-up and sign-in experiences.
References #
Delete policy key
#Description
Records the deletion of an Azure AD B2C policy key, a cryptographic key held in a key container and used by Identity Experience Framework custom policies to sign or encrypt tokens and to store secrets for identity-provider and REST API integrations. Removing signing or encryption keys can disrupt or be used to tamper with B2C authentication.
References #
Delete user attribute
#Description
Records deletion of a custom user attribute definition in an Azure AD B2C tenant (Authorization category). Custom attributes extend the B2C user schema for use in user flows, so this removes a directory schema extension.
References #
Delete user flow
#Description
Records deletion of an Azure AD B2C user flow (Authorization category), the built-in policy that defines a sign-up, sign-in, profile-edit, or password-reset experience. Removing a user flow disrupts the affected authentication journeys for the tenant.
References #
Delete v2 application
#Description
Records deletion of a v2 (Microsoft identity platform) application registration in an Azure AD B2C tenant (Authorization category). Application deletion can disrupt dependent authentication or remove evidence of an unauthorized app registration.
References #
Delete v2 application permission grant
#Description
Records deletion of an OAuth2 permission grant associated with a v2 (Microsoft identity platform) application in an Azure AD B2C tenant (Authorization category), removing previously consented API permissions for that application.
References #
Generate key
#Description
A new Azure AD B2C policy key was generated and added to a policy keyset (key container) in the Identity Experience Framework, producing cryptographic material used to sign or encrypt tokens. New signing material is security-relevant because rogue or forged keys can enable token forgery or persistence.
References #
Get active key metadata from policy key
#Description
The metadata of the currently active key within an Azure AD B2C policy keyset was read, such as the active key's identifier and activation date. This is a read-only operation against token signing or encryption key configuration and is low risk on its own.
References #
Get age gating configuration
#Description
The Azure AD B2C age gating configuration was read: the settings that identify minors and control whether they may access an application, with or without parental consent. This is a read-only operation.
References #
Get API connector
#Description
A single Azure AD B2C API connector configuration was read: a REST API endpoint, with its authentication settings, that a user flow calls to integrate external logic during sign-up. This is a read-only operation; reconnaissance of connector endpoints can precede tampering.
References #
Get API connectors
#Description
The collection of Azure AD B2C API connectors was listed, returning the configured REST API endpoints that user flows can call to integrate external logic during sign-up. This is a read-only operation.
References #
Get authentication flows policy
#Description
The authenticationFlowsPolicy was read: the tenant-level policy that controls whether the self-service sign-up experience is enabled. This is a read-only operation.
References #
Get authenticationEventListener
#Description
A single authenticationEventListener was read: a listener that registers custom logic (a custom authentication extension) to run for a specific authentication event under defined conditions. This is a read-only operation.
References #
Get authenticationEventsFlow
#Description
A single authenticationEventsFlow was read: a multi-event policy (user flow) that holds the handler configuration for multiple authentication events. This is a read-only operation.
References #
Get authenticationEventsFlows
#Description
The collection of authenticationEventsFlow objects was listed, returning the multi-event user-flow policies and their configured authentication-event handlers. This is a read-only operation.
References #
Get available output claims
#Description
Records a caller reading the set of available output claims (the claims that a B2C user flow or custom policy can return in its issued tokens) in the Azure AD B2C directory. This is a read-only Authorization activity; unexpected enumeration of policy claim configuration can indicate reconnaissance of a tenant's identity setup.
References #
Get B2C directory resource
#Description
Records a read of a single B2C directory resource (for example a policy, identity provider, or other B2C configuration object) in the Azure AD B2C tenant. This is a read-only Authorization activity.
References #
Get B2C directory resources in a resource group
#Description
Records a list/read of the B2C directory resources contained within an Azure resource group. This is a read-only Authorization activity; bulk enumeration of B2C resources can indicate reconnaissance of the tenant's configuration.
References #
Get B2C directory resources in a subscription
#Description
Records a list/read of the B2C directory resources across an Azure subscription. This is a read-only Authorization activity; subscription-wide enumeration can indicate reconnaissance of B2C deployments.
References #
Get B2C Tenants where the caller is an administrator
#Description
Records enumeration of all B2C tenants for which the calling identity holds administrator rights. This is a read-only Authorization activity; enumerating administered tenants can be a reconnaissance step for an actor mapping accessible B2C directories.
