Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: Authorization

OperationNameDescriptionSampleRule
Add v2 application permissionsAdds v2 (identity platform v2) application permissions to an app in an Azure AD B2C tenant.NN
Check whether the resource name is availableB2C checked whether a requested resource (tenant/directory) name is available before creation.NN
Create API connectorAn API connector was created in Azure AD B2C for calling external REST endpoints in user flows.NN
Create authenticationEventListenerAn authenticationEventListener was created, binding an auth event to a custom extension that calls an external REST API at sign-in.NN
Create authenticationEventsFlowAn authenticationEventsFlow (External ID sign-up or sign-in user flow) was created.NN
Create custom identity providerCreation of a custom external identity provider (e.g. OpenID Connect/SAML) for sign-in in an Azure AD B2C tenant.NN
Create custom policyCreation/upload of an Azure AD B2C Identity Experience Framework custom policy defining user journeys and trust-framework behavior.NN
Create customAuthenticationExtensionCreation of a customAuthenticationExtension: a REST callout invoked during authentication events (e.g. token issuance start).NN
Create Identity ProviderAn external identity provider (federation) was created in the Azure AD B2C tenant.YN
Create or update a B2C directory resourceAn Azure AD B2C directory resource was created or updated.NN
Create or update a B2C directory tenant and resourceAn Azure AD B2C directory tenant and its Azure resource were created or updated.NN
Create or update a CIAM directory tenant and resourceA CIAM (Microsoft Entra External ID) directory tenant and its Azure resource were created or updated.NN
Create or update a Guest Usages resourceA Guest Usages resource (subscription linkage for guest/external MAU billing) was created or updated.NN
Create or update localized resourceA localized (language-customization) resource was created or updated in Azure AD B2C.NN
Create policy keyCreation of an Azure AD B2C policy key (keyset cryptographic material) used to sign/encrypt tokens or establish service trust.NN
Create starter packCreation of an Azure AD B2C custom policy (Identity Experience Framework) starter pack.NN
Create user attributeCreation of a custom user attribute (extension attribute) in an Azure AD B2C tenant.NN
Create user flowCreation of an Azure AD B2C user flow (built-in sign-up/sign-in, profile-edit, or password-reset experience).NN
Create v2 applicationRegistration of a v2 (Microsoft identity platform) application in an Azure AD B2C tenant.NN
Delete API connectorAn Azure AD B2C API connector (external REST callout in a user flow) was deleted.NN
Delete authenticationEventlistenerAn authenticationEventListener binding a custom authentication extension to an event was deleted.NN
Delete authenticationEventsFlowAn authenticationEventsFlow (user-flow / multi-event policy) was deleted.NN
Delete B2C directory resourceA resource object within an Azure AD B2C directory was deleted.NN
Delete B2C Tenant where the caller is an administratorAn Azure AD B2C tenant was deleted by an administrator of that tenant.NN
Delete CIAM directory resourceA directory resource was deleted in a CIAM (Entra External ID / Azure AD B2C) customer tenant.NN
Delete custom policyAn Azure AD B2C custom policy (Identity Experience Framework / TrustFramework) was deleted.NN
Delete customAuthenticationExtensionDeletion of a custom authentication extension (REST API extension invoked during an Entra External ID / B2C authentication flow).NN
Delete Guest Usages resourceDeletion of the Guest Usages billing-link resource connecting a B2C / External ID tenant to its MAU billing subscription.NN
Delete Identity ProviderDeletion of an external identity provider configuration (e.g. a social or Apple provider) in B2C / External ID.NN
Delete localized resourceDeletes an Azure AD B2C localized resource (language-specific UI strings) used by a user flow or custom policy.NN
Delete policy keyDeletion of an Azure AD B2C policy key (IEF signing/encryption/secret key container).NN
Delete user attributeDeletes a custom user attribute (schema extension) in an Azure AD B2C tenant.NN
Delete user flowDeletes an Azure AD B2C user flow (sign-up/sign-in/profile policy).NN
Delete v2 applicationDeletes a v2 (Microsoft identity platform) application registration in Azure AD B2C.NN
Delete v2 application permission grantDeletes an OAuth2 permission grant for a v2 application in Azure AD B2C.NN
Generate keyA new Azure AD B2C policy key (token signing or encryption key) was generated in a policy keyset.NN
Get active key metadata from policy keyThe metadata of the active key within an Azure AD B2C policy keyset was read (read-only).NN
Get age gating configurationThe Azure AD B2C age gating configuration (minor identification and access settings) was read.NN
Get API connectorA single Azure AD B2C API connector configuration (REST endpoint used by a user flow) was read.NN
Get API connectorsThe collection of Azure AD B2C API connectors (REST endpoints called by user flows) was listed.NN
Get authentication flows policyThe authenticationFlowsPolicy (tenant self-service sign-up setting) was read.NN
Get authenticationEventListenerA single authenticationEventListener (custom-extension trigger for an auth event) was read.NN
Get authenticationEventsFlowA single authenticationEventsFlow (multi-event user-flow policy) was read.NN
Get authenticationEventsFlowsThe collection of authenticationEventsFlow objects (user-flow policies) was listed.NN
Get available output claimsA caller read the available output claims (token claims) configured in the Azure AD B2C directory.NN
Get B2C directory resourceA single Azure AD B2C directory resource (e.g. a policy or identity provider) was read.NN
Get B2C directory resources in a resource groupB2C directory resources within an Azure resource group were listed.NN
Get B2C directory resources in a subscriptionB2C directory resources across an Azure subscription were listed.NN
Get B2C Tenants where the caller is an administratorAll B2C tenants where the caller is an administrator were enumerated.NN
Get CIAM directory resourceA single CIAM (Entra External ID) directory resource was read.NN
Get CIAM directory resources in a resource groupCIAM (Entra External ID) directory resources within an Azure resource group were listed.NN
Get CIAM directory resources in a subscriptionCIAM (Entra External ID) directory resources across an Azure subscription were listed.NN
Get configured custom identity providersThe custom identity providers configured in the Azure AD B2C directory were read.NN
Get configured identity providersThe identity providers configured in the Azure AD B2C directory were read.NN
Get configured local identity providersReads the local (email/username/phone) identity providers configured in an Azure AD B2C tenant.NN
Get custom domainsReads the custom domains configured for an Azure AD B2C tenant's sign-in pages.NN
Get custom identity providerReads a configured custom (external) identity provider in an Azure AD B2C tenant.NN
Get custom policiesLists the custom (Identity Experience Framework) policies defined in an Azure AD B2C tenant.NN
Get custom policyReads a single Azure AD B2C custom policy (Identity Experience Framework).NN
Get custom policy metadataReads the metadata of an Azure AD B2C custom policy.NN
Get customAuthenticationExtensionReads a custom authentication extension (external REST callout used during authentication).NN
Get customAuthenticationExtensionsLists the custom authentication extensions (external REST callouts) configured in the tenant.NN
