Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: EntitlementManagement
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add Entitlement Management role assignment | An entitlement management role (e.g., catalog owner or access package manager) was assigned to a principal. | N | N |
| Administrator directly assigns user to access package | An administrator directly assigned a user to an entitlement management access package, bypassing request/approval. | N | N |
| Administrator directly removes user access package assignment | An administrator directly removed a user's entitlement management access package assignment. | N | N |
| Approval stage completed for access package assignment request | An approval stage in an access package assignment request's multi-stage approval workflow completed. | N | N |
| Approve access package assignment request | An approver approved a user's access package assignment request in entitlement management, granting the bundled access. | N | N |
| Assign user as external sponsor | A user was designated as an external sponsor for a connected organization in entitlement management. | N | N |
| Assign user as internal sponsor | A user was designated as an internal sponsor for a connected organization in entitlement management. | N | N |
| Auto approve access package assignment request | An access package assignment request was auto-approved with no approval required by policy. | N | N |
| Cancel access package assignment request | A pending entitlement-management access package assignment request was cancelled before it was fulfilled. | N | N |
| Create access package | An access package was created in Microsoft Entra entitlement management. | Y | N |
| Create access package assignment policy | An assignment policy was created for an access package in entitlement management. | N | N |
| Create access package assignment user update request | A request to update a user's existing access package assignment was created. | N | N |
| Create access package catalog | A catalog was created in Microsoft Entra entitlement management. | Y | N |
| Create connected organization | Creation of an entitlement-management connected organization defining an external directory/domain allowed to request access packages. | N | N |
| Create custom extension | Creation of an entitlement-management custom extension (Azure Logic App callout) triggered on access-package lifecycle events. | N | N |
| Create incompatible access package | An access package was marked incompatible with another (separation-of-duties) in entitlement management. | N | N |
| Create incompatible group | A group was marked incompatible with an access package (separation-of-duties) in entitlement management. | N | N |
| Create resource environment | Creation of an entitlement management resource environment (origin-system instance grouping catalog resources). | N | N |
| Create resource remove request | Request to remove a resource (group/app/SharePoint site) from an entitlement management catalog. | N | N |
| Create resource request | Request to add a resource (group/app/SharePoint site) to an entitlement management catalog for use in access packages. | N | N |
| Delete access package | An entitlement management access package (bundle of requestable groups, apps, and roles) was deleted. | Y | N |
| Delete access package assignment policy | An access package assignment policy (request, approval, and lifecycle rules) was deleted. | N | N |
| Delete access package assignment policy for a deleted user | An access package assignment policy tied to a deleted user was removed (typically system cleanup). | N | N |
| Delete access package assignment request | An access package assignment request (a user's request for the package) was deleted. | N | N |
| Delete access package catalog | An entitlement management catalog (container for access packages and resources) was deleted. | Y | N |
| Delete connected organization | A connected organization was deleted from entitlement management. | N | N |
| Delete custom extension | An entitlement management custom extension (Logic Apps callout) was deleted. | N | N |
| Delete incompatible access package | Removes an incompatible-access-package constraint from an access package's separation-of-duties settings in entitlement management. | N | N |
| Delete incompatible group | Removes an incompatible group from an access package's separation-of-duties settings in entitlement management. | N | N |
| Deny access package assignment request | An access package assignment request was denied in entitlement management. | N | N |
| Entitlement Management creates access package assignment request for user | Records entitlement management creating an access package assignment request to grant a user the package's bundled resources. | N | N |
| Entitlement Management removes access package assignment request for user | Records removal of a user's access package assignment request; deletes request data only, so existing access remains. | N | N |
| Execute custom extension | Records entitlement management executing a custom extension (an Azure Logic Apps callout) for an access package lifecycle event. | N | N |
| Extend access package assignment | A user's access package assignment was extended to a later expiration date under the lifecycle policy. | N | N |
| Failed access package assignment request | An access package assignment request failed and the requested access was not granted. | N | N |