References #
Get CIAM directory resources in a resource group
#Description
Records a list/read of the CIAM (Microsoft Entra External ID for customers) directory resources contained within an Azure resource group. This is a read-only Authorization activity; bulk enumeration can indicate reconnaissance.
References #
Get CIAM directory resources in a subscription
#Description
Records a list/read of the CIAM (Microsoft Entra External ID for customers) directory resources across an Azure subscription. This is a read-only Authorization activity; subscription-wide enumeration can indicate reconnaissance.
References #
Get configured custom identity providers
#Description
Records a read of the custom identity providers (for example federated OpenID Connect or SAML providers) configured in the Azure AD B2C directory. This is a read-only Authorization activity; enumerating federated identity providers can reveal trust relationships an actor could target or abuse.
References #
Get configured identity providers
#Description
Records a read of the identity providers configured in the Azure AD B2C directory. This is a read-only Authorization activity; enumeration of configured identity providers is a reconnaissance step that maps a tenant's federation and sign-in options.
References #
Get configured local identity providers
#Description
Records an administrator or application reading the list of local identity providers (the built-in email-, username-, or phone-based sign-up accounts) configured in an Azure AD B2C tenant. The operation is recorded in the B2C audit category and classified as an Authorization activity (the category the B2C audit log describes as authorization to access B2C resources). As a read-only operation it is low-signal alone but can contribute to enumeration of a tenant's identity configuration.
References #
Get custom domains
#Description
Records reading the custom domains configured for an Azure AD B2C tenant, which let sign-in and sign-up pages be served from a customer-owned domain instead of the default Azure AD B2C host. Recorded in the B2C audit category as a read-only Authorization activity; useful as configuration context rather than a standalone detection signal.
References #
Get custom identity provider
#Description
Records reading the configuration of a custom (external) identity provider set up in an Azure AD B2C tenant, such as a social or enterprise provider federated for sign-in. Recorded in the B2C audit category as a read-only Authorization activity.
References #
Get custom policies
#Description
Records an administrator reading the list of Azure AD B2C custom policies (Identity Experience Framework / TrustFramework policies that define user journeys). The B2C audit log gives 'an administrator accessing a list of B2C policies' as its example of an Authorization activity; enumeration of custom policies can be reconnaissance of a tenant's sign-in journeys.
References #
Get custom policy
#Description
Records reading a single Azure AD B2C custom policy, an Identity Experience Framework / TrustFramework policy that defines a sign-in or sign-up user journey. Recorded in the B2C audit category as a read-only Authorization activity.
References #
Get custom policy metadata
#Description
Records reading the metadata of an Azure AD B2C custom policy (an Identity Experience Framework / TrustFramework policy). Recorded in the B2C audit category as a read-only Authorization activity; the precise metadata returned is not detailed in the audit-logs documentation.
References #
Get customAuthenticationExtension
#Description
Records reading the properties of a custom authentication extension, a configuration that calls an external REST endpoint during a user authentication session (for example to augment tokens at token issuance or during attribute collection). Visibility into these reads supports monitoring of authentication-flow configuration, since the external callout can influence the claims that are issued.
References #
Get customAuthenticationExtensions
#Description
Records reading the list of custom authentication extensions configured in the tenant, each defining an external REST callout invoked during a user authentication session such as token issuance or attribute collection. Read-only Authorization activity; enumeration can reveal the external endpoints wired into the sign-in flow.
References #
Get Guest Usages resources
#Description
Records a read of the Azure AD B2C Guest Usages resources (Microsoft.AzureActiveDirectory/guestUsages), the resources that tie a tenant (identified by tenant ID) to an Azure subscription and resource group for monthly-active-user (MAU) billing of guest / external-identities (B2B) usage. As a read it enumerates these billing-linkage resources rather than changing any configuration.
References #
Get Guest Usages resources in a subscription
#Description
Records a read of the Azure AD B2C Guest Usages resources (Microsoft.AzureActiveDirectory/guestUsages) scoped to a specific Azure subscription, enumerating the guest-usage resources under that subscription. Each resource ties a tenant (by tenant ID) to the subscription for monthly-active-user (MAU) billing of guest / external-identities (B2B) usage.
References #
Get Identity Provider
#Description
Records retrieval of a single configured identity provider in an Azure AD B2C tenant (for example a social or external IdP such as Google, Facebook, Microsoft account, or a generic OpenID Connect or SAML provider). Reads of federation configuration are reconnaissance-relevant and are a useful precursor signal alongside identity-provider create or update events.