Get Guest Usages resourcesRead of the B2C Guest Usages resources (guestUsages) linking a tenant to a subscription for MAU billing of guest/B2B usage.NN
Get Guest Usages resources in a subscriptionRead of B2C Guest Usages resources (guestUsages) under a specific subscription: tenant-to-subscription MAU billing links.NN
Get Identity ProviderRead of a single configured identity provider (social/external IdP) in the B2C tenant.NN
Get identity provider typesRead of the identity provider types available for configuration in B2C (Google, Facebook, OIDC, SAML, etc.).NN
Get Identity ProvidersRead of all identity providers configured in the B2C tenant (federation enumeration).YN
Get list of tenantsRead of the list of Azure AD B2C tenants (e.g., those associated with a subscription).NN
Get localized resourceRead of a B2C localized resource (LocalizedResources language-customization for user flows / custom policies).NN
Get OnAttributeCollectionStartCustomExtensionRead of the custom auth extension for the OnAttributeCollectionStart event (start of sign-up attribute collection).NN
Get OnAttributeCollectionSubmitCustomExtensionRead of the custom auth extension for the OnAttributeCollectionSubmit event (after sign-up attribute submit).NN
Get OnPageRenderStartCustomExtensionRead of the custom auth extension for the OnPageRenderStart event in a B2C / External Identities tenant.NN
Get operation status for an async operationRead of the status of an asynchronous B2C operation (Authorization-category status poll).NN
Get operations of Microsoft.AzureActiveDirectory resource providerRead of the available operations exposed by the Microsoft.AzureActiveDirectory (Azure AD B2C) resource provider.NN
Get policy keyRead of a single B2C policy key (signing/encryption secret or certificate) from an IEF key container.NN
Get policy keysRead of the list of B2C policy keys / key containers configured in the tenant.NN
Get resource properties of a tenantRead of a B2C tenant's resource properties.NN
Get supported culturesRetrieval of the supported cultures (languages/locales) available for B2C user-flow localization.NN
Get supported identity providersRetrieval of the identity providers supported for configuration in the B2C tenant.NN
Get supported page contractsRetrieval of the supported B2C page layout versions ('page contracts') for pages such as selfasserted.NN
Get tenant detailsRetrieval of a B2C tenant's detail attributes.NN
Get tenant domainsRetrieval of the list of domains associated with the B2C tenant.NN
Get the authenticationEventsPolicyRetrieval of the authenticationEventsPolicy holding the tenant's custom authentication extension event listeners.NN
Get user attributeRead of a single Azure AD B2C user attribute definition (Authorization-category B2C read).NN
Get user attributesRead of the list of Azure AD B2C user attribute definitions (Authorization-category B2C read).NN
Get user flowRead of a single Azure AD B2C user flow (sign-up/sign-in policy).NN
Get user flowsRead of the list of Azure AD B2C user flows (sign-up/sign-in policies).NN
Get v1 and v2 applicationsRead of the combined list of v1 and v2 application registrations in an Azure AD B2C tenant.NN
Get v1 applicationsRead of the list of legacy (v1) application registrations in an Azure AD B2C tenant.NN
Get v2 applicationRead of a single v2 (Microsoft identity platform) application registration in an Azure AD B2C tenant.NN
Initialize tenantInitialization of an Azure AD B2C tenant; exact semantics undocumented and inferred from the name.NN
Move resourcesA move operation on Azure AD B2C resources (B2C Authorization activity category).NN
Restore policy keyAn Azure AD B2C Identity Experience Framework policy key (token-signing/encryption secret container) was restored.NN
Retrieve v2 application permissions grantsA read/enumeration of application permission grants in the Azure AD B2C tenant.NN
Retrieve v2 application service principalsA read/enumeration of application service principals in the Azure AD B2C tenant.NN
Update a B2C directory resourceAn Azure AD B2C directory resource (the B2C tenant's linked Azure resource) was updated.NN
Update a CIAM directory resourceA Microsoft Entra External ID (CIAM) directory resource was updated.NN
Update a Guest Usages resourceA 'Guest Usages' external-identity usage/billing resource was updated.NN
Update age gating configurationModification of the Azure AD B2C age gating configuration (identifies minors and controls their access).NN
Update API connectorModification of an Azure AD B2C API connector (external REST endpoint called during user flows).NN
Update authentication flows policyRecords a change to the authentication flows policy controlling whether self-service sign-up is enabled.NN
Update authenticationEventListenerRecords a change to an authentication event listener that binds custom logic to a point in the authentication flow.NN
Update authenticationEventsFlowRecords a change to an authentication events flow (external-identities self-service sign-up user flow).NN
Update authenticationEventsPolicyRecords a change to the authentication events policy defining authentication-experience events and their listeners.NN
Update authorization policyRecords a change to the tenant authorization policy (default user permissions, guest access, and user consent settings).YY
Update custom identity providerAn Azure AD B2C custom (external OIDC/SAML) identity provider was updated.NN
Update custom policyAn Azure AD B2C custom policy (Identity Experience Framework) was updated.NN
Update customAuthenticationExtensionA custom authentication extension (REST API callout in the auth flow) was updated.NN
Update Identity ProviderModification of an external/federated identity provider configuration in an Azure AD B2C tenant.NN
Update local identity providerChange to the local-account identity provider (email/username/phone sign-in) in an Azure AD B2C tenant.NN
Update OnAttributeCollectionStartCustomExtensionA custom authentication extension for the OnAttributeCollectionStart (pre-attribute-collection) event was updated.NN
Update OnAttributeCollectionSubmitCustomExtensionA custom authentication extension for the OnAttributeCollectionSubmit (post-attribute-submit) event was updated.NN
Update OnPageRenderStartCustomExtensionA custom authentication extension for the OnPageRenderStart (page-render) event was updated.NN
Update policy keyA B2C policy key (Identity Experience Framework signing/encryption key) was updated.NN
Update subscription statusAn Azure AD B2C subscription status value was updated.NN
Update tenant metadataAn Azure AD B2C tenant metadata value was updated.NN
Update user attributeAn Azure AD B2C user attribute (built-in profile attribute or custom directory-extension property) was modified.NN
Update user flowAn Azure AD B2C user flow (sign-up/sign-in/profile-edit/password-reset policy) was modified.NN
Upload certificate to policy keyA certificate/PKCS12 key was uploaded into an Azure AD B2C policy key (token-signing/IdP/REST trust material).NN
Upload key to policy keyAdmin uploaded a certificate/PKCS12 (asymmetric) key into an Azure AD B2C policy keyset.NN
Upload secret into policy keyAdmin stored a manually defined secret (symmetric key) into an Azure AD B2C policy keyset.NN
User authorization for application accessUser authorized to access an on-premises app published through Entra application proxy.NN
Validate customExtension authenticationConfigurationValidation of a custom authentication extension's auth config (how Entra authenticates to the extension's REST API endpoint).NN
Validate move resourcesAuthorization pre-check validating whether a set of resources may be moved before the move proceeds.NN
Verify if tenant is B2CCheck of whether the target tenant is an Azure AD B2C tenant (a tenant-type determination).NN

