Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: EntitlementManagement

OperationNameDescriptionSampleRule
Add Entitlement Management role assignmentAn entitlement management role (e.g., catalog owner or access package manager) was assigned to a principal.NN
Administrator directly assigns user to access packageAn administrator directly assigned a user to an entitlement management access package, bypassing request/approval.NN
Administrator directly removes user access package assignmentAn administrator directly removed a user's entitlement management access package assignment.NN
Approval stage completed for access package assignment requestAn approval stage in an access package assignment request's multi-stage approval workflow completed.NN
Approve access package assignment requestAn approver approved a user's access package assignment request in entitlement management, granting the bundled access.NN
Assign user as external sponsorA user was designated as an external sponsor for a connected organization in entitlement management.NN
Assign user as internal sponsorA user was designated as an internal sponsor for a connected organization in entitlement management.NN
Auto approve access package assignment requestAn access package assignment request was auto-approved with no approval required by policy.NN
Cancel access package assignment requestA pending entitlement-management access package assignment request was cancelled before it was fulfilled.NN
Create access packageAn access package was created in Microsoft Entra entitlement management.YN
Create access package assignment policyAn assignment policy was created for an access package in entitlement management.NN
Create access package assignment user update requestA request to update a user's existing access package assignment was created.NN
Create access package catalogA catalog was created in Microsoft Entra entitlement management.YN
Create connected organizationCreation of an entitlement-management connected organization defining an external directory/domain allowed to request access packages.NN
Create custom extensionCreation of an entitlement-management custom extension (Azure Logic App callout) triggered on access-package lifecycle events.NN
Create incompatible access packageAn access package was marked incompatible with another (separation-of-duties) in entitlement management.NN
Create incompatible groupA group was marked incompatible with an access package (separation-of-duties) in entitlement management.NN
Create resource environmentCreation of an entitlement management resource environment (origin-system instance grouping catalog resources).NN
Create resource remove requestRequest to remove a resource (group/app/SharePoint site) from an entitlement management catalog.NN
Create resource requestRequest to add a resource (group/app/SharePoint site) to an entitlement management catalog for use in access packages.NN
Delete access packageAn entitlement management access package (bundle of requestable groups, apps, and roles) was deleted.YN
Delete access package assignment policyAn access package assignment policy (request, approval, and lifecycle rules) was deleted.NN
Delete access package assignment policy for a deleted userAn access package assignment policy tied to a deleted user was removed (typically system cleanup).NN
Delete access package assignment requestAn access package assignment request (a user's request for the package) was deleted.NN
Delete access package catalogAn entitlement management catalog (container for access packages and resources) was deleted.YN
Delete connected organizationA connected organization was deleted from entitlement management.NN
Delete custom extensionAn entitlement management custom extension (Logic Apps callout) was deleted.NN
Delete incompatible access packageRemoves an incompatible-access-package constraint from an access package's separation-of-duties settings in entitlement management.NN
Delete incompatible groupRemoves an incompatible group from an access package's separation-of-duties settings in entitlement management.NN
Deny access package assignment requestAn access package assignment request was denied in entitlement management.NN
Entitlement Management creates access package assignment request for userRecords entitlement management creating an access package assignment request to grant a user the package's bundled resources.NN
Entitlement Management removes access package assignment request for userRecords removal of a user's access package assignment request; deletes request data only, so existing access remains.NN
Execute custom extensionRecords entitlement management executing a custom extension (an Azure Logic Apps callout) for an access package lifecycle event.NN
Extend access package assignmentA user's access package assignment was extended to a later expiration date under the lifecycle policy.NN
Failed access package assignment requestAn access package assignment request failed and the requested access was not granted.NN
Fulfill access package assignment requestAn access package assignment request was fulfilled, granting the user the access package's resources.NN
Fulfill access package resource assignmentEntitlement management delivered an access package's resource roles to an assigned user, granting the bundled access.NN
Partially fulfill access package assignment requestAn access package assignment request was only partially delivered (some resource roles provisioned, others failed/pending).NN
Ready to fulfill access package assignment requestAn access package assignment request became ready to fulfill, ahead of delivery and provisioning.NN
Remove access package resource assignmentA resource assignment was removed from an entitlement-management access package.NN
Remove Entitlement Management role assignmentA principal was removed from an entitlement-management delegation role (e.g. catalog owner or access package manager).NN
Remove user as external sponsorA user was removed as an external sponsor of a connected organization in entitlement management.NN
Remove user as internal sponsorA user was removed as an internal sponsor of a connected organization in entitlement management.NN
Schedule a future access package assignmentAn access package assignment was scheduled to take effect at a future start date in entitlement management.NN
Update access packageModification of an entitlement management access package (the bundle of resource roles users can request).NN
Update access package assignment policyModification of an access package assignment policy (who can request, approval, lifecycle, auto-assignment rules).NN
Update access package assignment requestUpdate to an access package assignment request (a request to be assigned access to an access package).NN
Update access package catalogModification of an entitlement management catalog (container for access packages and their resources).NN
Update access package catalog resourceModification of a resource (group, app, or SharePoint site) within an entitlement management catalog.NN
Update connected organizationChange to a connected organization (external org) in entitlement management.NN
Update custom extensionAn entitlement-management custom extension (Logic App trigger for access packages) was updated.NN
Update request answers by approverAn approver updated the answers on an access package request in entitlement management.NN
Update tenant settingA tenant-wide entitlement management (Microsoft Entra ID Governance) setting was changed.NN
User requests access package assignmentUser requested an access package assignment in Entra entitlement management (My Access).NN
User requests an access package assignment on behalf of service principalUser requested an access package assignment on behalf of a service principal/agent identity.NN
User requests to extend access package assignmentUser requested to extend an existing access package assignment before it expires.NN
User requests to remove access package assignmentUser submitted a self-service request to remove (cancel) their own entitlement management access package assignment.NN

