Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: DirectoryManagement

OperationNameDescriptionSampleRule
Add unverified domainAn unverified custom domain was added to the tenant.NY
Add verified domainA verified custom domain was added to the tenant.NY
Set Company InformationTenant company branding/information was changed.NY
Set DirSyncEnabled flagDirectory synchronization was enabled or disabled for the tenant.NN
Set domain authenticationA domain's authentication type was changed (managed vs federated).NY
Set federation settings on domainFederation settings on a domain were changed (federated-trust backdoor technique).NY
Verify domainA custom domain was verified.NY
Verify email verified domainAn email-verified domain was verified.NN
Add partner to companyA CSP partner (delegated administration) relationship was added to the tenant.NN
Add sharedEmailDomainInvitationCreates a shared email domain invitation in the directory (exact feature undocumented; appears related to cross-tenant email-domain sharing).NN
Bulk download hardware tokens - finished (bulk)A bulk job that exports hardware OATH token records from the Entra admin center completed.NN
Create CompanyThe company (Entra tenant/organization directory object) was created.NN
Create company settingsCreation of a tenant-wide directory (company) settings object overriding directory-level defaults in Core Directory.YN
Create programCreation of a legacy access reviews program (container grouping access review controls).NN
Delete company allowed data locationA configured tenant allowed data location (data-residency geography for data at rest) was removed.NN
Delete company settingsA tenant-wide directory (company) settings object was deleted.YN
Delete subscriptionDeletes a subscription object from the directory (Core Directory).NN
DELETE Subscription.DeleteProvidersAuthentication Methods service delete operation removing subscription provider entries.NN
DELETE Tenant.DeleteAgentStatusesAuthentication Methods service delete operation removing tenant agent-status records.NN
DELETE Tenant.DeleteCachesAuthentication Methods service delete operation removing tenant cache entries.NN
DELETE Tenant.DeleteGreetingsAuthentication Methods service delete operation removing tenant greeting records.NN
DeleteDataFromBackendStored Microsoft Entra MFA data was deleted from the MFA backend store.NN
DeleteDataFromCosmosDbStored Microsoft Entra MFA data was deleted from the Cosmos DB store.NN
Deleting Source Tenant subscriptionsSubscriptions belonging to a source tenant were deleted in Core Directory.NN
Demote partnerA partner relationship in the directory was demoted (standing lowered).NN
Directory deletedA Microsoft Entra tenant (directory/organization) was deleted, removing all of its resources.NN
Directory deleted permanentlyA Microsoft Entra tenant (directory) was permanently and irrevocably deleted.NN
Directory scheduled for deletion (Lifecycle)A tenant (directory) was scheduled for deletion by an automated lifecycle process, pending permanent deletion.NN
Directory scheduled for deletion (UserRequest)A tenant (directory) was scheduled for deletion in response to an administrator deletion request.NN
Disable application proxyMicrosoft Entra application proxy (on-premises app remote-access publishing) was disabled for the directory.NN
Disable Desktop SsoSeamless single sign-on (Desktop SSO) was disabled for the directory.NN
Disable Desktop Sso for a specific domainSeamless single sign-on (Desktop SSO) was disabled for a specific AD domain/forest.NN
Disable passthrough authenticationMicrosoft Entra pass-through authentication was disabled for the directory.NN
Disable password writeback for directorySSPR password writeback to on-premises Active Directory was disabled for the directory.NN
Dismiss recommendationA Microsoft Entra recommendation was dismissed, so it is no longer surfaced as active.NN
Download registration and reset events - finished (bulk)A bulk export of the authentication methods registration and reset events report completed.NN
Download role assignments - finished (bulk)A bulk export of directory role assignments (who holds which admin roles) completed.NN
Download service principals - finished (bulk)A bulk export of the directory's service principals (enterprise apps) completed.NN
Download user registration details - finished (bulk)A bulk export of the per-user MFA, passwordless, and SSPR registration details report completed.NN
Download users - finished (bulk)A bulk export of the tenant's user list to CSV completed; large pulls can signal directory reconnaissance.NN
Enable application proxyThe Microsoft Entra application proxy service was enabled for the directory.NN
Enable Desktop SsoMicrosoft Entra seamless single sign-on (Desktop SSO) was enabled for the directory.NN
Enable Desktop Sso for a specific domainSeamless SSO (Desktop SSO) was enabled for a specific on-premises AD domain.NN
Enable passthrough authenticationMicrosoft Entra pass-through authentication (PTA) was enabled for the directory.NN
Enable password writeback for directorySSPR password writeback to on-premises Active Directory was enabled for the directory.NN
Export summary data - finished (bulk)Records completion of a bulk summary-data export initiated from the Microsoft Entra admin center.NN