Add v2 application permissions

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the addition of v2 (Microsoft identity platform v2) application permissions to an application in an Azure AD B2C tenant. Application-permission grants broaden an app's access, so they are relevant to monitoring for over-privileged or malicious applications.

References #

Check whether the resource name is available

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Microsoft Entra B2C checked whether a requested resource name (such as a tenant or directory name) is available. This is a name-availability lookup performed while creating or updating a B2C directory resource.

References #

Create API connector

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the creation of an API connector in Azure AD B2C, which calls an external REST endpoint at defined steps of a sign-up (or sign-in) user flow and exchanges user information as claims in an HTTP POST. A malicious or altered connector could exfiltrate user claims or manipulate the sign-up flow.

References #

Create authenticationEventListener

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An authenticationEventListener was created, binding an authentication event such as token issuance or attribute collection to a custom authentication extension that calls an external REST API during sign-in. Because the listener runs inside the authentication flow, a rogue or compromised listener could influence claims or exfiltrate authentication context data.

References #

Create authenticationEventsFlow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An authenticationEventsFlow was created, defining a Microsoft Entra External ID self-service sign-up or sign-in user flow that orchestrates built-in authentication events and can invoke custom authentication extensions.

References #

Create custom identity provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom external identity provider was created in an Azure AD B2C tenant, such as a generic OpenID Connect or SAML provider that lets customers sign in with an external account. It establishes a new federated sign-in path into the B2C tenant.

References #

Create custom policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C custom policy was created (uploaded), an Identity Experience Framework XML configuration that defines user journeys and trust-framework behavior for the B2C tenant. Custom policies fully control authentication flows, so changes are sensitive to sign-in integrity.

References #

Create customAuthenticationExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A customAuthenticationExtension was created via Microsoft Graph, configuring a REST API callout to an external service during authentication events such as token issuance start or attribute collection. It defines an external endpoint and its authentication that participates in the sign-in/token pipeline, introducing an external code path into authentication.

References #

Create Identity Provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An external identity provider was created in the Azure AD B2C tenant, configuring federation (for example social, OAuth/OpenID Connect, or SAML) for customer sign-in. A new federation path changes which credentials can authenticate users and is relevant to authentication-backdoor monitoring.

Example Audit Log Entry #

{
  "AADOperationType": "Create",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:05.099485Z",
  "ActivityDisplayName": "Create Identity Provider",
  "AdditionalDetails": [
    {
      "key": "targetTenant",
      "value": "00000000-0000-0000-0000-000000000000"
    },
    {
      "key": "targetEntityType",
      "value": "None"
    },
    {
      "key": "actorIdentityType",
      "value": "UPN"
    },
    {
      "key": "RequiredPermissions",
      "value": "Delegated_IdentityProviderReadWrite, Application_IdentityProviderReadWrite"
    },
    {
      "key": "RequestId",
      "value": "02f73b30-eaa7-4824-9da8-3f9a4ec084d2"
    }
  ],
  "Category": "Authorization",
  "CorrelationId": "02f73b30-eaa7-4824-9da8-3f9a4ec084d2",
  "DurationMs": "0",
  "Id": "B2C_02f73b30-eaa7-4824-9da8-3f9a4ec084d2_11111111-1111-1111-1111-111111111111_134293368650994850",
  "Identity": "adminuser@example.onmicrosoft.com",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": "adminuser@example.onmicrosoft.com",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "B2C",
  "OperationName": "Create Identity Provider",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "failure",
  "ResultDescription": "Access denied. Client app does not have required app permissions.",
  "ResultReason": "Access denied. Client app does not have required app permissions.",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": null,
      "displayName": "00000000-0000-0000-0000-000000000000",
      "type": "Other",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Create or update a B2C directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C directory resource was created or updated: the Azure resource that represents a B2C tenant and links it to an Azure subscription for billing.

References #

Create or update a B2C directory tenant and resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C directory tenant and its associated Azure resource were created or updated, recording provisioning or reconfiguration of a B2C tenant together with its subscription-linked resource.

References #

Create or update a CIAM directory tenant and resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A CIAM (customer identity, Microsoft Entra External ID for customers) directory tenant and its associated Azure resource were created or updated. CIAM is Microsoft's customer identity access management offering, the successor model to Azure AD B2C.

References #

Create or update a Guest Usages resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A Guest Usages resource was created or updated: the Azure resource that links a Microsoft Entra tenant to an Azure subscription for monthly active users (MAU) billing of guest and external users.

References #

Create or update localized resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A localized resource was created or updated in the Azure AD B2C tenant, the language-customization content (translated user-flow or custom-policy UI strings) used to localize the sign-in and sign-up experience. This is the same action as 'Create or update a localized resource'; the differing audit category reflects the Entra category field, not a different operation.

References #

Create policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the creation of an Azure AD B2C policy key, a cryptographic key (a symmetric secret or an asymmetric certificate/key) stored in a keyset container in the Identity Experience Framework and used to establish trust between services or to sign or encrypt tokens. Unexpected policy-key creation can indicate tampering with B2C custom-policy trust material.