| Fulfill access package assignment request | An access package assignment request was fulfilled, granting the user the access package's resources. | N | N |
| Fulfill access package resource assignment | Entitlement management delivered an access package's resource roles to an assigned user, granting the bundled access. | N | N |
| Partially fulfill access package assignment request | An access package assignment request was only partially delivered (some resource roles provisioned, others failed/pending). | N | N |
| Ready to fulfill access package assignment request | An access package assignment request became ready to fulfill, ahead of delivery and provisioning. | N | N |
| Remove access package resource assignment | A resource assignment was removed from an entitlement-management access package. | N | N |
| Remove Entitlement Management role assignment | A principal was removed from an entitlement-management delegation role (e.g. catalog owner or access package manager). | N | N |
| Remove user as external sponsor | A user was removed as an external sponsor of a connected organization in entitlement management. | N | N |
| Remove user as internal sponsor | A user was removed as an internal sponsor of a connected organization in entitlement management. | N | N |
| Schedule a future access package assignment | An access package assignment was scheduled to take effect at a future start date in entitlement management. | N | N |
| Update access package | Modification of an entitlement management access package (the bundle of resource roles users can request). | N | N |
| Update access package assignment policy | Modification of an access package assignment policy (who can request, approval, lifecycle, auto-assignment rules). | N | N |
| Update access package assignment request | Update to an access package assignment request (a request to be assigned access to an access package). | N | N |
| Update access package catalog | Modification of an entitlement management catalog (container for access packages and their resources). | N | N |
| Update access package catalog resource | Modification of a resource (group, app, or SharePoint site) within an entitlement management catalog. | N | N |
| Update connected organization | Change to a connected organization (external org) in entitlement management. | N | N |
| Update custom extension | An entitlement-management custom extension (Logic App trigger for access packages) was updated. | N | N |
| Update request answers by approver | An approver updated the answers on an access package request in entitlement management. | N | N |
| Update tenant setting | A tenant-wide entitlement management (Microsoft Entra ID Governance) setting was changed. | N | N |
| User requests access package assignment | User requested an access package assignment in Entra entitlement management (My Access). | N | N |
| User requests an access package assignment on behalf of service principal | User requested an access package assignment on behalf of a service principal/agent identity. | N | N |
| User requests to extend access package assignment | User requested to extend an existing access package assignment before it expires. | N | N |
| User requests to remove access package assignment | User submitted a self-service request to remove (cancel) their own entitlement management access package assignment. | N | N |
Add Entitlement Management role assignment
#Description
An entitlement management governance role (such as catalog owner, access package manager, catalog reader, or access package assignment manager) was assigned to a user, group, or service principal. These roles delegate control over catalogs and access packages, so a new assignment expands who can grant access to governed resources.
References #
Administrator directly assigns user to access package
#Description
Records that an administrator created a direct assignment granting a user access to an entitlement management access package, bypassing the normal user-request and approval flow; the acting admin is identified by ActorUserPrincipalName. Direct grants of privileged access packages are relevant to privilege-escalation and persistence monitoring.
References #
Administrator directly removes user access package assignment
#Description
Records that an administrator directly removed a user's access package assignment in entitlement management, revoking the access the package granted. This is the administrative-removal counterpart to a direct assignment and is logged in the EntitlementManagement category.
References #
Approval stage completed for access package assignment request
#Description
Records that an approval stage in the multi-stage approval workflow for an access package assignment request completed after an approver in that stage submitted a decision, advancing the request to the next stage or to fulfillment.
References #
Approve access package assignment request
#Description
Records an approver approving a user's request for an access package assignment in entitlement management, after which the bundled resources (such as group memberships, application roles, and SharePoint sites) are delivered to the requester. Approval drives an access grant, so it is relevant to tracking how a principal obtained entitlements.
References #
Assign user as external sponsor
#Description
Records designating a user as an external sponsor for a connected organization in entitlement management. External sponsors are guest users from the connected organization who can be selected as approvers for access requests made by that organization's users.