Export summary data new - finished (bulk)Records completion of a bulk summary-data export using the newer Microsoft Entra admin center export experience.NN
ExportDataFromBackendExport of data from the Azure MFA service backend store (internal, undocumented operation).NN
ExportDataFromCosmosDbExport of data from the Azure Cosmos DB store backing Azure MFA (internal, undocumented operation).NN
Get cross-cloud verification code for domainRetrieves a cross-cloud verification code for a directory domain (Core Directory).NN
Get resources properties of a tenantRetrieval of a B2C tenant's directory resource properties (a directory-category read in the B2C audit log).NN
Hard Delete DomainPermanent deletion of a custom domain from the Entra tenant.NN
Link program controlLinks an access review to an access review program (legacy access reviews programControl).NN
Mark recommendation as completeA Microsoft Entra recommendation was marked complete (set automatically once all impacted resources are addressed).NN
PATCH Tenant.PatchInternal update (PATCH) to the tenant-level Authentication Methods configuration.NN
PATCH Tenant.PatchCachesInternal patch to the tenant-level Authentication Methods configuration cache.NN
POST SoundFile.PostA custom MFA voice-message sound file (.wav/.mp3) was uploaded for phone-call greetings.NN
POST Subscription.CreateProviderA Microsoft Entra MFA authentication provider (per-user or per-authentication billing entity) was created.NN
POST Subscription.CreateSubscriptionAn MFA service subscription (provider-to-Azure-subscription billing association) was created.NN
POST Tenant.CreateBlockedUserA user was added to the MFA block list, denying MFA attempts for that account (legacy feature).NN
POST Tenant.CreateBypassedUserA one-time MFA bypass was created for a user (single sign-in without completing MFA until it expires).NN
POST Tenant.CreateCacheConfigAn MFA caching rule (cache type + max seconds for auto-success) was created.NN
POST Tenant.CreateGreetingA custom MFA phone-call greeting (voice message) was added for the tenant.NN
POST Tenant.CreateTenantInitialization of the tenant's configuration record in the Microsoft Entra MFA service (inferred).NN
POST Tenant.GenerateNewActivationCredentialsNew activation credentials were generated to activate an on-premises MFA Server against the tenant.NN
POST Tenant.RemoveBlockedUserA user was removed from the MFA block list (unblocked), re-enabling MFA for that account (legacy feature).NN
POST Tenant.RemoveBypassedUserA one-time MFA bypass was removed for a user, ending the temporary skip of MFA.NN
Postpone recommendationAn administrator postponed a Microsoft Entra recommendation, deferring it to a later date.NN
Promote company to partnerA Core Directory operation promoted the tenant (company) to partner status.NN
Promote sub domain to root domainA verified subdomain was promoted to an independent root domain with its own authentication settings.NN
Remove partner from companyA partner relationship was removed from the tenant, ending a partner organization's administrative link.NN
Remove unverified domainAn unverified (DNS ownership not confirmed) custom domain was removed from the tenant.NN
Remove verified domainA verified (DNS-confirmed) custom domain was removed from the tenant.NN
Schedule Add sharedEmailDomainA Core Directory background task was scheduled to add a shared email domain to the tenant configuration.NN
Schedule Remove sharedEmailDomainA Core Directory background task was scheduled to remove a shared email domain from the tenant configuration.NN
Set accidental deletion thresholdThe tenant's accidental-deletion-prevention threshold (max deletions allowed per sync run) was set or changed.NN
Set company allowed data locationAn allowed data location (Microsoft 365 Multi-Geo data residency) was set for the tenant.NN
Set company multinational feature enabledThe tenant's multinational (Microsoft 365 Multi-Geo) feature was enabled or disabled.NN
Set directory feature on tenantA directory-level feature flag was set or modified for the tenant.NN
Set DirSync featureA directory synchronization (DirSync) feature flag was set for the tenant.NN
Set PartnershipA partnership relationship was set or configured in the directory.NN
Set password policyThe password policy (such as expiration and validity settings) was set for the tenant or a domain.NN
Soft Delete DomainA domain was soft-deleted (marked deleted, not permanently removed).NN
Suspending Source Tenant SubscriptionsSuspends a source tenant's subscriptions, consistent with a tenant-to-tenant subscription transfer.NN
Unlink program controlAn access review control was unlinked from an access reviews program (legacy programs/controls grouping).NN
Update companyChange to the tenant organization (company) object's directory properties.NN
Update company settingsChange to tenant-wide directory (company) settings, logged by Core Directory.YN
Update DomainA domain object (settings/authentication type) was updated in the Entra tenant.NN
Update programAn access review program (legacy container grouping access reviews) was updated.NN
Update sharedEmailDomainA shared email domain directory object was updated.NN
Update sharedEmailDomainInvitationA shared email domain invitation object was updated.NN

