Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: DirectoryManagement
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add unverified domain | An unverified custom domain was added to the tenant. | N | Y |
| Add verified domain | A verified custom domain was added to the tenant. | N | Y |
| Set Company Information | Tenant company branding/information was changed. | N | Y |
| Set Dir | Directory synchronization was enabled or disabled for the tenant. | N | N |
| Set domain authentication | A domain's authentication type was changed (managed vs federated). | N | Y |
| Set federation settings on domain | Federation settings on a domain were changed (federated-trust backdoor technique). | N | Y |
| Verify domain | A custom domain was verified. | N | Y |
| Verify email verified domain | An email-verified domain was verified. | N | N |
| Add partner to company | A CSP partner (delegated administration) relationship was added to the tenant. | N | N |
| Add shared | Creates a shared email domain invitation in the directory (exact feature undocumented; appears related to cross-tenant email-domain sharing). | N | N |
| Bulk download hardware tokens - finished (bulk) | A bulk job that exports hardware OATH token records from the Entra admin center completed. | N | N |
| Create Company | The company (Entra tenant/organization directory object) was created. | N | N |
| Create company settings | Creation of a tenant-wide directory (company) settings object overriding directory-level defaults in Core Directory. | Y | N |
| Create program | Creation of a legacy access reviews program (container grouping access review controls). | N | N |
| Delete company allowed data location | A configured tenant allowed data location (data-residency geography for data at rest) was removed. | N | N |
| Delete company settings | A tenant-wide directory (company) settings object was deleted. | Y | N |
| Delete subscription | Deletes a subscription object from the directory (Core Directory). | N | N |
| DELETE Subscription. | Authentication Methods service delete operation removing subscription provider entries. | N | N |
| DELETE Tenant. | Authentication Methods service delete operation removing tenant agent-status records. | N | N |
| DELETE Tenant. | Authentication Methods service delete operation removing tenant cache entries. | N | N |
| DELETE Tenant. | Authentication Methods service delete operation removing tenant greeting records. | N | N |
| Delete | Stored Microsoft Entra MFA data was deleted from the MFA backend store. | N | N |
| Delete | Stored Microsoft Entra MFA data was deleted from the Cosmos DB store. | N | N |
| Deleting Source Tenant subscriptions | Subscriptions belonging to a source tenant were deleted in Core Directory. | N | N |
| Demote partner | A partner relationship in the directory was demoted (standing lowered). | N | N |
| Directory deleted | A Microsoft Entra tenant (directory/organization) was deleted, removing all of its resources. | N | N |
| Directory deleted permanently | A Microsoft Entra tenant (directory) was permanently and irrevocably deleted. | N | N |
| Directory scheduled for deletion (Lifecycle) | A tenant (directory) was scheduled for deletion by an automated lifecycle process, pending permanent deletion. | N | N |
| Directory scheduled for deletion (User | A tenant (directory) was scheduled for deletion in response to an administrator deletion request. | N | N |
| Disable application proxy | Microsoft Entra application proxy (on-premises app remote-access publishing) was disabled for the directory. | N | N |
| Disable Desktop Sso | Seamless single sign-on (Desktop SSO) was disabled for the directory. | N | N |
| Disable Desktop Sso for a specific domain | Seamless single sign-on (Desktop SSO) was disabled for a specific AD domain/forest. | N | N |
| Disable passthrough authentication | Microsoft Entra pass-through authentication was disabled for the directory. | N | N |
| Disable password writeback for directory | SSPR password writeback to on-premises Active Directory was disabled for the directory. | N | N |
| Dismiss recommendation | A Microsoft Entra recommendation was dismissed, so it is no longer surfaced as active. | N | N |
| Download registration and reset events - finished (bulk) | A bulk export of the authentication methods registration and reset events report completed. | N | N |
| Download role assignments - finished (bulk) | A bulk export of directory role assignments (who holds which admin roles) completed. | N | N |
| Download service principals - finished (bulk) | A bulk export of the directory's service principals (enterprise apps) completed. | N | N |
| Download user registration details - finished (bulk) | A bulk export of the per-user MFA, passwordless, and SSPR registration details report completed. | N | N |
| Download users - finished (bulk) | A bulk export of the tenant's user list to CSV completed; large pulls can signal directory reconnaissance. | N | N |