References #
Assign user as internal sponsor
#Description
Records designating a user in your own directory as an internal sponsor for a connected organization in entitlement management. Internal sponsors are members of your directory who can be selected as approvers for access requests from that connected organization's users.
References #
Auto approve access package assignment request
#Description
Records Microsoft Entra entitlement management automatically approving an access package assignment request without a human approver, as occurs when the access package's request policy is configured to require no approval.
References #
Cancel access package assignment request
#Description
A pending access package assignment request in Microsoft Entra ID Governance entitlement management was cancelled before it was fulfilled. The operation is listed under the EntitlementManagement category in the Entitlement Management service; a request can be cancelled while it is still pending and not yet delivered.
References #
Create access package
#Description
Records the creation of an access package in Microsoft Entra entitlement management, a bundle of resources and roles that identities can be granted through request policies or direct assignment. New access packages define what standing access can be provisioned and are relevant to access-governance monitoring.
Example Audit Log Entry #
{
"AADOperationType": "CreateEntitlement",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-03T03:19:12.5335053Z",
"ActivityDisplayName": "Create access package",
"AdditionalDetails": [
{
"key": "DisplayName",
"value": "dw-harness-ap-e6ddf76e"
},
{
"key": "Description",
"value": "harness"
},
{
"key": "IsDeleted",
"value": "False"
},
{
"key": "tid",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "oid",
"value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
},
{
"key": "ipaddr",
"value": null
}
],
"Category": "EntitlementManagement",
"CorrelationId": "7696669a-996f-4b97-ba6b-a610152ed0bf",
"DurationMs": "0",
"Id": "Entitlement Management_7696669a-996f-4b97-ba6b-a610152ed0bf_83BKZ_5672772",
"Identity": "dw-activity-gen",
"InitiatedBy": {
"app": {
"appId": null,
"displayName": "dw-activity-gen",
"servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
}
},
"LoggedByService": "Entitlement Management",
"OperationName": "Create access package",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "b86c9acb-0bb6-4a07-9207-5b72703ed1c9",
"displayName": "dw-harness-ap-e6ddf76e",
"type": "AccessPackage",
"modifiedProperties": [
{
"displayName": "DisplayName",
"oldValue": "\"\"",
"newValue": "\"dw-harness-ap-e6ddf76e\""
},
{
"displayName": "Description",
"oldValue": "\"\"",
"newValue": "\"harness\""
},
{
"displayName": "IsDeleted",
"oldValue": "\"\"",
"newValue": "\"False\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "d2c3f08b-e41a-4477-813c-3cccd7f8fb79",
"displayName": "",
"type": "AccessPackageCatalog",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "",
"type": "Directory",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Create access package assignment policy
#Description
Records the creation of an assignment policy for an access package in entitlement management, which defines who can request or be assigned the package and any approval and lifecycle requirements. Permissive request or approval policies can enable unexpected standing-access grants.
References #
Create access package assignment user update request
#Description
Records the creation of a request, submitted for a user, to update an existing access package assignment in entitlement management. The record reflects a change request raised against a user's current access package assignment within the entitlement-management request model.
References #
Create access package catalog
#Description
Records the creation of a catalog in Microsoft Entra entitlement management, the container that holds access packages and the resources they grant. Catalogs are used for delegation, letting designated individuals create and own access packages, so their creation is part of access-governance monitoring.