Add unverified domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

An unverified custom domain was added to the tenant.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Result (kusto rule field)eqsuccess2 ruleskusto
azure.auditlogs.properties.category (elastic rule field)eqdirectorymanagement1 ruleelastic
properties.result (splunk rule field)eqsuccess1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Entra ID Custom Domain Added or Verified source low: Detects when a custom domain is added or verified in an Entra ID tenant. Adding and verifying a custom domain are precursor steps to configuring domain federation, which can be abused by adversaries to route authentication through an attacker-controlled identity provider (Golden SAML). In most organizations, custom domains are added infrequently and these events should be investigated to ensure they are part of a legitimate administrative workflow.T1584, T1584.001↳ also matches Verify domain

Splunk #

  • Azure AD New Custom Domain Added source: The following analytic detects the addition of a new custom domain within an Azure Active Directory (AD) tenant. It leverages Azure AD AuditLogs to identify successful "Add unverified domain" operations. This activity is significant as it…T1484, T1484.002

Kusto #

  • New onmicrosoft domain added to tenant source medium: This detection looks for new onmicrosoft domains being added to a tenant. An attacker who compromises a tenant may register a new onmicrosoft domain in order to masquerade as a service provider for launching phishing campaigns. Domain additions are not a common occurrence and users should validate that the domain was added by a legitimate user, with a legitimate purpose.T1585, T1585.003↳ also matches Add verified domain
  • Possible SignIn from Azure Backdoor source medium: Identifies when a user adds an unverified domain as an authentication method, followed by a sign-in from a user the newly added domain. Threat actors may add custom domains to create a backdoor to your tenant. It's important to monitor whenever custom domains are added to the tenant.T1098

References #

Add verified domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A verified custom domain was added to the tenant.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • New onmicrosoft domain added to tenant source medium: This detection looks for new onmicrosoft domains being added to a tenant. An attacker who compromises a tenant may register a new onmicrosoft domain in order to masquerade as a service provider for launching phishing campaigns. Domain additions are not a common occurrence and users should validate that the domain was added by a legitimate user, with a legitimate purpose.T1585, T1585.003↳ also matches Add unverified domain

References #

Set Company Information

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Tenant company branding/information was changed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Set DirSyncEnabled flag

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Directory synchronization was enabled or disabled for the tenant.

References #

Set domain authentication

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A domain's authentication type was changed (managed vs federated).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
displayName (kusto rule field)eqlivetype3 ruleskusto
key (kusto rule field)equser-agent3 ruleskusto
NewDomainValue (kusto rule field)containsfederated2 ruleskusto
azure.auditlogs.properties.category (elastic rule field)eqdirectorymanagement1 ruleelastic
properties.result (splunk rule field)eqsuccess1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Entra ID Domain Federation Configuration Change source high: Detects when domain federation settings are configured or modified in an Entra ID tenant via the Microsoft Graph API. Adversaries with Global Administrator or Domain Administrator privileges may add a custom domain, verify ownership, and configure it to federate authentication with an attacker-controlled identity provider. Once federated, the adversary can forge SAML or WS-Federation tokens to authenticate as any user under that domain, bypassing MFA and conditional access policies. This technique, commonly known as Golden SAML, was used by UNC2452 (APT29) during the SolarWinds campaign for persistent, stealthy access to victim tenants.T1098, T1098.001, T1484, T1484.002, T1556, T1556.007↳ also matches Set federation settings on domain

Splunk #

  • Azure AD New Federated Domain Added source: The following analytic detects the addition of a new federated domain within an Azure Active Directory tenant. It leverages Azure AD AuditLogs to identify successful "Set domain authentication" operations. This activity is significant as…T1484, T1484.002

Kusto #

References #

Set federation settings on domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Federation settings on a domain were changed (federated-trust backdoor technique).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
displayName (kusto rule field)eqlivetype3 ruleskusto
key (kusto rule field)equser-agent3 ruleskusto
NewDomainValue (kusto rule field)containsfederated2 ruleskusto
azure.auditlogs.properties.category (elastic rule field)eqdirectorymanagement1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID Domain Federation Configuration Change source high: Detects when domain federation settings are configured or modified in an Entra ID tenant via the Microsoft Graph API. Adversaries with Global Administrator or Domain Administrator privileges may add a custom domain, verify ownership, and configure it to federate authentication with an attacker-controlled identity provider. Once federated, the adversary can forge SAML or WS-Federation tokens to authenticate as any user under that domain, bypassing MFA and conditional access policies. This technique, commonly known as Golden SAML, was used by UNC2452 (APT29) during the SolarWinds campaign for persistent, stealthy access to victim tenants.T1098, T1098.001, T1484, T1484.002, T1556, T1556.007↳ also matches Set domain authentication