| Enable application proxy | The Microsoft Entra application proxy service was enabled for the directory. | N | N |
| Enable Desktop Sso | Microsoft Entra seamless single sign-on (Desktop SSO) was enabled for the directory. | N | N |
| Enable Desktop Sso for a specific domain | Seamless SSO (Desktop SSO) was enabled for a specific on-premises AD domain. | N | N |
| Enable passthrough authentication | Microsoft Entra pass-through authentication (PTA) was enabled for the directory. | N | N |
| Enable password writeback for directory | SSPR password writeback to on-premises Active Directory was enabled for the directory. | N | N |
| Export summary data - finished (bulk) | Records completion of a bulk summary-data export initiated from the Microsoft Entra admin center. | N | N |
| Export summary data new - finished (bulk) | Records completion of a bulk summary-data export using the newer Microsoft Entra admin center export experience. | N | N |
| Export | Export of data from the Azure MFA service backend store (internal, undocumented operation). | N | N |
| Export | Export of data from the Azure Cosmos DB store backing Azure MFA (internal, undocumented operation). | N | N |
| Get cross-cloud verification code for domain | Retrieves a cross-cloud verification code for a directory domain (Core Directory). | N | N |
| Get resources properties of a tenant | Retrieval of a B2C tenant's directory resource properties (a directory-category read in the B2C audit log). | N | N |
| Hard Delete Domain | Permanent deletion of a custom domain from the Entra tenant. | N | N |
| Link program control | Links an access review to an access review program (legacy access reviews programControl). | N | N |
| Mark recommendation as complete | A Microsoft Entra recommendation was marked complete (set automatically once all impacted resources are addressed). | N | N |
| PATCH Tenant. | Internal update (PATCH) to the tenant-level Authentication Methods configuration. | N | N |
| PATCH Tenant. | Internal patch to the tenant-level Authentication Methods configuration cache. | N | N |
| POST Sound | A custom MFA voice-message sound file (.wav/.mp3) was uploaded for phone-call greetings. | N | N |
| POST Subscription. | A Microsoft Entra MFA authentication provider (per-user or per-authentication billing entity) was created. | N | N |
| POST Subscription. | An MFA service subscription (provider-to-Azure-subscription billing association) was created. | N | N |
| POST Tenant. | A user was added to the MFA block list, denying MFA attempts for that account (legacy feature). | N | N |
| POST Tenant. | A one-time MFA bypass was created for a user (single sign-in without completing MFA until it expires). | N | N |
| POST Tenant. | An MFA caching rule (cache type + max seconds for auto-success) was created. | N | N |
| POST Tenant. | A custom MFA phone-call greeting (voice message) was added for the tenant. | N | N |
| POST Tenant. | Initialization of the tenant's configuration record in the Microsoft Entra MFA service (inferred). | N | N |
| POST Tenant. | New activation credentials were generated to activate an on-premises MFA Server against the tenant. | N | N |
| POST Tenant. | A user was removed from the MFA block list (unblocked), re-enabling MFA for that account (legacy feature). | N | N |
| POST Tenant. | A one-time MFA bypass was removed for a user, ending the temporary skip of MFA. | N | N |
| Postpone recommendation | An administrator postponed a Microsoft Entra recommendation, deferring it to a later date. | N | N |
| Promote company to partner | A Core Directory operation promoted the tenant (company) to partner status. | N | N |
| Promote sub domain to root domain | A verified subdomain was promoted to an independent root domain with its own authentication settings. | N | N |
| Remove partner from company | A partner relationship was removed from the tenant, ending a partner organization's administrative link. | N | N |
| Remove unverified domain | An unverified (DNS ownership not confirmed) custom domain was removed from the tenant. | N | N |
| Remove verified domain | A verified (DNS-confirmed) custom domain was removed from the tenant. | N | N |
| Schedule Add shared | A Core Directory background task was scheduled to add a shared email domain to the tenant configuration. | N | N |
| Schedule Remove shared | A Core Directory background task was scheduled to remove a shared email domain from the tenant configuration. | N | N |
| Set accidental deletion threshold | The tenant's accidental-deletion-prevention threshold (max deletions allowed per sync run) was set or changed. | N | N |
| Set company allowed data location | An allowed data location (Microsoft 365 Multi-Geo data residency) was set for the tenant. | N | N |
| Set company multinational feature enabled | The tenant's multinational (Microsoft 365 Multi-Geo) feature was enabled or disabled. | N | N |