References #
Get identity provider types
#Description
Records retrieval of the identity provider types available for configuration in Azure AD B2C, the supported provider kinds such as Google, Facebook, Microsoft account, X, and generic OpenID Connect or SAML providers. This is a read of available provider categories rather than the tenant's configured providers.
References #
Get Identity Providers
#Description
Records retrieval (enumeration) of the identity providers configured in an Azure AD B2C tenant. As a read of the tenant's federation configuration it is reconnaissance-relevant and is a useful precursor signal alongside identity-provider create or update events.
Example Audit Log Entry #
{
"AADOperationType": "Read",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:35.870893Z",
"ActivityDisplayName": "Get Identity Providers",
"AdditionalDetails": [
{
"key": "targetTenant",
"value": "00000000-0000-0000-0000-000000000000"
},
{
"key": "targetEntityType",
"value": "None"
},
{
"key": "actorIdentityType",
"value": "UPN"
},
{
"key": "RequiredPermissions",
"value": "Delegated_IdentityProviderRead, Delegated_IdentityProviderReadWrite, Application_IdentityProviderRead, Application_IdentityProviderReadWrite"
},
{
"key": "RequestId",
"value": "8c4cea1b-d146-4bde-a3b8-6b55a95bead2"
}
],
"Category": "Authorization",
"CorrelationId": "8c4cea1b-d146-4bde-a3b8-6b55a95bead2",
"DurationMs": "0",
"Id": "B2C_8c4cea1b-d146-4bde-a3b8-6b55a95bead2_11111111-1111-1111-1111-111111111111_134293368958708930",
"Identity": "adminuser@example.onmicrosoft.com",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": "adminuser@example.onmicrosoft.com",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "B2C",
"OperationName": "Get Identity Providers",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "failure",
"ResultDescription": "Access denied. Client app does not have required app permissions.",
"ResultReason": "Access denied. Client app does not have required app permissions.",
"ResultSignature": "None",
"TargetResources": [
{
"id": null,
"displayName": "00000000-0000-0000-0000-000000000000",
"type": "Other",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Get list of tenants
#Description
Records retrieval of the list of Azure AD B2C tenants, for example the B2C tenants associated with a subscription or otherwise visible to the caller. Enumerating tenants is reconnaissance-relevant for an actor mapping the B2C estate.
References #
Get localized resource
#Description
Records retrieval of a localized resource used by Azure AD B2C user flows or custom policies: the language-customization content (the policy's LocalizedResources, its language-specific strings and collections) that translates sign-up and sign-in pages into a given locale. This is a read of UI localization configuration.
References #
Get OnAttributeCollectionStartCustomExtension
#Description
Records retrieval of the custom authentication extension registered for the OnAttributeCollectionStart event in an Azure AD B2C / External Identities tenant. That event fires at the start of the attribute-collection step of a self-service sign-up flow, before the page renders, and invokes a configured REST API; reading the extension exposes the external endpoint wired into the sign-up flow.
References #
Get OnAttributeCollectionSubmitCustomExtension
#Description
Records retrieval of the custom authentication extension registered for the OnAttributeCollectionSubmit event in an Azure AD B2C / External Identities tenant. That event fires after a user submits attributes during self-service sign-up and invokes a configured REST API to validate or modify the entries; reading the extension exposes the external endpoint wired into the sign-up flow.
References #
Get OnPageRenderStartCustomExtension
#Description
Records retrieval of the custom authentication extension registered for the OnPageRenderStart event in an Azure AD B2C / External Identities tenant. Like the other *CustomExtension operations it names a custom authentication extension (a configured REST-API event listener) bound to a point in the sign-in or sign-up flow, so reading it exposes the external endpoint wired into that flow. The specific OnPageRenderStart trigger point is not individually documented on Microsoft Learn.
References #
Get operation status for an async operation
#Description
Records a read of the status of a long-running (asynchronous) Azure AD B2C operation, the poll a caller issues to check whether a previously submitted operation has completed. Logged under the Authorization category, it is routine control-plane polling and is low-signal on its own.