Kusto #

References #

Verify domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A custom domain was verified.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.auditlogs.properties.category (elastic rule field)eqdirectorymanagement1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Entra ID Custom Domain Added or Verified source low: Detects when a custom domain is added or verified in an Entra ID tenant. Adding and verifying a custom domain are precursor steps to configuring domain federation, which can be abused by adversaries to route authentication through an attacker-controlled identity provider (Golden SAML). In most organizations, custom domains are added infrequently and these events should be investigated to ensure they are part of a legitimate administrative workflow.T1584, T1584.001↳ also matches Add unverified domain

References #

Verify email verified domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

An email-verified domain was verified.

References #

Add partner to company

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the addition of a partner relationship to the tenant, typically a Cloud Solution Provider (CSP) delegated-administration relationship by which an external partner gains administrative access to the directory. Delegated administration (DAP or GDAP) can grant external technicians administrative roles, so a newly added partner expands the external-admin surface and warrants review.

References #

Add sharedEmailDomainInvitation

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records creation of a shared email domain invitation object in the directory. The specific capability is not documented on Microsoft Learn; based on the operation name and DirectoryManagement category, it appears to register an invitation associated with sharing an email domain (for example across tenants in a multitenant organization).

References #

Bulk download hardware tokens - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a bulk operation to download (export) hardware OATH token records from the Microsoft Entra admin center finished. Exporting the MFA hardware-token inventory can be relevant to multifactor-authentication reconnaissance.

References #

Create Company

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

The company, meaning the Microsoft Entra tenant or organization directory object, was created in Core Directory. This is a foundational directory-provisioning event rather than a routine administrative change.

References #

Create company settings

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A tenant-wide directory settings object (company settings) was created in the Core Directory. These settings are instantiated from a setting template to override directory-level defaults, for example password-rule, consent, prohibited-name, or application settings, so the record is relevant to reviewing org-wide configuration or policy weakening.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:40.5851537Z",
  "ActivityDisplayName": "Create company settings",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "DirectoryManagement",
  "CorrelationId": "5ed8ff73-0fb9-4a83-9eea-2fe5cca8a4c8",
  "DurationMs": "0",
  "Id": "Directory_5ed8ff73-0fb9-4a83-9eea-2fe5cca8a4c8_9RYV3_139803344",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Create company settings",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "NCT",
      "type": "Directory",
      "modifiedProperties": [
        {
          "displayName": "ObjectSettings",
          "oldValue": [
            {
              "Settings": []
            }
          ],
          "newValue": [
            {
              "Settings": [
                {
                  "Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
                  "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
                  "Properties": [
                    {
                      "Key": "EnableMSStandardBlockedWords",
                      "Value": "false"
                    }
                  ]
                }
              ]
            }
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"ObjectSettings\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Create program

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the creation of an access reviews program, a legacy governance container used to group related access review controls for organization and reporting in Microsoft Entra (formerly Azure AD) access reviews.

References #

Delete company allowed data location

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A configured allowed data location for the tenant (company) was removed. An allowed data location designates the geography in which the organization's directory data is stored at rest, part of Microsoft Entra data-residency configuration.

References #

Delete company settings

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A tenant-wide directory settings object (company settings) was deleted. These objects are instantiated from directory settings templates and govern organization-wide directory behaviors.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:42.6592027Z",
  "ActivityDisplayName": "Delete company settings",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "DirectoryManagement",
  "CorrelationId": "eb2285f2-995b-4971-b6f8-b6aed5198e07",
  "DurationMs": "0",
  "Id": "Directory_eb2285f2-995b-4971-b6f8-b6aed5198e07_H2DJ9_135895549",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Delete company settings",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "NCT",
      "type": "Directory",
      "modifiedProperties": [
        {
          "displayName": "ObjectSettings",
          "oldValue": [
            {
              "Settings": [
                {
                  "Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
                  "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
                  "Properties": [
                    {
                      "Key": "EnableMSStandardBlockedWords",
                      "Value": "true"
                    }
                  ]
                }
              ]
            }
          ],
          "newValue": [
            {
              "Settings": []
            }
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"ObjectSettings\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Delete subscription

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the deletion of a subscription object in the directory under the Core Directory service (DirectoryManagement category). The audit activity reference lists the operation but does not document which subscription object is removed, so the precise scope is not authoritatively detailed.

References #

DELETE Subscription.DeleteProviders

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes subscription provider entries. The Microsoft Entra audit activity reference lists this internal operation name but does not document the underlying provider objects.