References #

Create starter pack

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the creation of an Azure AD B2C custom policy starter pack: the base set of Identity Experience Framework custom policy files (such as TrustFrameworkBase and TrustFrameworkExtensions) that bootstrap sign-up/sign-in user journeys in the B2C tenant.

References #

Create user attribute

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the creation of a custom user attribute (directory extension attribute) in an Azure AD B2C tenant, which can then be collected as a claim in user flows or custom policies and read/written via the Microsoft Graph API.

References #

Create user flow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the creation of an Azure AD B2C user flow: a built-in, configurable identity experience (such as sign-up/sign-in, profile editing, or password reset) that defines how end users authenticate against the B2C tenant.

References #

Create v2 application

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the registration of an application (app registration) in an Azure AD B2C tenant using the v2 Microsoft identity platform app model. A new application registration establishes a security principal that can request tokens and permissions, so creation events are worth reviewing.

References #

Delete API connector

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C API connector was deleted. API connectors call an external REST endpoint at defined steps of a user flow (for example to validate or enrich data during sign-up), so deleting one removes that external validation or enrichment integration.

References #

Delete authenticationEventlistener

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the deletion of an authenticationEventListener, the object that binds a custom authentication extension (an HTTP callout to an external REST API) to a specific authentication event for one or more applications. Removing a listener stops that custom logic from running during sign-in, which could disable a security control or alter token/claims behavior.

References #

Delete authenticationEventsFlow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the deletion of an authenticationEventsFlow, the multi-event policy (user flow) that holds handler configuration for authentication events such as self-service sign-up and attribute collection in Entra External ID / B2C. Deleting it removes the user-flow definition governing how external users sign up and authenticate.

References #

Delete B2C directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the deletion of a resource object within an Azure AD B2C directory, such as a user flow, identity provider, application, or user. Such deletions are part of routine B2C directory management; removing all of a tenant's resources is also a prerequisite before the B2C tenant itself can be deleted.

References #

Delete B2C Tenant where the caller is an administrator

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the deletion of an Azure AD B2C tenant by a caller holding administrator (Global Administrator) rights over that tenant. Tenant deletion permanently destroys the B2C directory and requires all tenant resources to be removed first.

References #

Delete CIAM directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A directory resource was deleted within a customer identity and access management (CIAM) context, emitted by the B2C / Microsoft Entra External ID logging service for a customer (external) tenant. CIAM is Microsoft's consumer- and business-customer-facing identity platform built on Entra External ID.

References #

Delete custom policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C custom policy was deleted. Custom policies are Identity Experience Framework (TrustFramework) XML configurations that define user journeys and authentication behavior for a B2C tenant.

References #

Delete customAuthenticationExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom authentication extension was deleted. Custom authentication extensions are event-listener / REST API extensions that Microsoft Entra (including External ID and Azure AD B2C) invokes at specific points in an authentication flow, for example to add claims at token issuance or to validate attributes during sign-up, so removing one alters a tenant's authentication pipeline.

References #

Delete Guest Usages resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A Guest Usages resource was deleted. Guest Usages is the linked-subscription billing resource that connects a Microsoft Entra External ID or Azure AD B2C tenant to the Azure subscription used for monthly active user (MAU) billing of external and guest identities. Deleting it removes the billing link only, not the tenant, its users, or its applications.

References #

Delete Identity Provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An external identity provider configuration was deleted in Azure AD B2C or Microsoft Entra External ID. The Microsoft Graph delete identityProvider operation removes a configured provider, such as a social identity provider (for example Google or Facebook) or, in Azure AD B2C, an Apple identity provider. Removing an identity provider stops users from signing in through it.

References #

Delete localized resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records deletion of a localized resource in Azure AD B2C, the language-specific UI strings and collections that a user flow or custom policy loads to support multiple locales. Removing it affects localized sign-up and sign-in experiences.

References #

Delete policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the deletion of an Azure AD B2C policy key, a cryptographic key held in a key container and used by Identity Experience Framework custom policies to sign or encrypt tokens and to store secrets for identity-provider and REST API integrations. Removing signing or encryption keys can disrupt or be used to tamper with B2C authentication.

References #

Delete user attribute

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records deletion of a custom user attribute definition in an Azure AD B2C tenant (Authorization category). Custom attributes extend the B2C user schema for use in user flows, so this removes a directory schema extension.

References #

Delete user flow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records deletion of an Azure AD B2C user flow (Authorization category), the built-in policy that defines a sign-up, sign-in, profile-edit, or password-reset experience. Removing a user flow disrupts the affected authentication journeys for the tenant.

References #

Delete v2 application

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records deletion of a v2 (Microsoft identity platform) application registration in an Azure AD B2C tenant (Authorization category). Application deletion can disrupt dependent authentication or remove evidence of an unauthorized app registration.

References #

Delete v2 application permission grant

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records deletion of an OAuth2 permission grant associated with a v2 (Microsoft identity platform) application in an Azure AD B2C tenant (Authorization category), removing previously consented API permissions for that application.

References #

Generate key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A new Azure AD B2C policy key was generated and added to a policy keyset (key container) in the Identity Experience Framework, producing cryptographic material used to sign or encrypt tokens. New signing material is security-relevant because rogue or forged keys can enable token forgery or persistence.

References #

Get active key metadata from policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

The metadata of the currently active key within an Azure AD B2C policy keyset was read, such as the active key's identifier and activation date. This is a read-only operation against token signing or encryption key configuration and is low risk on its own.

References #

Get age gating configuration

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

The Azure AD B2C age gating configuration was read: the settings that identify minors and control whether they may access an application, with or without parental consent. This is a read-only operation.

References #

Get API connector

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A single Azure AD B2C API connector configuration was read: a REST API endpoint, with its authentication settings, that a user flow calls to integrate external logic during sign-up. This is a read-only operation; reconnaissance of connector endpoints can precede tampering.

References #

Get API connectors

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

The collection of Azure AD B2C API connectors was listed, returning the configured REST API endpoints that user flows can call to integrate external logic during sign-up. This is a read-only operation.

References #

Get authentication flows policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

The authenticationFlowsPolicy was read: the tenant-level policy that controls whether the self-service sign-up experience is enabled. This is a read-only operation.