References #
Get operations of Microsoft.AzureActiveDirectory resource provider
#Description
Records a read of the list of available operations (control-plane actions) exposed by the Microsoft.AzureActiveDirectory Azure resource provider, the ARM resource provider that backs Azure AD B2C directories. This is a metadata/enumeration call typically emitted by the portal or tooling when listing the actions the B2C resource provider supports.
References #
Get policy key
#Description
Records read access to a single Azure AD B2C policy key, a cryptographic secret or certificate stored in an Identity Experience Framework key container (keyset) and used for token signing/encryption or for establishing trust with external identity providers and REST API services. Access to signing/encryption key material is relevant to credential-access monitoring.
References #
Get policy keys
#Description
Records read access to the list of Azure AD B2C policy keys (key containers/keysets) configured in the tenant. Policy keys hold the secrets and certificates the Identity Experience Framework uses for token signing/encryption and trust with integrated services, so enumeration of them is relevant to credential-access and reconnaissance monitoring.
References #
Get resource properties of a tenant
#Description
Records read access to the properties of a B2C tenant resource. Under the B2C Authorization category, this reflects an administrator or service reading configuration properties of the tenant.
References #
Get supported cultures
#Description
Records retrieval of the list of cultures (languages/locales) supported for an Azure AD B2C tenant's user flows and page localization. B2C language customization selects which ISO 639-1 locales a user flow renders in, and this read returns the available set.
References #
Get supported identity providers
#Description
Records retrieval of the list of identity providers supported for configuration in an Azure AD B2C tenant (for example the social and enterprise IdPs that user flows and custom policies can integrate).
References #
Get supported page contracts
#Description
Records retrieval of the supported Azure AD B2C page layout versions ('page contracts') used for custom UI. Page layout packages are the versioned layouts for pages such as selfasserted, unifiedssp, and multifactor that Azure AD B2C periodically updates, and this read returns the supported set.
References #
Get tenant details
#Description
Records retrieval of an Azure AD B2C tenant's detail attributes, typically the directory/tenant attributes read when an administrator accesses the tenant in the Azure portal.
References #
Get tenant domains
#Description
Records retrieval of the list of domains associated with an Azure AD B2C tenant (its verified and onmicrosoft.com domain names).
References #
Get the authenticationEventsPolicy
#Description
Records retrieval of the tenant's authenticationEventsPolicy, the policy object that holds custom authentication extension event listeners (such as an OnTokenIssuanceStart custom claims provider) that invoke external REST APIs during authentication. Reading this configuration is relevant to monitoring custom auth-flow extensions, which can inject claims into issued tokens.
References #
Get user attribute
#Description
Records a read of a single Azure AD B2C user attribute definition (most plausibly a user-flow attribute definition rather than a user's stored profile value). Logged in the Authorization category as authorized administrator or application access to B2C configuration; a read-only operation relevant mainly as configuration enumeration.
References #
Get user attributes
#Description
Records retrieval of the list of Azure AD B2C user attribute definitions (most plausibly user-flow attribute definitions). An Authorization-category B2C read representing authorized access to B2C configuration; useful for detecting enumeration of identity configuration.
References #
Get user flow
#Description
Records a read of a single Azure AD B2C user flow (a sign-up or sign-in policy) configuration. Logged in the Authorization category as authorized access to B2C resources; a read-only operation relevant as configuration reconnaissance.
References #
Get user flows
#Description
Records retrieval of the list of Azure AD B2C user flows (sign-up and sign-in policies). An Authorization-category B2C read of configuration resources that matches the documented example of an administrator accessing a list of B2C policies; benign individually but useful for spotting enumeration.
References #
Get v1 and v2 applications
#Description
Records retrieval of the combined list of legacy (v1) and current (v2, Microsoft identity platform) application registrations in an Azure AD B2C tenant. An Authorization-category B2C read representing enumeration of registered applications.
References #
Get v1 applications
#Description
Records retrieval of the list of legacy (v1) application registrations in an Azure AD B2C tenant. An Authorization-category B2C read of application configuration representing application enumeration.
References #
Get v2 application
#Description
Records a read of a single current (v2, Microsoft identity platform) application registration in an Azure AD B2C tenant. Logged in the Authorization category as authorized access to B2C application configuration.
References #
Initialize tenant
#Description
Records the initialization of an Azure AD B2C tenant, plausibly a bootstrap/provisioning step for the B2C directory. This description is derived only from the operation name, the Authorization category, and the B2C service; Microsoft Learn does not document this specific audit activity, so the exact semantics are not confirmed. Note that the B2C Authorization category is documented as concerning user authorization to access B2C resources, which does not clearly map to tenant provisioning.