References #

DELETE Tenant.DeleteAgentStatuses

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes tenant agent-status records. The Microsoft Entra audit activity reference lists this internal operation name without documenting the underlying objects.

References #

DELETE Tenant.DeleteCaches

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes tenant cache entries. The Microsoft Entra audit activity reference lists this internal operation name without documenting the underlying objects.

References #

DELETE Tenant.DeleteGreetings

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A back-end delete operation recorded by the Authentication Methods service (DirectoryManagement category) that removes tenant greeting records. The Microsoft Entra audit activity reference lists this internal operation name without documenting the underlying objects.

References #

DeleteDataFromBackend

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the deletion of stored Microsoft Entra multifactor authentication data from the MFA backend data store. Logged by the Azure MFA service under the DirectoryManagement category.

References #

DeleteDataFromCosmosDb

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the deletion of stored Microsoft Entra multifactor authentication data from the service's Cosmos DB data store. Logged by the Azure MFA service under the DirectoryManagement category, paralleling DeleteDataFromBackend for the Cosmos DB store.

References #

Deleting Source Tenant subscriptions

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the deletion of subscriptions associated with a source tenant in Core Directory. The 'source tenant' wording and the sibling 'Suspending Source Tenant Subscriptions' activity suggest it occurs during a cross-tenant subscription lifecycle, though the reference states no per-activity prose.

References #

Demote partner

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records a 'Demote partner' action in Core Directory, lowering a partner's standing or relationship in the directory. Changes to a partner relationship can be relevant to monitoring delegated administrative access. The reference provides no per-activity description.

References #

Directory deleted

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the deletion of a Microsoft Entra tenant (directory/organization), an action that removes all resources in the tenant and can only be performed by a Global Administrator. Tenant deletion requires the organization to first pass billing, user, application, and subscription checks.

References #

Directory deleted permanently

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the permanent, irrevocable deletion of a Microsoft Entra tenant (directory), removing the organization and all of its resources. As the 'permanently' qualifier indicates, this is the irrevocable counterpart to the initial tenant-deletion operation.

References #

Directory scheduled for deletion (Lifecycle)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a Microsoft Entra tenant (directory) was placed in a pending-deletion (scheduled) state. The '(Lifecycle)' qualifier indicates the scheduling was driven by an automated system lifecycle process rather than an explicit deletion request, ahead of eventual permanent deletion.

References #

Directory scheduled for deletion (UserRequest)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a Microsoft Entra tenant (directory) was scheduled for deletion in response to an explicit administrator deletion request, entering a pending-deletion state before permanent removal. Tenant deletion is a Global Administrator action.

References #

Disable application proxy

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra application proxy was disabled for the directory. Application proxy publishes on-premises web applications for secure remote access through Microsoft Entra ID, so disabling it is a tenant-level configuration change that removes that remote-access publishing capability and is worth monitoring as a security-relevant change.

References #

Disable Desktop Sso

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra seamless single sign-on (Desktop SSO) was disabled for the directory, turning off automatic sign-in for domain-joined corporate devices on the corporate network. Disabling a hybrid-identity authentication feature is a security-relevant configuration change.

References #

Disable Desktop Sso for a specific domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra seamless single sign-on (Desktop SSO) was disabled for a specific Active Directory domain/forest, removing that domain from the Seamless SSO configuration while leaving other configured domains intact (the Disable-AzureADSSOForest operation).

References #

Disable passthrough authentication

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra pass-through authentication was disabled for the directory. Pass-through authentication validates user passwords directly against on-premises Active Directory through a lightweight agent, so disabling it changes the tenant's hybrid sign-in method and is a security-relevant configuration change.

References #

Disable password writeback for directory

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Self-service password reset (SSPR) password writeback was disabled for the directory, stopping cloud-initiated password changes and resets from being written back to on-premises Active Directory. Disabling password writeback is a security-relevant configuration change to hybrid SSPR.

References #

Dismiss recommendation

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A Microsoft Entra recommendation was dismissed, changing its status to dismissed so it is no longer surfaced as an active recommendation to act on.

References #

Download registration and reset events - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A bulk export of the registration and reset events report, part of the Microsoft Entra authentication methods activity dashboard, completed in the admin center. The report lists individual authentication-method registration and password-reset events (date, user, feature, method used, and status), so an unexpected bulk pull is worth reviewing alongside other directory-read activity.

References #

Download role assignments - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A bulk export of Microsoft Entra directory role assignments completed in the admin center, listing which users and service principals hold which administrative roles. Enumerating privileged role holders is a common precursor to privilege-escalation targeting.

References #

Download service principals - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A bulk export of the directory's service principals (enterprise applications) completed in the admin center, listing the application identities provisioned in the tenant. Enumerating service principals can support reconnaissance of application-based access paths.