References #

Get authenticationEventListener

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A single authenticationEventListener was read: a listener that registers custom logic (a custom authentication extension) to run for a specific authentication event under defined conditions. This is a read-only operation.

References #

Get authenticationEventsFlow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A single authenticationEventsFlow was read: a multi-event policy (user flow) that holds the handler configuration for multiple authentication events. This is a read-only operation.

References #

Get authenticationEventsFlows

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

The collection of authenticationEventsFlow objects was listed, returning the multi-event user-flow policies and their configured authentication-event handlers. This is a read-only operation.

References #

Get available output claims

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a caller reading the set of available output claims (the claims that a B2C user flow or custom policy can return in its issued tokens) in the Azure AD B2C directory. This is a read-only Authorization activity; unexpected enumeration of policy claim configuration can indicate reconnaissance of a tenant's identity setup.

References #

Get B2C directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of a single B2C directory resource (for example a policy, identity provider, or other B2C configuration object) in the Azure AD B2C tenant. This is a read-only Authorization activity.

References #

Get B2C directory resources in a resource group

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a list/read of the B2C directory resources contained within an Azure resource group. This is a read-only Authorization activity; bulk enumeration of B2C resources can indicate reconnaissance of the tenant's configuration.

References #

Get B2C directory resources in a subscription

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a list/read of the B2C directory resources across an Azure subscription. This is a read-only Authorization activity; subscription-wide enumeration can indicate reconnaissance of B2C deployments.

References #

Get B2C Tenants where the caller is an administrator

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records enumeration of all B2C tenants for which the calling identity holds administrator rights. This is a read-only Authorization activity; enumerating administered tenants can be a reconnaissance step for an actor mapping accessible B2C directories.

References #

Get CIAM directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of a single CIAM (Microsoft Entra External ID for customers) directory resource in the tenant. This is a read-only Authorization activity.

References #

Get CIAM directory resources in a resource group

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a list/read of the CIAM (Microsoft Entra External ID for customers) directory resources contained within an Azure resource group. This is a read-only Authorization activity; bulk enumeration can indicate reconnaissance.

References #

Get CIAM directory resources in a subscription

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a list/read of the CIAM (Microsoft Entra External ID for customers) directory resources across an Azure subscription. This is a read-only Authorization activity; subscription-wide enumeration can indicate reconnaissance.

References #

Get configured custom identity providers

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of the custom identity providers (for example federated OpenID Connect or SAML providers) configured in the Azure AD B2C directory. This is a read-only Authorization activity; enumerating federated identity providers can reveal trust relationships an actor could target or abuse.

References #

Get configured identity providers

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of the identity providers configured in the Azure AD B2C directory. This is a read-only Authorization activity; enumeration of configured identity providers is a reconnaissance step that maps a tenant's federation and sign-in options.

References #

Get configured local identity providers

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records an administrator or application reading the list of local identity providers (the built-in email-, username-, or phone-based sign-up accounts) configured in an Azure AD B2C tenant. The operation is recorded in the B2C audit category and classified as an Authorization activity (the category the B2C audit log describes as authorization to access B2C resources). As a read-only operation it is low-signal alone but can contribute to enumeration of a tenant's identity configuration.

References #

Get custom domains

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records reading the custom domains configured for an Azure AD B2C tenant, which let sign-in and sign-up pages be served from a customer-owned domain instead of the default Azure AD B2C host. Recorded in the B2C audit category as a read-only Authorization activity; useful as configuration context rather than a standalone detection signal.

References #

Get custom identity provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records reading the configuration of a custom (external) identity provider set up in an Azure AD B2C tenant, such as a social or enterprise provider federated for sign-in. Recorded in the B2C audit category as a read-only Authorization activity.

References #

Get custom policies

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records an administrator reading the list of Azure AD B2C custom policies (Identity Experience Framework / TrustFramework policies that define user journeys). The B2C audit log gives 'an administrator accessing a list of B2C policies' as its example of an Authorization activity; enumeration of custom policies can be reconnaissance of a tenant's sign-in journeys.

References #

Get custom policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records reading a single Azure AD B2C custom policy, an Identity Experience Framework / TrustFramework policy that defines a sign-in or sign-up user journey. Recorded in the B2C audit category as a read-only Authorization activity.

References #

Get custom policy metadata

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records reading the metadata of an Azure AD B2C custom policy (an Identity Experience Framework / TrustFramework policy). Recorded in the B2C audit category as a read-only Authorization activity; the precise metadata returned is not detailed in the audit-logs documentation.

References #

Get customAuthenticationExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records reading the properties of a custom authentication extension, a configuration that calls an external REST endpoint during a user authentication session (for example to augment tokens at token issuance or during attribute collection). Visibility into these reads supports monitoring of authentication-flow configuration, since the external callout can influence the claims that are issued.

References #

Get customAuthenticationExtensions

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records reading the list of custom authentication extensions configured in the tenant, each defining an external REST callout invoked during a user authentication session such as token issuance or attribute collection. Read-only Authorization activity; enumeration can reveal the external endpoints wired into the sign-in flow.

References #

Get Guest Usages resources

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of the Azure AD B2C Guest Usages resources (Microsoft.AzureActiveDirectory/guestUsages), the resources that tie a tenant (identified by tenant ID) to an Azure subscription and resource group for monthly-active-user (MAU) billing of guest / external-identities (B2B) usage. As a read it enumerates these billing-linkage resources rather than changing any configuration.

References #

Get Guest Usages resources in a subscription

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of the Azure AD B2C Guest Usages resources (Microsoft.AzureActiveDirectory/guestUsages) scoped to a specific Azure subscription, enumerating the guest-usage resources under that subscription. Each resource ties a tenant (by tenant ID) to the subscription for monthly-active-user (MAU) billing of guest / external-identities (B2B) usage.

References #

Get Identity Provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of a single configured identity provider in an Azure AD B2C tenant (for example a social or external IdP such as Google, Facebook, Microsoft account, or a generic OpenID Connect or SAML provider). Reads of federation configuration are reconnaissance-relevant and are a useful precursor signal alongside identity-provider create or update events.

References #

Get identity provider types

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the identity provider types available for configuration in Azure AD B2C, the supported provider kinds such as Google, Facebook, Microsoft account, X, and generic OpenID Connect or SAML providers. This is a read of available provider categories rather than the tenant's configured providers.