References #
Move resources
#Description
Records a move operation on Azure AD B2C resources, logged under the B2C Authorization activity category, which covers activities concerning the authorization of a user to access B2C resources. The exact resource scope is not documented in Microsoft Learn; the entry reflects a management action against B2C resources.
References #
Restore policy key
#Description
An Azure AD B2C Identity Experience Framework policy key (a trustFrameworkKeySet / keyset container holding token-signing or encryption secrets) was restored. Because policy keys hold signing key material, changes to them bear on token-trust integrity.
References #
Retrieve v2 application permissions grants
#Description
A read of application permission grants in the Azure AD B2C tenant was performed. Bulk enumeration of permission grants can support reconnaissance of which applications hold what access.
References #
Retrieve v2 application service principals
#Description
A read of application service principals in the Azure AD B2C tenant was performed. Service-principal enumeration can support reconnaissance of registered applications and their identities.
References #
Update a B2C directory resource
#Description
Records an update to a B2C directory resource in the Azure AD B2C service. An Azure AD B2C directory is represented by an Azure AD B2C resource that is created within and linked to an Azure subscription, so this entry reflects a configuration change to the B2C tenant's resource rather than a sign-in or end-user action.
References #
Update a CIAM directory resource
#Description
Records an update to a CIAM directory resource. CIAM (customer identity and access management) is Microsoft Entra External ID's capability for external-facing apps, delivered through a dedicated external tenant and directory; this entry reflects a change to that External ID (CIAM) directory resource rather than an end-user action.
References #
Update a Guest Usages resource
#Description
Records an update to a 'Guest Usages' resource. In Microsoft Entra External ID and Azure AD B2C, external-identity (guest) usage is metered for monthly-active-user (MAU) billing when a tenant is linked to an Azure subscription, and the Guest Usages resource is the object associated with that external-identity usage linkage. The entry reflects a configuration change to that resource rather than a change to a specific user account.
References #
Update age gating configuration
#Description
Records modification of the age gating configuration in Azure AD B2C, the tenant-level setting that identifies minor users and populates the ageGroup attribute to control whether minors can access applications.
References #
Update API connector
#Description
Records modification of an API connector in Azure AD B2C, which defines the HTTP endpoint URL and authentication used to call an external REST API during a user flow. Because a connector points sign-up or sign-in flows at an external endpoint and exchanges user claims, changes to its target URL or credentials are relevant to tampering with the authentication flow and to data exfiltration.
References #
Update authentication flows policy
#Description
Records a change to the tenant authentication flows policy, which governs authentication-flow settings such as whether self-service sign-up is enabled. Enabling self-service sign-up lets external users create accounts, which is relevant to unauthorized-access and account-creation monitoring.
References #
Update authenticationEventListener
#Description
Records a change to an authentication event listener, which binds custom logic (a custom authentication extension) to a point in the authentication flow such as token issuance or attribute collection. A modified listener can alter issued tokens or invoke an external endpoint during sign-in, relevant to persistence and tampering.
References #
Update authenticationEventsFlow
#Description
Records a change to an authentication events flow, the multi-step user flow used for external-identities self-service sign-up (covering identity providers, attribute collection, and user-creation events). Changes can alter who is allowed to register and how accounts are created.
References #
Update authenticationEventsPolicy
#Description
Records a change to the authentication events policy, the tenant policy that defines the events available in the authentication experience and the custom-logic listeners that can be attached to them (part of Microsoft Entra External ID custom authentication extensions). The audit name alone does not identify the specific change.
References #
Update custom identity provider
#Description
A custom identity provider was updated in Azure AD B2C, enabling user sign-in through an external social or enterprise OpenID Connect or SAML identity provider.
References #
Update custom policy
#Description
An Azure AD B2C custom policy was updated: the Identity Experience Framework TrustFrameworkPolicy XML that defines user journeys and authentication behavior. Changes can alter sign-in logic and are security-relevant.
References #
Update customAuthenticationExtension
#Description
A custom authentication extension was updated. The extension is an event listener that calls a REST API at a point in the authentication flow, such as token issuance start or attribute collection, to run custom business logic.
References #
Update Identity Provider
#Description
Records modification of an external identity provider configuration (a social or enterprise OAuth/OpenID Connect/SAML IdP) in an Azure AD B2C tenant. Changes to federation settings can redirect or weaken customer sign-in trust.