References #

Download user registration details - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A bulk export of the user registration details report, part of the Microsoft Entra authentication methods activity dashboard, completed in the admin center. The report lists each user's registered MFA, passwordless, and self-service password reset (SSPR) methods and capability status, revealing which accounts lack strong authentication, information useful for administration and for adversary targeting.

References #

Download users - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A bulk export of the directory's user list to CSV completed in the Microsoft Entra admin center, covering user profile attributes such as userPrincipalName, objectId, userType, and accountEnabled. Large-scale enumeration of all users can indicate reconnaissance or data collection by an actor with directory read access.

References #

Enable application proxy

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

The Microsoft Entra application proxy service was enabled for the directory, allowing on-premises web applications to be published for secure remote access. Exposing internal applications externally expands the tenant's attack surface and is worth reviewing when unexpected.

References #

Enable Desktop Sso

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra seamless single sign-on (referred to internally as Desktop SSO) was enabled for the directory, typically configured through Microsoft Entra Connect. Seamless SSO relies on the AZUREADSSOACC computer account in on-premises Active Directory, making changes to it relevant to hybrid-identity security review.

References #

Enable Desktop Sso for a specific domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra seamless single sign-on (Desktop SSO) was enabled for a specific on-premises Active Directory domain, the per-domain variant used when a forest contains multiple domains. Like tenant-wide Desktop SSO, it provisions the AZUREADSSOACC account in the targeted domain, which is relevant to hybrid-identity security review.

References #

Enable passthrough authentication

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Microsoft Entra pass-through authentication (PTA) was enabled as the user sign-in method for the directory, validating passwords directly against on-premises Active Directory through PTA agents. Changes to PTA are security-relevant because a rogue or unexpected authentication agent can intercept credentials.

References #

Enable password writeback for directory

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Self-service password reset (SSPR) password writeback was enabled for the directory, letting password changes made in the cloud be written back to on-premises Active Directory. Because writeback bridges cloud password changes into on-premises AD, enabling it is relevant to hybrid persistence and privilege review.

References #

Export summary data - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a bulk export of summary data initiated from the Microsoft Entra admin center completed. The entry reflects an administrator exporting directory summary data through the portal's bulk export experience.

References #

Export summary data new - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a bulk export of summary data completed using the newer Microsoft Entra admin center export experience. Like the prior variant, it reflects an administrator exporting directory summary data in bulk through the portal.

References #

ExportDataFromBackend

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records an export of data from the Azure MFA service backend store. Microsoft does not document this as a tenant-facing feature, so treat it as an internal multifactor-authentication data-export operation surfaced under the DirectoryManagement audit category. The exported scope is not specified, so do not assume a particular data set without confirmation.

References #

ExportDataFromCosmosDb

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records an export of data from the Azure Cosmos DB store backing the Azure MFA service. Microsoft does not document this as a tenant-facing feature, so treat it as an internal multifactor-authentication data-export operation logged under the DirectoryManagement audit category. The exact records exported are unspecified.

References #

Get cross-cloud verification code for domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records retrieval of a cross-cloud verification code associated with a directory domain, a Core Directory (DirectoryManagement) read that, by its name, relates to validating a domain relationship across separate Microsoft cloud environments. The exact behavior is not documented as a named feature, so the action is described conservatively from its operation name, category, and service.

References #

Get resources properties of a tenant

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records retrieval of a B2C tenant's directory resource properties. The Azure AD B2C audit-log reference describes its Directory activity type as directory attributes retrieved when an administrator accesses the tenant through the Azure portal, so this read reflects the portal reading tenant/directory properties.

References #

Hard Delete Domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records the permanent (hard) deletion of a custom domain name from the Microsoft Entra tenant. A domain does not support soft delete, so it is hard deleted directly and cannot be restored, only recreated.

References #

Link program control

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Mark recommendation as complete

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a Microsoft Entra recommendation's status was set to completed, meaning every impacted resource for that recommendation has been addressed. Microsoft documents that recommendations cannot be marked complete manually: the recommendation service sets this status automatically once all impacted resources are addressed, and completing a recommendation is the only recommendation action captured in the audit log.

References #

PATCH Tenant.Patch

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

An internal Authentication Methods service operation that records a patch (update) applied to the tenant-level authentication-methods configuration. The operation name alone does not distinguish which specific tenant setting changed.

References #

PATCH Tenant.PatchCaches

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

An internal Authentication Methods service operation that records a patch to the tenant-level authentication-methods configuration cache. It reflects a backend update to cached tenant authentication-method settings rather than a distinct administrator-facing action.