| Set directory feature on tenant | A directory-level feature flag was set or modified for the tenant. | N | N |
| Set Dir | A directory synchronization (DirSync) feature flag was set for the tenant. | N | N |
| Set Partnership | A partnership relationship was set or configured in the directory. | N | N |
| Set password policy | The password policy (such as expiration and validity settings) was set for the tenant or a domain. | N | N |
| Soft Delete Domain | A domain was soft-deleted (marked deleted, not permanently removed). | N | N |
| Suspending Source Tenant Subscriptions | Suspends a source tenant's subscriptions, consistent with a tenant-to-tenant subscription transfer. | N | N |
| Unlink program control | An access review control was unlinked from an access reviews program (legacy programs/controls grouping). | N | N |
| Update company | Change to the tenant organization (company) object's directory properties. | N | N |
| Update company settings | Change to tenant-wide directory (company) settings, logged by Core Directory. | Y | N |
| Update Domain | A domain object (settings/authentication type) was updated in the Entra tenant. | N | N |
| Update program | An access review program (legacy container grouping access reviews) was updated. | N | N |
| Update shared | A shared email domain directory object was updated. | N | N |
| Update shared | A shared email domain invitation object was updated. | N | N |
Add unverified domain
#Description
An unverified custom domain was added to the tenant.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Result (kusto rule field) | eq | success | 2 rules | kusto |
azure.auditlogs.properties.category (elastic rule field) | eq | directorymanagement | 1 rule | elastic |
properties.result (splunk rule field) | eq | success | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1584, T1584.001↳ also matches Verify domain Splunk #
T1484, T1484.002Kusto #
T1585, T1585.003↳ also matches Add verified domain T1098
References #
Add verified domain
#Description
A verified custom domain was added to the tenant.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1585, T1585.003↳ also matches Add unverified domain
References #
Set Company Information
#Description
Tenant company branding/information was changed.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1556
References #
Set DirSyncEnabled flag
#Description
Directory synchronization was enabled or disabled for the tenant.
References #
Set domain authentication
#Description
A domain's authentication type was changed (managed vs federated).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
displayName (kusto rule field) | eq | livetype | 3 rules | kusto |
key (kusto rule field) | eq | user-agent | 3 rules | kusto |
NewDomainValue (kusto rule field) | contains | federated | 2 rules | kusto |
azure.auditlogs.properties.category (elastic rule field) | eq | directorymanagement | 1 rule | elastic |
properties.result (splunk rule field) | eq | success | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.001, T1484, T1484.002, T1556, T1556.007↳ also matches Set federation settings on domain Splunk #
T1484, T1484.002Kusto #
T1098, T1555↳ also matches Set federation settings on domain T1098, T1555↳ also matches Set federation settings on domain T1098, T1555↳ also matches Set federation settings on domain
References #
Set federation settings on domain
#Description
Federation settings on a domain were changed (federated-trust backdoor technique).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
displayName (kusto rule field) | eq | livetype | 3 rules | kusto |
key (kusto rule field) | eq | user-agent | 3 rules | kusto |
NewDomainValue (kusto rule field) | contains | federated | 2 rules | kusto |
azure.auditlogs.properties.category (elastic rule field) | eq | directorymanagement | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078Elastic #
T1098, T1098.001, T1484, T1484.002, T1556, T1556.007↳ also matches Set domain authentication Kusto #
T1098, T1555↳ also matches Set domain authentication T1098, T1555↳ also matches Set domain authentication T1098, T1555↳ also matches Set domain authentication
References #
Verify domain
#Description
A custom domain was verified.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.auditlogs.properties.category (elastic rule field) | eq | directorymanagement | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1584, T1584.001↳ also matches Add unverified domain
References #
Add partner to company
#Description
Records the addition of a partner relationship to the tenant, typically a Cloud Solution Provider (CSP) delegated-administration relationship by which an external partner gains administrative access to the directory. Delegated administration (DAP or GDAP) can grant external technicians administrative roles, so a newly added partner expands the external-admin surface and warrants review.
