Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: CertificateAuthorityEntity
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Create Certificate | A certificate authority was added to the Entra CBA trust store, expanding which certificates can authenticate users. | N | N |
| Delete Certificate | A trusted certificate authority was removed from the tenant's certificate-based authentication trust store. | N | N |
| Hard Delete Certificate | Permanent deletion of a certificate authority from the Entra certificate-based auth trust store. | N | N |
| Restore Certificate | A certificate authority entity in the tenant trust store was restored. | N | N |
| Update Certificate | Change to a certificate authority entity in the Entra CBA trust store. | N | N |
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.