Example Audit Log Entry #
{
"AADOperationType": "CreateEntitlementCatalog",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-03T03:16:32.6582203Z",
"ActivityDisplayName": "Create access package catalog",
"AdditionalDetails": [
{
"key": "DisplayName",
"value": "dw-apptest-cat2"
},
{
"key": "Status",
"value": "Published"
},
{
"key": "IsExternallyVisible",
"value": "False"
},
{
"key": "IsDeleted",
"value": "False"
},
{
"key": "tid",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "oid",
"value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
},
{
"key": "ipaddr",
"value": null
}
],
"Category": "EntitlementManagement",
"CorrelationId": "0aaed24a-a1bd-4b96-ab6d-c6730378d4ed",
"DurationMs": "0",
"Id": "Entitlement Management_0aaed24a-a1bd-4b96-ab6d-c6730378d4ed_F3JPV_37015",
"Identity": "dw-activity-gen",
"InitiatedBy": {
"app": {
"appId": null,
"displayName": "dw-activity-gen",
"servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
}
},
"LoggedByService": "Entitlement Management",
"OperationName": "Create access package catalog",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "80eb1f2a-a2e0-45d4-89c4-1e4e885e92cc",
"displayName": "dw-apptest-cat2",
"type": "AccessPackageCatalog",
"modifiedProperties": [
{
"displayName": "DisplayName",
"oldValue": "\"\"",
"newValue": "\"dw-apptest-cat2\""
},
{
"displayName": "Status",
"oldValue": "\"\"",
"newValue": "\"Published\""
},
{
"displayName": "IsExternallyVisible",
"oldValue": "\"\"",
"newValue": "\"False\""
},
{
"displayName": "IsDeleted",
"oldValue": "\"\"",
"newValue": "\"False\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "",
"type": "Directory",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Create connected organization
#Description
A connected organization was created in entitlement management, representing an external Microsoft Entra directory or domain whose users are allowed to request access packages. It broadens the population of external identities that can be granted access, so it is relevant to reviewing external-collaboration and B2B onboarding scope.
References #
Create custom extension
#Description
A custom extension was created in entitlement management, configuring a callout to an Azure Logic App that runs at defined access-package lifecycle events such as request or grant. It introduces an external automation code path into governance workflows, so a new one is worth reviewing.
References #
Create incompatible access package
#Description
Another access package was designated as incompatible with an access package under entitlement management separation-of-duties, so a user who already holds an assignment to the named package cannot request this one. Changes to separation-of-duties constraints are relevant to access-governance monitoring.
References #
Create incompatible group
#Description
A group was designated as incompatible with an access package under entitlement management separation-of-duties, preventing members of that group from requesting the access package. Changes to separation-of-duties constraints are relevant to access-governance monitoring.
References #
Create resource environment
#Description
Records the creation of a resource environment in Microsoft Entra entitlement management, a container representing an external origin-system instance (for example a specific SharePoint Online environment) under which catalog resources are organized.
References #
Create resource remove request
#Description
Records a request to remove a resource (such as a group, application, or SharePoint site) from a Microsoft Entra entitlement management catalog so that it is no longer available to that catalog's access packages.
References #
Create resource request
#Description
Records a request to add a resource (such as a group, application, or SharePoint site) to a Microsoft Entra entitlement management catalog so that the resource's roles can be used in the catalog's access packages. Adding resources broadens what access packages can grant, so unexpected requests are worth reviewing.
References #
Delete access package
#Description
An entitlement management access package was deleted. An access package bundles the groups, applications, and roles users can request together, so deleting one removes that governed access-request path and can indicate tampering with access governance.