References #
Bulk download hardware tokens - finished (bulk)
#Description
Records that a bulk operation to download (export) hardware OATH token records from the Microsoft Entra admin center finished. Exporting the MFA hardware-token inventory can be relevant to multifactor-authentication reconnaissance.
References #
Create Company
#Description
The company, meaning the Microsoft Entra tenant or organization directory object, was created in Core Directory. This is a foundational directory-provisioning event rather than a routine administrative change.
References #
Create company settings
#Description
A tenant-wide directory settings object (company settings) was created in the Core Directory. These settings are instantiated from a setting template to override directory-level defaults, for example password-rule, consent, prohibited-name, or application settings, so the record is relevant to reviewing org-wide configuration or policy weakening.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:40.5851537Z",
"ActivityDisplayName": "Create company settings",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "DirectoryManagement",
"CorrelationId": "5ed8ff73-0fb9-4a83-9eea-2fe5cca8a4c8",
"DurationMs": "0",
"Id": "Directory_5ed8ff73-0fb9-4a83-9eea-2fe5cca8a4c8_9RYV3_139803344",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Create company settings",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "NCT",
"type": "Directory",
"modifiedProperties": [
{
"displayName": "ObjectSettings",
"oldValue": [
{
"Settings": []
}
],
"newValue": [
{
"Settings": [
{
"Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "false"
}
]
}
]
}
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"ObjectSettings\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Create program
#Description
Records the creation of an access reviews program, a legacy governance container used to group related access review controls for organization and reporting in Microsoft Entra (formerly Azure AD) access reviews.
References #
Delete company allowed data location
#Description
A configured allowed data location for the tenant (company) was removed. An allowed data location designates the geography in which the organization's directory data is stored at rest, part of Microsoft Entra data-residency configuration.
References #
Delete company settings
#Description
A tenant-wide directory settings object (company settings) was deleted. These objects are instantiated from directory settings templates and govern organization-wide directory behaviors.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:42.6592027Z",
"ActivityDisplayName": "Delete company settings",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "DirectoryManagement",
"CorrelationId": "eb2285f2-995b-4971-b6f8-b6aed5198e07",
"DurationMs": "0",
"Id": "Directory_eb2285f2-995b-4971-b6f8-b6aed5198e07_H2DJ9_135895549",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Delete company settings",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "NCT",
"type": "Directory",
"modifiedProperties": [
{
"displayName": "ObjectSettings",
"oldValue": [
{
"Settings": [
{
"Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "true"
}
]
}
]
}
],
"newValue": [
{
"Settings": []
}
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"ObjectSettings\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Delete subscription
#Description
Records the deletion of a subscription object in the directory under the Core Directory service (DirectoryManagement category). The audit activity reference lists the operation but does not document which subscription object is removed, so the precise scope is not authoritatively detailed.
References #
DELETE Subscription.DeleteProviders
#Description
A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes subscription provider entries. The Microsoft Entra audit activity reference lists this internal operation name but does not document the underlying provider objects.
References #
DELETE Tenant.DeleteAgentStatuses
#Description
A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes tenant agent-status records. The Microsoft Entra audit activity reference lists this internal operation name without documenting the underlying objects.
References #
DELETE Tenant.DeleteCaches
#Description
A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes tenant cache entries. The Microsoft Entra audit activity reference lists this internal operation name without documenting the underlying objects.
References #
DELETE Tenant.DeleteGreetings
#Description
A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes tenant greeting records. The Microsoft Entra audit activity reference lists this internal operation name without documenting the underlying objects.
References #
DeleteDataFromBackend
#Description
Records the deletion of stored Microsoft Entra multifactor authentication data from the MFA backend data store. Logged by the Azure MFA service under the DirectoryManagement category.
References #
DeleteDataFromCosmosDb
#Description
Records the deletion of stored Microsoft Entra multifactor authentication data from the service's Cosmos DB data store. Logged by the Azure MFA service under the DirectoryManagement category, paralleling DeleteDataFromBackend for the Cosmos DB store.
References #
Deleting Source Tenant subscriptions
#Description
Records the deletion of subscriptions associated with a source tenant in Core Directory. The 'source tenant' wording and the sibling 'Suspending Source Tenant Subscriptions' activity suggest it occurs during a cross-tenant subscription lifecycle, though the reference states no per-activity prose.
