Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: CertBasedConfiguration

OperationNameDescriptionSampleRule
Add CertBasedAuthConfigurationA certificate-based authentication configuration (CBA settings, e.g. trusted CAs) was created in the directory.NN
Hard delete CertificationBasedAuthConfigurationPermanent deletion of the trusted-CA collection used for Entra certificate-based authentication.NN

Add CertBasedAuthConfiguration

#
Source
Microsoft Entra ID audit log
Audit Category
CertBasedConfiguration

Description

A certificate-based authentication configuration was created in the directory, defining settings used to validate user X.509 certificates for sign-in, including the trusted certificate authorities. Adding or altering trusted CAs is security-sensitive because it governs which certificates are accepted for authentication, and a rogue CA could enable certificate-based authentication abuse.

References #

Hard delete CertificationBasedAuthConfiguration

#
Source
Microsoft Entra ID audit log
Audit Category
CertBasedConfiguration

Description

Records the permanent (hard) deletion of the certificateBasedAuthConfiguration object, the collection of trusted certificate authorities Microsoft Entra uses to validate the certificate chain for certificate-based authentication. This configuration can only be changed by deleting and recreating it, so the event can be routine reconfiguration or indicate tampering with the CBA trust anchor.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.