References #
Update local identity provider
#Description
Records a change to the local account identity provider configuration in an Azure AD B2C tenant, which sets the local sign-in identifier types (email, username, or phone) available for user flows. This is distinct from external/social identity provider configuration.
References #
Update OnAttributeCollectionStartCustomExtension
#Description
A custom authentication extension registered for the OnAttributeCollectionStart event was updated. This event fires at the start of attribute collection, before the sign-up attribute page renders, letting a B2C/External ID user flow call an external REST API to prefill values, add attributes, or block sign-up. Tampering with such extensions can alter or bypass sign-up controls.
References #
Update OnAttributeCollectionSubmitCustomExtension
#Description
A custom authentication extension registered for the OnAttributeCollectionSubmit event was updated. This event fires after a user enters and submits attributes during sign-up, letting a B2C/External ID user flow call an external REST API to validate, modify, or block on the submitted values. Tampering with such extensions can weaken sign-up validation.
References #
Update OnPageRenderStartCustomExtension
#Description
A custom authentication extension registered for the OnPageRenderStart event in an Azure AD B2C user flow was updated. By its name the extension point is invoked as a user-flow page begins to render; the specific behavior was not confirmed against a Learn doc.
References #
Update policy key
#Description
A B2C policy key was updated. Policy keys are cryptographic secrets and certificates stored in a key container that the Identity Experience Framework uses to sign or encrypt tokens and establish trust with integrated services.
References #
Update subscription status
#Description
An Azure AD B2C subscription status value was updated. This Authorization-category B2C operation reflects a change to a subscription state associated with the tenant; the precise subscription it refers to is not documented for this specific audit operation.
References #
Update tenant metadata
#Description
An Azure AD B2C tenant metadata value was updated. This Authorization-category B2C operation reflects a change to tenant-level metadata or configuration; the specific fields are not publicly documented.
References #
Update user attribute
#Description
An Azure AD B2C user attribute was modified. User attributes are the built-in profile attributes or custom attributes (custom attributes are directory extension properties) that define what data is collected from and stored about consumer accounts during B2C user-flow sign-up and sign-in.
References #
Update user flow
#Description
An Azure AD B2C user flow was modified. A user flow is a predefined, configurable policy defining a consumer identity experience (sign-up, sign-in, profile edit, or password reset), including sign-in account types, identity providers, attributes collected, multifactor authentication, and the token claims the application receives.
References #
Upload certificate to policy key
#Description
A certificate (or PKCS12 key) was uploaded into an Azure AD B2C policy key (keyset/key container). B2C stores secrets and certificates as policy keys to establish trust for token signing and encryption and for integration with external identity providers and REST APIs, so changes to policy-key material are relevant to token-signing trust and B2C custom-policy integrity.
References #
Upload key to policy key
#Description
An administrator uploaded a certificate or PKCS12 key (an asymmetric key pair) into an Azure AD B2C policy keyset, which B2C uses to establish trust for token signing and encryption and for integration with identity providers or REST APIs. Adding key material to a policy keyset is relevant to monitoring persistence and credential management in the B2C Identity Experience Framework.
References #
Upload secret into policy key
#Description
An administrator stored a manually defined secret (a symmetric key) into an Azure AD B2C policy keyset, used to establish trust with integrated services such as REST APIs or identity providers. Adding secret material to a policy keyset is relevant to credential-management and persistence monitoring of the B2C Identity Experience Framework.
References #
Validate customExtension authenticationConfiguration
#Description
Records validation of a custom authentication extension's authenticationConfiguration: the settings Microsoft Entra ID uses to authenticate to the extension's external REST API endpoint. The check confirms the configured token authentication (for example an Entra-issued token scoped to the API's resource ID) is well-formed before the extension is invoked.
References #
Validate move resources
#Description
Records an authorization check that validates whether a set of resources may be moved before the move proceeds. No Microsoft Learn page specific to this B2C audit operation was located, so it is described conservatively from its name and its Authorization category, without asserting the specific resource type or destination.
References #
Verify if tenant is B2C
#Description
Records a check of whether the target tenant is an Azure AD B2C tenant (a tenant-type determination). No Microsoft Learn page specific to this B2C audit operation was located, so it is described conservatively from its name and its Authorization category.
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.