Example Audit Log Entry #
{
"AADOperationType": "DeleteEntitlement",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-03T03:19:13.8069236Z",
"ActivityDisplayName": "Delete access package",
"AdditionalDetails": [
{
"key": "DisplayName",
"value": "dw-harness-ap-e6ddf76e"
},
{
"key": "Description",
"value": "harness"
},
{
"key": "IsDeleted",
"value": "False"
},
{
"key": "tid",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "oid",
"value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
},
{
"key": "ipaddr",
"value": null
}
],
"Category": "EntitlementManagement",
"CorrelationId": "a58338f7-a9c9-4276-8117-331cd24f1861",
"DurationMs": "0",
"Id": "Entitlement Management_a58338f7-a9c9-4276-8117-331cd24f1861_W7E59_5689446",
"Identity": "dw-activity-gen",
"InitiatedBy": {
"app": {
"appId": null,
"displayName": "dw-activity-gen",
"servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
}
},
"LoggedByService": "Entitlement Management",
"OperationName": "Delete access package",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "b86c9acb-0bb6-4a07-9207-5b72703ed1c9",
"displayName": "dw-harness-ap-e6ddf76e",
"type": "AccessPackage",
"modifiedProperties": [
{
"displayName": "DisplayName",
"oldValue": "\"dw-harness-ap-e6ddf76e\"",
"newValue": "\"\""
},
{
"displayName": "Description",
"oldValue": "\"harness\"",
"newValue": "\"\""
},
{
"displayName": "IsDeleted",
"oldValue": "\"False\"",
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "d2c3f08b-e41a-4477-813c-3cccd7f8fb79",
"displayName": "dw-harness-cat-e6ddf76e",
"type": "AccessPackageCatalog",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "",
"type": "Directory",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Delete access package assignment policy
#Description
An access package assignment policy was deleted. Assignment policies define who can request an access package, any required approvals, and the assignment lifecycle, so removing one eliminates those request, approval, and expiration controls.
References #
Delete access package assignment policy for a deleted user
#Description
An access package assignment policy tied to a user that was deleted from the directory was removed. This is typically automated cleanup that follows deletion of the user account rather than an interactive administrator action.
References #
Delete access package assignment request
#Description
An access package assignment request was deleted. Assignment requests are the per-user requests to receive or remove an access package, so deleting one removes that pending or completed request record.
References #
Delete access package catalog
#Description
An entitlement management catalog was deleted. A catalog is the container that holds access packages and the resources (groups, applications, sites) they grant, so deleting it removes that governance boundary along with its packages.
Example Audit Log Entry #
{
"AADOperationType": "DeleteEntitlementCatalog",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-03T03:19:45.2943603Z",
"ActivityDisplayName": "Delete access package catalog",
"AdditionalDetails": [
{
"key": "DisplayName",
"value": "dw-harness-cat-e6ddf76e"
},
{
"key": "Description",
"value": "harness"
},
{
"key": "Status",
"value": "Published"
},
{
"key": "IsExternallyVisible",
"value": "False"
},
{
"key": "IsDeleted",
"value": "False"
},
{
"key": "tid",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "oid",
"value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
},
{
"key": "ipaddr",
"value": null
}
],
"Category": "EntitlementManagement",
"CorrelationId": "3128201e-2e66-48c2-beda-78bd5b43af23",
"DurationMs": "0",
"Id": "Entitlement Management_3128201e-2e66-48c2-beda-78bd5b43af23_BJMRJ_310025",
"Identity": "dw-activity-gen",
"InitiatedBy": {
"app": {
"appId": null,
"displayName": "dw-activity-gen",
"servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
}
},
"LoggedByService": "Entitlement Management",
"OperationName": "Delete access package catalog",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "failure",
"ResultDescription": "An error occurred while updating the entries. See the inner exception for details.",
"ResultReason": "An error occurred while updating the entries. See the inner exception for details.",
"ResultSignature": "None",
"TargetResources": [
{
"id": "d2c3f08b-e41a-4477-813c-3cccd7f8fb79",
"displayName": "dw-harness-cat-e6ddf76e",
"type": "AccessPackageCatalog",
"modifiedProperties": [
{
"displayName": "DisplayName",
"oldValue": "\"dw-harness-cat-e6ddf76e\"",
"newValue": "\"\""
},
{
"displayName": "Description",
"oldValue": "\"harness\"",
"newValue": "\"\""
},
{
"displayName": "Status",
"oldValue": "\"Published\"",
"newValue": "\"\""
},
{
"displayName": "IsExternallyVisible",
"oldValue": "\"False\"",
"newValue": "\"\""
},
{
"displayName": "IsDeleted",
"oldValue": "\"False\"",
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "11111111-1111-1111-1111-111111111111",
"displayName": "",
"type": "Directory",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Delete connected organization
#Description
A connected organization was deleted from entitlement management. A connected organization is an external Microsoft Entra directory or domain whose users can request access packages, so its removal revokes that external request relationship.