References #
Demote partner
#Description
Records a 'Demote partner' action in Core Directory, lowering a partner's standing or relationship in the directory. Changes to a partner relationship can be relevant to monitoring delegated administrative access. The reference provides no per-activity description.
References #
Directory deleted
#Description
Records the deletion of a Microsoft Entra tenant (directory/organization), an action that removes all resources in the tenant and can only be performed by a Global Administrator. Tenant deletion requires the organization to first pass billing, user, application, and subscription checks.
References #
Directory deleted permanently
#Description
Records the permanent, irrevocable deletion of a Microsoft Entra tenant (directory), removing the organization and all of its resources. As the 'permanently' qualifier indicates, this is the irrevocable counterpart to the initial tenant-deletion operation.
References #
Directory scheduled for deletion (Lifecycle)
#Description
Records that a Microsoft Entra tenant (directory) was placed in a pending-deletion (scheduled) state. The '(Lifecycle)' qualifier indicates the scheduling was driven by an automated system lifecycle process rather than an explicit deletion request, ahead of eventual permanent deletion.
References #
Directory scheduled for deletion (UserRequest)
#Description
Records that a Microsoft Entra tenant (directory) was scheduled for deletion in response to an explicit administrator deletion request, entering a pending-deletion state before permanent removal. Tenant deletion is a Global Administrator action.
References #
Disable application proxy
#Description
Microsoft Entra application proxy was disabled for the directory. Application proxy publishes on-premises web applications for secure remote access through Microsoft Entra ID, so disabling it is a tenant-level configuration change that removes that remote-access publishing capability and is worth monitoring as a security-relevant change.
References #
Disable Desktop Sso
#Description
Microsoft Entra seamless single sign-on (Desktop SSO) was disabled for the directory, turning off automatic sign-in for domain-joined corporate devices on the corporate network. Disabling a hybrid-identity authentication feature is a security-relevant configuration change.
References #
Disable Desktop Sso for a specific domain
#Description
Microsoft Entra seamless single sign-on (Desktop SSO) was disabled for a specific Active Directory domain/forest, removing that domain from the Seamless SSO configuration while leaving other configured domains intact (the Disable-AzureADSSOForest operation).
References #
Disable passthrough authentication
#Description
Microsoft Entra pass-through authentication was disabled for the directory. Pass-through authentication validates user passwords directly against on-premises Active Directory through a lightweight agent, so disabling it changes the tenant's hybrid sign-in method and is a security-relevant configuration change.
References #
Disable password writeback for directory
#Description
Self-service password reset (SSPR) password writeback was disabled for the directory, stopping cloud-initiated password changes and resets from being written back to on-premises Active Directory. Disabling password writeback is a security-relevant configuration change to hybrid SSPR.
References #
Dismiss recommendation
#Description
A Microsoft Entra recommendation was dismissed, changing its status to dismissed so it is no longer surfaced as an active recommendation to act on.
References #
Download registration and reset events - finished (bulk)
#Description
A bulk export of the registration and reset events report, part of the Microsoft Entra authentication methods activity dashboard, completed in the admin center. The report lists individual authentication-method registration and password-reset events (date, user, feature, method used, and status), so an unexpected bulk pull is worth reviewing alongside other directory-read activity.
References #
Download role assignments - finished (bulk)
#Description
A bulk export of Microsoft Entra directory role assignments completed in the admin center, listing which users and service principals hold which administrative roles. Enumerating privileged role holders is a common precursor to privilege-escalation targeting.
References #
Download service principals - finished (bulk)
#Description
A bulk export of the directory's service principals (enterprise applications) completed in the admin center, listing the application identities provisioned in the tenant. Enumerating service principals can support reconnaissance of application-based access paths.
References #
Download user registration details - finished (bulk)
#Description
A bulk export of the user registration details report, part of the Microsoft Entra authentication methods activity dashboard, completed in the admin center. The report lists each user's registered MFA, passwordless, and self-service password reset (SSPR) methods and capability status, revealing which accounts lack strong authentication, information useful for administration and for adversary targeting.
References #
Download users - finished (bulk)
#Description
A bulk export of the directory's user list to CSV completed in the Microsoft Entra admin center, covering user profile attributes such as userPrincipalName, objectId, userType, and accountEnabled. Large-scale enumeration of all users can indicate reconnaissance or data collection by an actor with directory read access.