References #

Get Identity Providers

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval (enumeration) of the identity providers configured in an Azure AD B2C tenant. As a read of the tenant's federation configuration it is reconnaissance-relevant and is a useful precursor signal alongside identity-provider create or update events.

Example Audit Log Entry #

{
  "AADOperationType": "Read",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:35.870893Z",
  "ActivityDisplayName": "Get Identity Providers",
  "AdditionalDetails": [
    {
      "key": "targetTenant",
      "value": "00000000-0000-0000-0000-000000000000"
    },
    {
      "key": "targetEntityType",
      "value": "None"
    },
    {
      "key": "actorIdentityType",
      "value": "UPN"
    },
    {
      "key": "RequiredPermissions",
      "value": "Delegated_IdentityProviderRead, Delegated_IdentityProviderReadWrite, Application_IdentityProviderRead, Application_IdentityProviderReadWrite"
    },
    {
      "key": "RequestId",
      "value": "8c4cea1b-d146-4bde-a3b8-6b55a95bead2"
    }
  ],
  "Category": "Authorization",
  "CorrelationId": "8c4cea1b-d146-4bde-a3b8-6b55a95bead2",
  "DurationMs": "0",
  "Id": "B2C_8c4cea1b-d146-4bde-a3b8-6b55a95bead2_11111111-1111-1111-1111-111111111111_134293368958708930",
  "Identity": "adminuser@example.onmicrosoft.com",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": "adminuser@example.onmicrosoft.com",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "B2C",
  "OperationName": "Get Identity Providers",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "failure",
  "ResultDescription": "Access denied. Client app does not have required app permissions.",
  "ResultReason": "Access denied. Client app does not have required app permissions.",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": null,
      "displayName": "00000000-0000-0000-0000-000000000000",
      "type": "Other",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Get list of tenants

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of Azure AD B2C tenants, for example the B2C tenants associated with a subscription or otherwise visible to the caller. Enumerating tenants is reconnaissance-relevant for an actor mapping the B2C estate.

References #

Get localized resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of a localized resource used by Azure AD B2C user flows or custom policies: the language-customization content (the policy's LocalizedResources, its language-specific strings and collections) that translates sign-up and sign-in pages into a given locale. This is a read of UI localization configuration.

References #

Get OnAttributeCollectionStartCustomExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the custom authentication extension registered for the OnAttributeCollectionStart event in an Azure AD B2C / External Identities tenant. That event fires at the start of the attribute-collection step of a self-service sign-up flow, before the page renders, and invokes a configured REST API; reading the extension exposes the external endpoint wired into the sign-up flow.

References #

Get OnAttributeCollectionSubmitCustomExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the custom authentication extension registered for the OnAttributeCollectionSubmit event in an Azure AD B2C / External Identities tenant. That event fires after a user submits attributes during self-service sign-up and invokes a configured REST API to validate or modify the entries; reading the extension exposes the external endpoint wired into the sign-up flow.

References #

Get OnPageRenderStartCustomExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the custom authentication extension registered for the OnPageRenderStart event in an Azure AD B2C / External Identities tenant. Like the other *CustomExtension operations it names a custom authentication extension (a configured REST-API event listener) bound to a point in the sign-in or sign-up flow, so reading it exposes the external endpoint wired into that flow. The specific OnPageRenderStart trigger point is not individually documented on Microsoft Learn.

References #

Get operation status for an async operation

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of the status of a long-running (asynchronous) Azure AD B2C operation, the poll a caller issues to check whether a previously submitted operation has completed. Logged under the Authorization category, it is routine control-plane polling and is low-signal on its own.

References #

Get operations of Microsoft.AzureActiveDirectory resource provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of the list of available operations (control-plane actions) exposed by the Microsoft.AzureActiveDirectory Azure resource provider, the ARM resource provider that backs Azure AD B2C directories. This is a metadata/enumeration call typically emitted by the portal or tooling when listing the actions the B2C resource provider supports.

References #

Get policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records read access to a single Azure AD B2C policy key, a cryptographic secret or certificate stored in an Identity Experience Framework key container (keyset) and used for token signing/encryption or for establishing trust with external identity providers and REST API services. Access to signing/encryption key material is relevant to credential-access monitoring.

References #

Get policy keys

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records read access to the list of Azure AD B2C policy keys (key containers/keysets) configured in the tenant. Policy keys hold the secrets and certificates the Identity Experience Framework uses for token signing/encryption and trust with integrated services, so enumeration of them is relevant to credential-access and reconnaissance monitoring.

References #

Get resource properties of a tenant

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records read access to the properties of a B2C tenant resource. Under the B2C Authorization category, this reflects an administrator or service reading configuration properties of the tenant.

References #

Get supported cultures

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of cultures (languages/locales) supported for an Azure AD B2C tenant's user flows and page localization. B2C language customization selects which ISO 639-1 locales a user flow renders in, and this read returns the available set.

References #

Get supported identity providers

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of identity providers supported for configuration in an Azure AD B2C tenant (for example the social and enterprise IdPs that user flows and custom policies can integrate).

References #

Get supported page contracts

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the supported Azure AD B2C page layout versions ('page contracts') used for custom UI. Page layout packages are the versioned layouts for pages such as selfasserted, unifiedssp, and multifactor that Azure AD B2C periodically updates, and this read returns the supported set.

References #

Get tenant details

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of an Azure AD B2C tenant's detail attributes, typically the directory/tenant attributes read when an administrator accesses the tenant in the Azure portal.

References #

Get tenant domains

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of domains associated with an Azure AD B2C tenant (its verified and onmicrosoft.com domain names).

References #

Get the authenticationEventsPolicy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the tenant's authenticationEventsPolicy, the policy object that holds custom authentication extension event listeners (such as an OnTokenIssuanceStart custom claims provider) that invoke external REST APIs during authentication. Reading this configuration is relevant to monitoring custom auth-flow extensions, which can inject claims into issued tokens.

References #

Get user attribute

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of a single Azure AD B2C user attribute definition (most plausibly a user-flow attribute definition rather than a user's stored profile value). Logged in the Authorization category as authorized administrator or application access to B2C configuration; a read-only operation relevant mainly as configuration enumeration.

References #

Get user attributes

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of Azure AD B2C user attribute definitions (most plausibly user-flow attribute definitions). An Authorization-category B2C read representing authorized access to B2C configuration; useful for detecting enumeration of identity configuration.