References #
Delete custom extension
#Description
A custom extension was deleted from entitlement management. Custom extensions are Azure Logic Apps callouts linked to catalogs or access packages that run on access-package events such as request, grant, or approval.
References #
Delete incompatible access package
#Description
Records removal of an incompatible-access-package relationship from an access package's separation-of-duties configuration in entitlement management, undoing a constraint that blocked users already assigned to the other package from requesting this one. Loosening a separation-of-duties control can weaken access governance and warrants review.
References #
Delete incompatible group
#Description
Records removal of an incompatible group from an access package's separation-of-duties configuration in entitlement management; that constraint had blocked members of the named security group from requesting the access package. Removing it relaxes a governance control.
References #
Deny access package assignment request
#Description
Records the denial of a user's request for an access package assignment in entitlement management, so the requested access is not granted. It appears alongside 'Approve access package assignment request' and 'Auto approve access package assignment request', consistent with an approver-side denial.
References #
Entitlement Management creates access package assignment request for user
#Description
Records that entitlement management created an access package assignment request for a user, a step on the path toward granting that user the resources bundled in the access package (group memberships, application roles, and SharePoint sites). These requests are part of the access-provisioning path and are relevant to monitoring how users obtain bundled access.
References #
Entitlement Management removes access package assignment request for user
#Description
Records that an access package assignment request for a user was removed. Removing a completed request deletes only the request record and does not revoke the underlying active assignment, so the user keeps access; this distinction matters when reconstructing grant history or investigating cleanup of request trails.
References #
Execute custom extension
#Description
Records that entitlement management executed a custom extension, a callout to an Azure Logic App triggered by an access package lifecycle event (such as a request being created or approved, or an assignment being granted or removed) to run organization-specific business logic. Because custom extensions invoke external automation inside the access-provisioning path, their executions are relevant to provisioning-integrity monitoring.
References #
Extend access package assignment
#Description
A user's existing access package assignment was extended, pushing its expiration to a later date under the access package's lifecycle policy (which must permit extensions). Recorded under the EntitlementManagement audit category as part of access-package lifecycle governance.
References #
Failed access package assignment request
#Description
An access package assignment request failed and the requested access was not granted (for example the request could not be approved or fulfilled). Recorded under the EntitlementManagement audit category alongside the successful 'Fulfill access package assignment request' counterpart.
References #
Fulfill access package assignment request
#Description
An access package assignment request was fulfilled, granting the requesting user the resource roles bundled in the access package. Recorded under the EntitlementManagement audit category and useful for tracking who was provisioned access to governed resources.
References #
Fulfill access package resource assignment
#Description
The resource roles bundled in a Microsoft Entra entitlement-management access package were delivered to an assigned user, adding the user to each resource role the package grants. Anomalous fulfillment can indicate over-provisioning or unauthorized access to governed resources.
References #
Partially fulfill access package assignment request
#Description
Records that an entitlement-management access package assignment request was only partially fulfilled: some of the access package's resource roles were provisioned to the target user while others failed or remain pending (a 'Partially Delivered' request). Such requests can be retried via the reprocess functionality to complete delivery.
References #
Ready to fulfill access package assignment request
#Description
Records an entitlement management access package assignment request reaching the 'ready to fulfill' stage, where the request is ready to be delivered ahead of provisioning the access package's resource roles. This sits in the request lifecycle before the delivered state.
References #
Remove access package resource assignment
#Description
A resource assignment was removed from an entitlement-management access package, revoking that resource (and its role) from the package. Identities holding an assignment to the package lose access to the removed resource.
References #
Remove Entitlement Management role assignment
#Description
Records removal of a principal from an Entra entitlement-management delegation role, such as catalog owner, catalog reader, access package manager, or access package assignment manager. These roles delegate administration of catalogs and access packages, so a removal reduces the principal's access-governance privileges.