References #
Enable application proxy
#Description
The Microsoft Entra application proxy service was enabled for the directory, allowing on-premises web applications to be published for secure remote access. Exposing internal applications externally expands the tenant's attack surface and is worth reviewing when unexpected.
References #
Enable Desktop Sso
#Description
Microsoft Entra seamless single sign-on (referred to internally as Desktop SSO) was enabled for the directory, typically configured through Microsoft Entra Connect. Seamless SSO relies on the AZUREADSSOACC computer account in on-premises Active Directory, making changes to it relevant to hybrid-identity security review.
References #
Enable Desktop Sso for a specific domain
#Description
Microsoft Entra seamless single sign-on (Desktop SSO) was enabled for a specific on-premises Active Directory domain, the per-domain variant used when a forest contains multiple domains. Like tenant-wide Desktop SSO, it provisions the AZUREADSSOACC account in the targeted domain, which is relevant to hybrid-identity security review.
References #
Enable passthrough authentication
#Description
Microsoft Entra pass-through authentication (PTA) was enabled as the user sign-in method for the directory, validating passwords directly against on-premises Active Directory through PTA agents. Changes to PTA are security-relevant because a rogue or unexpected authentication agent can intercept credentials.
References #
Enable password writeback for directory
#Description
Self-service password reset (SSPR) password writeback was enabled for the directory, letting password changes made in the cloud be written back to on-premises Active Directory. Because writeback bridges cloud password changes into on-premises AD, enabling it is relevant to hybrid persistence and privilege review.
References #
Export summary data - finished (bulk)
#Description
Records that a bulk export of summary data initiated from the Microsoft Entra admin center completed. The entry reflects an administrator exporting directory summary data through the portal's bulk export experience.
References #
Export summary data new - finished (bulk)
#Description
Records that a bulk export of summary data completed using the newer Microsoft Entra admin center export experience. Like the prior variant, it reflects an administrator exporting directory summary data in bulk through the portal.
References #
ExportDataFromBackend
#Description
Records an export of data from the Azure MFA service backend store. Microsoft does not document this as a tenant-facing feature, so treat it as an internal multifactor-authentication data-export operation surfaced under the DirectoryManagement audit category. The exported scope is not specified, so do not assume a particular data set without confirmation.
References #
ExportDataFromCosmosDb
#Description
Records an export of data from the Azure Cosmos DB store backing the Azure MFA service. Microsoft does not document this as a tenant-facing feature, so treat it as an internal multifactor-authentication data-export operation logged under the DirectoryManagement audit category. The exact records exported are unspecified.
References #
Get cross-cloud verification code for domain
#Description
Records retrieval of a cross-cloud verification code associated with a directory domain, a Core Directory (DirectoryManagement) read that, by its name, relates to validating a domain relationship across separate Microsoft cloud environments. The exact behavior is not documented as a named feature, so the action is described conservatively from its operation name, category, and service.
References #
Get resources properties of a tenant
#Description
Records retrieval of a B2C tenant's directory resource properties. The Azure AD B2C audit-log reference describes its Directory activity type as directory attributes retrieved when an administrator accesses the tenant through the Azure portal, so this read reflects the portal reading tenant/directory properties.
References #
Hard Delete Domain
#Description
Records the permanent (hard) deletion of a custom domain name from the Microsoft Entra tenant. A domain does not support soft delete, so it is hard deleted directly and cannot be restored, only recreated.
References #
Link program control
#Description
Records the creation of a programControl that links an access review to a program in the (now deprecated) Microsoft Entra access reviews API. The programControl object represents the link associating a review with a program.
References #
Mark recommendation as complete
#Description
Records that a Microsoft Entra recommendation's status was set to completed, meaning every impacted resource for that recommendation has been addressed. Microsoft documents that recommendations cannot be marked complete manually: the recommendation service sets this status automatically once all impacted resources are addressed, and completing a recommendation is the only recommendation action captured in the audit log.
References #
PATCH Tenant.Patch
#Description
An internal Authentication Methods service operation that records a patch (update) applied to the tenant-level authentication-methods configuration. The operation name alone does not distinguish which specific tenant setting changed.