References #

Get user flow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of a single Azure AD B2C user flow (a sign-up or sign-in policy) configuration. Logged in the Authorization category as authorized access to B2C resources; a read-only operation relevant as configuration reconnaissance.

References #

Get user flows

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of Azure AD B2C user flows (sign-up and sign-in policies). An Authorization-category B2C read of configuration resources that matches the documented example of an administrator accessing a list of B2C policies; benign individually but useful for spotting enumeration.

References #

Get v1 and v2 applications

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the combined list of legacy (v1) and current (v2, Microsoft identity platform) application registrations in an Azure AD B2C tenant. An Authorization-category B2C read representing enumeration of registered applications.

References #

Get v1 applications

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records retrieval of the list of legacy (v1) application registrations in an Azure AD B2C tenant. An Authorization-category B2C read of application configuration representing application enumeration.

References #

Get v2 application

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a read of a single current (v2, Microsoft identity platform) application registration in an Azure AD B2C tenant. Logged in the Authorization category as authorized access to B2C application configuration.

References #

Initialize tenant

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records the initialization of an Azure AD B2C tenant, plausibly a bootstrap/provisioning step for the B2C directory. This description is derived only from the operation name, the Authorization category, and the B2C service; Microsoft Learn does not document this specific audit activity, so the exact semantics are not confirmed. Note that the B2C Authorization category is documented as concerning user authorization to access B2C resources, which does not clearly map to tenant provisioning.

References #

Move resources

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a move operation on Azure AD B2C resources, logged under the B2C Authorization activity category, which covers activities concerning the authorization of a user to access B2C resources. The exact resource scope is not documented in Microsoft Learn; the entry reflects a management action against B2C resources.

References #

Restore policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C Identity Experience Framework policy key (a trustFrameworkKeySet / keyset container holding token-signing or encryption secrets) was restored. Because policy keys hold signing key material, changes to them bear on token-trust integrity.

References #

Retrieve v2 application permissions grants

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A read of application permission grants in the Azure AD B2C tenant was performed. Bulk enumeration of permission grants can support reconnaissance of which applications hold what access.

References #

Retrieve v2 application service principals

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A read of application service principals in the Azure AD B2C tenant was performed. Service-principal enumeration can support reconnaissance of registered applications and their identities.

References #

Update a B2C directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records an update to a B2C directory resource in the Azure AD B2C service. An Azure AD B2C directory is represented by an Azure AD B2C resource that is created within and linked to an Azure subscription, so this entry reflects a configuration change to the B2C tenant's resource rather than a sign-in or end-user action.

References #

Update a CIAM directory resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records an update to a CIAM directory resource. CIAM (customer identity and access management) is Microsoft Entra External ID's capability for external-facing apps, delivered through a dedicated external tenant and directory; this entry reflects a change to that External ID (CIAM) directory resource rather than an end-user action.

References #

Update a Guest Usages resource

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records an update to a 'Guest Usages' resource. In Microsoft Entra External ID and Azure AD B2C, external-identity (guest) usage is metered for monthly-active-user (MAU) billing when a tenant is linked to an Azure subscription, and the Guest Usages resource is the object associated with that external-identity usage linkage. The entry reflects a configuration change to that resource rather than a change to a specific user account.

References #

Update age gating configuration

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records modification of the age gating configuration in Azure AD B2C, the tenant-level setting that identifies minor users and populates the ageGroup attribute to control whether minors can access applications.

References #

Update API connector

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records modification of an API connector in Azure AD B2C, which defines the HTTP endpoint URL and authentication used to call an external REST API during a user flow. Because a connector points sign-up or sign-in flows at an external endpoint and exchanges user claims, changes to its target URL or credentials are relevant to tampering with the authentication flow and to data exfiltration.

References #

Update authentication flows policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a change to the tenant authentication flows policy, which governs authentication-flow settings such as whether self-service sign-up is enabled. Enabling self-service sign-up lets external users create accounts, which is relevant to unauthorized-access and account-creation monitoring.

References #

Update authenticationEventListener

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a change to an authentication event listener, which binds custom logic (a custom authentication extension) to a point in the authentication flow such as token issuance or attribute collection. A modified listener can alter issued tokens or invoke an external endpoint during sign-in, relevant to persistence and tampering.

References #

Update authenticationEventsFlow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a change to an authentication events flow, the multi-step user flow used for external-identities self-service sign-up (covering identity providers, attribute collection, and user-creation events). Changes can alter who is allowed to register and how accounts are created.

References #

Update authenticationEventsPolicy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a change to the authentication events policy, the tenant policy that defines the events available in the authentication experience and the custom-logic listeners that can be attached to them (part of Microsoft Entra External ID custom authentication extensions). The audit name alone does not identify the specific change.

References #

Update authorization policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a change to the tenant authorization policy, which governs default user-role permissions (for example whether users can register applications, create tenants, or read other users), the guest-user access level, and user app-consent settings. Loosening these defaults is relevant to privilege escalation and illicit-consent-grant risk.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-06-29T17:56:22.2367171Z",
  "ActivityDisplayName": "Update authorization policy",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
    }
  ],
  "Category": "AuthorizationPolicy",
  "CorrelationId": "bb4cb77c-88d0-40a9-9155-55b9ed0df680",
  "DurationMs": "0",
  "Id": "Directory_bb4cb77c-88d0-40a9-9155-55b9ed0df680_PUEU2_136850026",
  "Identity": "",
  "InitiatedBy": {
    "user": {
      "displayName": null,
      "agentType": "notAgentic",
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": []
    }
  },
  "Level": "",
  "Location": "",
  "LoggedByService": "Core Directory",
  "OperationName": "Update authorization policy",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "ResourceProvider": "",
  "Result": "success",
  "ResultDescription": "",
  "ResultReason": "",
  "ResultSignature": "None",
  "ResultType": "",
  "SourceSystem": "Azure AD",
  "TargetResources": [
    {
      "id": "572101b7-34a1-4db5-bdfb-cae9a7ed7676",
      "displayName": "Authorization Policy",
      "type": "Other",
      "modifiedProperties": [
        {
          "displayName": "BlockMsolPowerShell",
          "oldValue": [],
          "newValue": [
            false
          ]
        },
        {
          "displayName": "Description",
          "oldValue": [],
          "newValue": [
            "Used to manage authorization related settings across the company."
          ]
        },
        {
          "displayName": "DisplayName",
          "oldValue": [],
          "newValue": [
            "Authorization Policy"
          ]
        },
        {
          "displayName": "GuestUserRole",
          "oldValue": [],
          "newValue": [
            "10dae51f-b6af-4016-8d66-8c2a99b929b3"
          ]
        },
        {
          "displayName": "PermissionGrantPolicyIdsAssignedToDefaultUserRole",
          "oldValue": [
            "ManagePermissionGrantsForSelf.microsoft-user-default-recommended",
            "ManagePermissionGrantsForSelf.microsoft-user-default-allow-consent-apps"
          ],
          "newValue": [
            "ManagePermissionGrantsForSelf.microsoft-user-default-recommended",
            "ManagePermissionGrantsForSelf.microsoft-user-default-allow-consent-apps",
            "ManagePermissionGrantsForOwnedResource.microsoft-dynamically-managed-permissions-for-team",
            "ManagePermissionGrantsForOwnedResource.microsoft-dynamically-managed-permissions-for-chat"
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"BlockMsolPowerShell, Description, DisplayName, GuestUserRole, PermissionGrantPolicyIdsAssignedToDefaultUserRole\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ],
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:56:22.2367171Z",
  "Type": "AuditLogs"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
index_number (splunk rule field)ge01 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Update custom identity provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom identity provider was updated in Azure AD B2C, enabling user sign-in through an external social or enterprise OpenID Connect or SAML identity provider.

