Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: DeviceManagement

OperationNameDescriptionSampleRule
Bulk add authentication devices - finished (bulk)Completion of an administrator bulk operation that adds authentication devices via the Entra admin center.NN
Download devices - finished (bulk)A bulk export of the tenant's device list to a CSV file finished.NN

Bulk add authentication devices - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DeviceManagement

Description

Records completion of an administrator-initiated bulk operation that adds authentication devices in batch via the Microsoft Entra admin center (Microsoft Entra Management UX); the 'finished (bulk)' suffix marks the asynchronous batch job completing. The exact authentication-device type involved is not independently confirmed.

References #

Download devices - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DeviceManagement

Description

A bulk operation that exports the tenant's device list to a CSV file from the Microsoft Entra admin center finished.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.