References #
PATCH Tenant.PatchCaches
#Description
An internal Authentication Methods service operation that records a patch to the tenant-level authentication-methods configuration cache. It reflects a backend update to cached tenant authentication-method settings rather than a distinct administrator-facing action.
References #
POST SoundFile.Post
#Description
A custom voice-message sound file (.wav or .mp3) was uploaded for use in the tenant's Microsoft Entra multifactor authentication phone-call greetings. The settings page documents this upload as part of the Add greeting flow under Phone call settings.
References #
POST Subscription.CreateProvider
#Description
A Microsoft Entra multifactor authentication provider was created. The provider is the per-user or per-authentication billing entity that extends MFA beyond licensed users; adding new MFA providers has been disabled since September 1, 2018.
References #
POST Subscription.CreateSubscription
#Description
A Microsoft Entra multifactor authentication service subscription was created, associating the MFA authentication provider with the Azure subscription that is billed monthly for per-user or per-authentication MFA usage.
References #
POST Tenant.CreateBlockedUser
#Description
A user was added to the Microsoft Entra multifactor authentication block list, so that MFA attempts for that account are denied. Block/unblock users was a legacy MFA feature that was removed on March 1, 2025, and replaced by Report suspicious activity.
References #
POST Tenant.CreateBypassedUser
#Description
A one-time MFA bypass was created for a user, letting them authenticate a single time without completing multifactor authentication until the bypass expires after a set number of seconds. Because it temporarily removes the second factor, bypass creation is a recognized MFA-circumvention vector worth monitoring.
References #
POST Tenant.CreateCacheConfig
#Description
An MFA caching rule was created, defining a cache type and a maximum number of seconds during which a user's subsequent authentication attempts succeed automatically after their first successful verification. Caching is intended for on-premises systems (such as VPN) that send multiple verification requests, not for sign-ins to Microsoft Entra ID.
References #
POST Tenant.CreateGreeting
#Description
A custom greeting (voice message) was added for the tenant's Microsoft Entra multifactor authentication phone calls, such as a standard greeting or an authentication-successful message. The greeting is configured via the Add greeting flow under Phone call settings.
References #
POST Tenant.CreateTenant
#Description
Records creation or initialization of the tenant's configuration record within the Microsoft Entra (Azure) multifactor authentication service. No Microsoft Learn page documents this as a user-facing action, so the meaning is inferred conservatively from the operation name and the Authentication Methods logging service.
References #
POST Tenant.GenerateNewActivationCredentials
#Description
New activation credentials were generated for the tenant's on-premises Microsoft Entra multifactor authentication Server, used to activate and bind an MFA Server instance to the tenant during initialization. Generating activation credentials lets a new MFA Server register against the tenant, which is worth noting for unexpected on-premises MFA Server provisioning.
References #
POST Tenant.RemoveBlockedUser
#Description
A user was removed from the Microsoft Entra multifactor authentication block list (unblocked), re-enabling MFA attempts for that account. Block/unblock users was a legacy MFA feature removed on March 1, 2025; unblocking a previously blocked account can re-enable access for an account that was blocked due to suspected compromise.
References #
POST Tenant.RemoveBypassedUser
#Description
A one-time MFA bypass entry was removed for a user, ending the temporary allowance to authenticate without completing multifactor authentication before the bypass would otherwise expire.
References #
Postpone recommendation
#Description
Records an administrator postponing a Microsoft Entra recommendation, deferring the recommended action to a later date instead of completing or dismissing it. Postponed is one of the documented recommendation statuses (active, completed, dismissed, postponed).
References #
Promote company to partner
#Description
Records a Core Directory operation that changes the tenant (company) designation to partner status within the directory. The precise effect is not covered by a public Learn reference; the record reflects a change to the organization's partner designation.
References #
Promote sub domain to root domain
#Description
Records promotion of a verified subdomain to an independent root domain, which lets the subdomain be managed with its own authentication type (for example switching between managed and federated) separately from its parent domain. Domain authentication-type changes are relevant to federation-tampering detection.
References #
Remove partner from company
#Description
Records that a partner relationship was removed from the tenant, ending an external partner organization's administrative link to the company. Partner relationships of this kind are associated with delegated administration (such as CSP partners); the reference lists the activity name without detailing the exact relationship type.