References #

POST SoundFile.Post

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A custom voice-message sound file (.wav or .mp3) was uploaded for use in the tenant's Microsoft Entra multifactor authentication phone-call greetings. The settings page documents this upload as part of the Add greeting flow under Phone call settings.

References #

POST Subscription.CreateProvider

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A Microsoft Entra multifactor authentication provider was created. The provider is the per-user or per-authentication billing entity that extends MFA beyond licensed users; adding new MFA providers has been disabled since September 1, 2018.

References #

POST Subscription.CreateSubscription

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A Microsoft Entra multifactor authentication service subscription was created, associating the MFA authentication provider with the Azure subscription that is billed monthly for per-user or per-authentication MFA usage.

References #

POST Tenant.CreateBlockedUser

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A user was added to the Microsoft Entra multifactor authentication block list, so that MFA attempts for that account are denied. Block/unblock users was a legacy MFA feature that was removed on March 1, 2025, and replaced by Report suspicious activity.

References #

POST Tenant.CreateBypassedUser

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A one-time MFA bypass was created for a user, letting them authenticate a single time without completing multifactor authentication until the bypass expires after a set number of seconds. Because it temporarily removes the second factor, bypass creation is a recognized MFA-circumvention vector worth monitoring.

References #

POST Tenant.CreateCacheConfig

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

An MFA caching rule was created, defining a cache type and a maximum number of seconds during which a user's subsequent authentication attempts succeed automatically after their first successful verification. Caching is intended for on-premises systems (such as VPN) that send multiple verification requests, not for sign-ins to Microsoft Entra ID.

References #

POST Tenant.CreateGreeting

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A custom greeting (voice message) was added for the tenant's Microsoft Entra multifactor authentication phone calls, such as a standard greeting or an authentication-successful message. The greeting is configured via the Add greeting flow under Phone call settings.

References #

POST Tenant.CreateTenant

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records creation or initialization of the tenant's configuration record within the Microsoft Entra (Azure) multifactor authentication service. No Microsoft Learn page documents this as a user-facing action, so the meaning is inferred conservatively from the operation name and the Authentication Methods logging service.

References #

POST Tenant.GenerateNewActivationCredentials

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

New activation credentials were generated for the tenant's on-premises Microsoft Entra multifactor authentication Server, used to activate and bind an MFA Server instance to the tenant during initialization. Generating activation credentials lets a new MFA Server register against the tenant, which is worth noting for unexpected on-premises MFA Server provisioning.

References #

POST Tenant.RemoveBlockedUser

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A user was removed from the Microsoft Entra multifactor authentication block list (unblocked), re-enabling MFA attempts for that account. Block/unblock users was a legacy MFA feature removed on March 1, 2025; unblocking a previously blocked account can re-enable access for an account that was blocked due to suspected compromise.

References #

POST Tenant.RemoveBypassedUser

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A one-time MFA bypass entry was removed for a user, ending the temporary allowance to authenticate without completing multifactor authentication before the bypass would otherwise expire.

References #

Postpone recommendation

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records an administrator postponing a Microsoft Entra recommendation, deferring the recommended action to a later date instead of completing or dismissing it. Postponed is one of the documented recommendation statuses (active, completed, dismissed, postponed).

References #

Promote company to partner

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records a Core Directory operation that changes the tenant (company) designation to partner status within the directory. The precise effect is not covered by a public Learn reference; the record reflects a change to the organization's partner designation.

References #

Promote sub domain to root domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records promotion of a verified subdomain to an independent root domain, which lets the subdomain be managed with its own authentication type (for example switching between managed and federated) separately from its parent domain. Domain authentication-type changes are relevant to federation-tampering detection.

References #

Remove partner from company

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that a partner relationship was removed from the tenant, ending an external partner organization's administrative link to the company. Partner relationships of this kind are associated with delegated administration (such as CSP partners); the reference lists the activity name without detailing the exact relationship type.

References #

Remove unverified domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A custom domain that had not yet completed DNS ownership verification was removed from the tenant. This is routine custom-domain management; an added-then-removed unverified domain has little lasting effect since it was never usable for accounts or federation.

References #

Remove verified domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A custom domain whose ownership had been confirmed via DNS verification was removed from the tenant. Because verified domains underpin user UPNs and federation, removing one is a significant directory change; domain and federation manipulation is a known persistence and defense-evasion technique, though a domain can be removed only once it is no longer in use.

References #

Schedule Add sharedEmailDomain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that the directory scheduled a background task to add a shared email domain entry to the tenant's Core Directory configuration. The precise feature behind this operation name is not documented on Microsoft Learn, so the description is taken conservatively from the operation name, audit category, and logging service.