References #

Update custom policy

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C custom policy was updated: the Identity Experience Framework TrustFrameworkPolicy XML that defines user journeys and authentication behavior. Changes can alter sign-in logic and are security-relevant.

References #

Update customAuthenticationExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom authentication extension was updated. The extension is an event listener that calls a REST API at a point in the authentication flow, such as token issuance start or attribute collection, to run custom business logic.

References #

Update Identity Provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records modification of an external identity provider configuration (a social or enterprise OAuth/OpenID Connect/SAML IdP) in an Azure AD B2C tenant. Changes to federation settings can redirect or weaken customer sign-in trust.

References #

Update local identity provider

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a change to the local account identity provider configuration in an Azure AD B2C tenant, which sets the local sign-in identifier types (email, username, or phone) available for user flows. This is distinct from external/social identity provider configuration.

References #

Update OnAttributeCollectionStartCustomExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom authentication extension registered for the OnAttributeCollectionStart event was updated. This event fires at the start of attribute collection, before the sign-up attribute page renders, letting a B2C/External ID user flow call an external REST API to prefill values, add attributes, or block sign-up. Tampering with such extensions can alter or bypass sign-up controls.

References #

Update OnAttributeCollectionSubmitCustomExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom authentication extension registered for the OnAttributeCollectionSubmit event was updated. This event fires after a user enters and submits attributes during sign-up, letting a B2C/External ID user flow call an external REST API to validate, modify, or block on the submitted values. Tampering with such extensions can weaken sign-up validation.

References #

Update OnPageRenderStartCustomExtension

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A custom authentication extension registered for the OnPageRenderStart event in an Azure AD B2C user flow was updated. By its name the extension point is invoked as a user-flow page begins to render; the specific behavior was not confirmed against a Learn doc.

References #

Update policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A B2C policy key was updated. Policy keys are cryptographic secrets and certificates stored in a key container that the Identity Experience Framework uses to sign or encrypt tokens and establish trust with integrated services.

References #

Update subscription status

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C subscription status value was updated. This Authorization-category B2C operation reflects a change to a subscription state associated with the tenant; the precise subscription it refers to is not documented for this specific audit operation.

References #

Update tenant metadata

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C tenant metadata value was updated. This Authorization-category B2C operation reflects a change to tenant-level metadata or configuration; the specific fields are not publicly documented.

References #

Update user attribute

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C user attribute was modified. User attributes are the built-in profile attributes or custom attributes (custom attributes are directory extension properties) that define what data is collected from and stored about consumer accounts during B2C user-flow sign-up and sign-in.

References #

Update user flow

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An Azure AD B2C user flow was modified. A user flow is a predefined, configurable policy defining a consumer identity experience (sign-up, sign-in, profile edit, or password reset), including sign-in account types, identity providers, attributes collected, multifactor authentication, and the token claims the application receives.

References #

Upload certificate to policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

A certificate (or PKCS12 key) was uploaded into an Azure AD B2C policy key (keyset/key container). B2C stores secrets and certificates as policy keys to establish trust for token signing and encryption and for integration with external identity providers and REST APIs, so changes to policy-key material are relevant to token-signing trust and B2C custom-policy integrity.

References #

Upload key to policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An administrator uploaded a certificate or PKCS12 key (an asymmetric key pair) into an Azure AD B2C policy keyset, which B2C uses to establish trust for token signing and encryption and for integration with identity providers or REST APIs. Adding key material to a policy keyset is relevant to monitoring persistence and credential management in the B2C Identity Experience Framework.

References #

Upload secret into policy key

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

An administrator stored a manually defined secret (a symmetric key) into an Azure AD B2C policy keyset, used to establish trust with integrated services such as REST APIs or identity providers. Adding secret material to a policy keyset is relevant to credential-management and persistence monitoring of the B2C Identity Experience Framework.

References #

User authorization for application access

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records authorization of a user to access an on-premises or internal application published through Microsoft Entra application proxy, capturing the access decision for that user against the published application.

References #

Validate customExtension authenticationConfiguration

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records validation of a custom authentication extension's authenticationConfiguration: the settings Microsoft Entra ID uses to authenticate to the extension's external REST API endpoint. The check confirms the configured token authentication (for example an Entra-issued token scoped to the API's resource ID) is well-formed before the extension is invoked.

References #

Validate move resources

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records an authorization check that validates whether a set of resources may be moved before the move proceeds. No Microsoft Learn page specific to this B2C audit operation was located, so it is described conservatively from its name and its Authorization category, without asserting the specific resource type or destination.

References #

Verify if tenant is B2C

#
Source
Microsoft Entra ID audit log
Audit Category
Authorization

Description

Records a check of whether the target tenant is an Azure AD B2C tenant (a tenant-type determination). No Microsoft Learn page specific to this B2C audit operation was located, so it is described conservatively from its name and its Authorization category.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.