References #
Remove user as external sponsor
#Description
A user was removed from the external sponsors of a connected organization in entitlement management. External sponsors are guest users from the connected (partner) organization, already present in your directory, who serve as a point of contact for that relationship and can be used as approvers for that organization's access-package requests, so removal changes that contact and approver set.
References #
Remove user as internal sponsor
#Description
A user was removed from the internal sponsors of a connected organization in entitlement management. Internal sponsors are member users in your own directory who serve as a point of contact for that connected organization and can be used as approvers for its access-package requests, so removal changes that contact and approver set.
References #
Schedule a future access package assignment
#Description
Records that an access package assignment in entitlement management was scheduled to take effect at a future start date, granting the target identity the package's linked resource roles when that date arrives. Future-dated access grants can be used for delayed, stealthy persistence, so the scheduled start time is worth correlating against the requestor.
References #
Update access package
#Description
Records modification of an access package in Microsoft Entra entitlement management, the bundle of resource roles (groups, applications, and SharePoint sites) that identities can request access to. Changes can alter what resources and roles a successful request grants, which is relevant to access-governance tampering and privilege escalation.
References #
Update access package assignment policy
#Description
Records modification of an assignment policy for an entitlement management access package, the rules governing who can request the package, approval and lifecycle settings, and how access is automatically assigned. Weakening approval requirements or broadening who can request access is relevant to privilege escalation and persistence.
References #
Update access package assignment request
#Description
Records an update to an access package assignment request in entitlement management, the request object generated when an identity requests, or an administrator directly assigns, access to an access package.
References #
Update access package catalog
#Description
Records modification of a catalog in entitlement management, the container that holds access packages and the resources (groups, applications, and SharePoint sites) available to them.
References #
Update access package catalog resource
#Description
Records modification of a resource within an entitlement management catalog, such as a group, application, or SharePoint site that has been added to the catalog and made available for inclusion in access packages.
References #
Update connected organization
#Description
Records a change to a connected organization in Microsoft Entra entitlement management, which is the directory representation of an external organization whose users can request access to your resources. Modifying a connected organization can alter which external domains or tenants are trusted for access-package requests, relevant to external-access governance monitoring.
References #
Update custom extension
#Description
An entitlement-management custom extension was updated. These extensions trigger an Azure Logic App at access-package lifecycle stages such as request, approval, assignment, or removal.
References #
Update request answers by approver
#Description
An approver updated the answers attached to an access package assignment request in entitlement management. Requestors answer custom questions at request time, and those answers are surfaced to approvers to inform the approve/deny decision.
References #
Update tenant setting
#Description
A tenant-wide entitlement management setting was changed, altering the global (tenant-level) configuration for Microsoft Entra ID Governance entitlement management. The change is recorded under the EntitlementManagement audit category.
References #
User requests access package assignment
#Description
Records a user requesting an access package assignment in Microsoft Entra entitlement management (through the My Access portal). When the request is received, Entra writes this audit record with category EntitlementManagement and activity 'User requests access package assignment'. Access packages bundle resource roles, so these requests are relevant to access-governance and privilege monitoring.
References #
User requests an access package assignment on behalf of service principal
#Description
Records a user requesting an access package assignment on behalf of a service principal (such as an owned or sponsored agent identity), which would grant that non-human identity the bundled resource roles in the access package. Relevant to monitoring delegated and non-human-identity access grants.
References #
User requests to extend access package assignment
#Description
Records a user requesting to extend the duration of an existing access package assignment in Microsoft Entra entitlement management, before the assignment expires, where the access package policy permits extension. Logged under the EntitlementManagement category.
References #
User requests to remove access package assignment
#Description
Records that a user submitted a self-service request to remove (cancel) their own Entitlement Management access package assignment, giving up the access that the package granted. Routine access-lifecycle activity that is rarely security-relevant on its own.
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.