References #

Schedule Remove sharedEmailDomain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that the directory scheduled a background task to remove a shared email domain entry from the tenant's Core Directory configuration. The precise feature behind this operation name is not documented on Microsoft Learn, so the description is taken conservatively from the operation name, audit category, and logging service.

References #

Set accidental deletion threshold

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that the tenant's accidental-deletion-prevention threshold was set or changed. The threshold caps how many objects a single synchronization or provisioning run may delete before deletions are blocked, so raising or disabling it removes a safeguard against mass-deletion (destructive) activity.

References #

Set company allowed data location

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that an allowed data location was set for the tenant, part of Microsoft 365 Multi-Geo data-residency configuration that governs which geographies user resources (such as mailboxes and OneDrive) may be stored in. Changes affect where organizational data resides and are relevant to data-residency and compliance monitoring.

References #

Set company multinational feature enabled

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records that the tenant's multinational (Microsoft 365 Multi-Geo) feature was enabled or disabled. Enabling it lets the organization store in-scope data across multiple geographies within a single tenant based on each user's preferred data location.

References #

Set directory feature on tenant

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A directory-level feature flag was set or modified for the tenant. Tenant-wide directory feature changes affect baseline behavior across the directory and can be relevant as configuration-tampering signals.

References #

Set DirSync feature

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A directory synchronization (DirSync) feature flag was set for the tenant, toggling one of the hybrid-identity sync behaviors (for example, match handling). This is distinct from the separate 'Set DirSyncEnabled flag' on/off toggle, and changes to sync features can weaken hybrid-identity protections and merit review.

References #

Set Partnership

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A partnership relationship was set or configured in the directory. The operation name does not identify the partner type or scope, so this is described conservatively; the specific relationship could not be grounded to a Microsoft Learn doc.

References #

Set password policy

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

The password policy was set for the tenant or a domain, covering settings such as password expiration/validity period and expiration-notification window. Weakening the policy, for example extending or disabling password expiration, can support persistence and defense evasion.

References #

Soft Delete Domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A domain was soft-deleted, marking it as deleted rather than permanently removing it. Domain deletion or manipulation can disrupt authentication and is relevant to tenant-integrity monitoring.

References #

Suspending Source Tenant Subscriptions

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records a Core Directory action that suspends the subscriptions belonging to a source tenant, consistent with moving or transferring subscriptions away from that tenant. The precise triggering flow is not described in public Microsoft Learn material.

References #

Unlink program control

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Update company

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records a change to the tenant organization (company) object in the directory, such as organization-level properties. These tenant-level property changes are written to the Core Directory audit logs under DirectoryManagement.

References #

Update company settings

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

Records a change to tenant-wide directory (company) settings in Microsoft Entra ID, logged by the Core Directory service under DirectoryManagement. These tenant-level configuration changes are relevant to detecting modifications to directory-wide policy or feature settings.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:41.4863411Z",
  "ActivityDisplayName": "Update company settings",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "DirectoryManagement",
  "CorrelationId": "ca02f8f3-d508-4724-92e5-e13debb424b0",
  "DurationMs": "0",
  "Id": "Directory_ca02f8f3-d508-4724-92e5-e13debb424b0_8K2EC_138133951",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update company settings",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "NCT",
      "type": "Directory",
      "modifiedProperties": [
        {
          "displayName": "ObjectSettings",
          "oldValue": [
            {
              "Settings": [
                {
                  "Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
                  "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
                  "Properties": [
                    {
                      "Key": "EnableMSStandardBlockedWords",
                      "Value": "false"
                    }
                  ]
                }
              ]
            }
          ],
          "newValue": [
            {
              "Settings": [
                {
                  "Id": "745294a4-a3c5-4e33-8512-a9c9140a4bc0",
                  "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
                  "Properties": [
                    {
                      "Key": "EnableMSStandardBlockedWords",
                      "Value": "true"
                    }
                  ]
                }
              ]
            }
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"ObjectSettings\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Update Domain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A domain object in the Microsoft Entra tenant was updated, such as a change to a custom domain's settings or authentication type. Changes to a domain (particularly its federation/authentication settings) are security-relevant, because domain-federation manipulation is a recognized identity-persistence technique.

References #

Update program

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

An access review program was updated. In the legacy access reviews model a program is a container used to group related access reviews.

References #

Update sharedEmailDomain

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A shared email domain directory object was updated. This is a Core Directory directory-management object in Microsoft Entra ID, and the audit record reflects a change to its configuration.

References #

Update sharedEmailDomainInvitation

#
Source
Microsoft Entra ID audit log
Audit Category
DirectoryManagement

Description

A shared email domain invitation object was updated. This Core Directory directory-management object is associated with shared email domain configuration, and the audit record reflects a change to the invitation's state or properties.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.