References #
Remove unverified domain
#Description
A custom domain that had not yet completed DNS ownership verification was removed from the tenant. This is routine custom-domain management; an added-then-removed unverified domain has little lasting effect since it was never usable for accounts or federation.
References #
Remove verified domain
#Description
A custom domain whose ownership had been confirmed via DNS verification was removed from the tenant. Because verified domains underpin user UPNs and federation, removing one is a significant directory change; domain and federation manipulation is a known persistence and defense-evasion technique, though a domain can be removed only once it is no longer in use.
References #
Set accidental deletion threshold
#Description
Records that the tenant's accidental-deletion-prevention threshold was set or changed. The threshold caps how many objects a single synchronization or provisioning run may delete before deletions are blocked, so raising or disabling it removes a safeguard against mass-deletion (destructive) activity.
References #
Set company allowed data location
#Description
Records that an allowed data location was set for the tenant, part of Microsoft 365 Multi-Geo data-residency configuration that governs which geographies user resources (such as mailboxes and OneDrive) may be stored in. Changes affect where organizational data resides and are relevant to data-residency and compliance monitoring.
References #
Set company multinational feature enabled
#Description
Records that the tenant's multinational (Microsoft 365 Multi-Geo) feature was enabled or disabled. Enabling it lets the organization store in-scope data across multiple geographies within a single tenant based on each user's preferred data location.
References #
Set directory feature on tenant
#Description
A directory-level feature flag was set or modified for the tenant. Tenant-wide directory feature changes affect baseline behavior across the directory and can be relevant as configuration-tampering signals.
References #
Set DirSync feature
#Description
A directory synchronization (DirSync) feature flag was set for the tenant, toggling one of the hybrid-identity sync behaviors (for example, match handling). This is distinct from the separate 'Set DirSyncEnabled flag' on/off toggle, and changes to sync features can weaken hybrid-identity protections and merit review.
References #
Set Partnership
#Description
A partnership relationship was set or configured in the directory. The operation name does not identify the partner type or scope, so this is described conservatively; the specific relationship could not be grounded to a Microsoft Learn doc.
References #
Set password policy
#Description
The password policy was set for the tenant or a domain, covering settings such as password expiration/validity period and expiration-notification window. Weakening the policy, for example extending or disabling password expiration, can support persistence and defense evasion.
References #
Soft Delete Domain
#Description
A domain was soft-deleted, marking it as deleted rather than permanently removing it. Domain deletion or manipulation can disrupt authentication and is relevant to tenant-integrity monitoring.
References #
Suspending Source Tenant Subscriptions
#Description
Records a Core Directory action that suspends the subscriptions belonging to a source tenant, consistent with moving or transferring subscriptions away from that tenant. The precise triggering flow is not described in public Microsoft Learn material.
References #
Unlink program control
#Description
Records that an access review control was unlinked from a program in Microsoft Entra access reviews (the legacy programs-and-controls model for organizing access reviews). The entry reflects a change to how access reviews are grouped rather than a change to any user's access.
References #
Update company
#Description
Records a change to the tenant organization (company) object in the directory, such as organization-level properties. These tenant-level property changes are written to the Core Directory audit logs under DirectoryManagement.
References #
Update company settings
#Description
Records a change to tenant-wide directory (company) settings in Microsoft Entra ID, logged by the Core Directory service under DirectoryManagement. These tenant-level configuration changes are relevant to detecting modifications to directory-wide policy or feature settings.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:41.4863411Z",
"ActivityDisplayName": "Update company settings",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "DirectoryManagement",
"CorrelationId": "ca02f8f3-d508-4724-92e5-e13debb424b0",
"DurationMs": "0",
"Id": "Directory_ca02f8f3-d508-4724-92e5-e13debb424b0_8K2EC_138133951",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update company settings",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "NCT",
"type": "Directory",
"modifiedProperties": [
{
"displayName": "ObjectSettings",
"oldValue": [
{
"Settings": [
{
"Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "false"
}
]
}
]
}
],
"newValue": [
{
"Settings": [
{
"Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "true"
}
]
}
]
}
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"ObjectSettings\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Update Domain
#Description
A domain object in the Microsoft Entra tenant was updated, such as a change to a custom domain's settings or authentication type. Changes to a domain (particularly its federation/authentication settings) are security-relevant, because domain-federation manipulation is a recognized identity-persistence technique.
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.