Add Entitlement Management role assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An entitlement management governance role (such as catalog owner, access package manager, catalog reader, or access package assignment manager) was assigned to a user, group, or service principal. These roles delegate control over catalogs and access packages, so a new assignment expands who can grant access to governed resources.

References #

Administrator directly assigns user to access package

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that an administrator created a direct assignment granting a user access to an entitlement management access package, bypassing the normal user-request and approval flow; the acting admin is identified by ActorUserPrincipalName. Direct grants of privileged access packages are relevant to privilege-escalation and persistence monitoring.

References #

Administrator directly removes user access package assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that an administrator directly removed a user's access package assignment in entitlement management, revoking the access the package granted. This is the administrative-removal counterpart to a direct assignment and is logged in the EntitlementManagement category.

References #

Approval stage completed for access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that an approval stage in the multi-stage approval workflow for an access package assignment request completed after an approver in that stage submitted a decision, advancing the request to the next stage or to fulfillment.

References #

Approve access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records an approver approving a user's request for an access package assignment in entitlement management, after which the bundled resources (such as group memberships, application roles, and SharePoint sites) are delivered to the requester. Approval drives an access grant, so it is relevant to tracking how a principal obtained entitlements.

References #

Assign user as external sponsor

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records designating a user as an external sponsor for a connected organization in entitlement management. External sponsors are guest users from the connected organization who can be selected as approvers for access requests made by that organization's users.

References #

Assign user as internal sponsor

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records designating a user in your own directory as an internal sponsor for a connected organization in entitlement management. Internal sponsors are members of your directory who can be selected as approvers for access requests from that connected organization's users.

References #

Auto approve access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records Microsoft Entra entitlement management automatically approving an access package assignment request without a human approver, as occurs when the access package's request policy is configured to require no approval.

References #

Cancel access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A pending access package assignment request in Microsoft Entra ID Governance entitlement management was cancelled before it was fulfilled. The operation is listed under the EntitlementManagement category in the Entitlement Management service; a request can be cancelled while it is still pending and not yet delivered.

References #

Create access package

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records the creation of an access package in Microsoft Entra entitlement management, a bundle of resources and roles that identities can be granted through request policies or direct assignment. New access packages define what standing access can be provisioned and are relevant to access-governance monitoring.

Example Audit Log Entry #

{
  "AADOperationType": "CreateEntitlement",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-03T03:19:12.5335053Z",
  "ActivityDisplayName": "Create access package",
  "AdditionalDetails": [
    {
      "key": "DisplayName",
      "value": "dw-harness-ap-e6ddf76e"
    },
    {
      "key": "Description",
      "value": "harness"
    },
    {
      "key": "IsDeleted",
      "value": "False"
    },
    {
      "key": "tid",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "oid",
      "value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "key": "ipaddr",
      "value": null
    }
  ],
  "Category": "EntitlementManagement",
  "CorrelationId": "7696669a-996f-4b97-ba6b-a610152ed0bf",
  "DurationMs": "0",
  "Id": "Entitlement Management_7696669a-996f-4b97-ba6b-a610152ed0bf_83BKZ_5672772",
  "Identity": "dw-activity-gen",
  "InitiatedBy": {
    "app": {
      "appId": null,
      "displayName": "dw-activity-gen",
      "servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    }
  },
  "LoggedByService": "Entitlement Management",
  "OperationName": "Create access package",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "b86c9acb-0bb6-4a07-9207-5b72703ed1c9",
      "displayName": "dw-harness-ap-e6ddf76e",
      "type": "AccessPackage",
      "modifiedProperties": [
        {
          "displayName": "DisplayName",
          "oldValue": "\"\"",
          "newValue": "\"dw-harness-ap-e6ddf76e\""
        },
        {
          "displayName": "Description",
          "oldValue": "\"\"",
          "newValue": "\"harness\""
        },
        {
          "displayName": "IsDeleted",
          "oldValue": "\"\"",
          "newValue": "\"False\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "d2c3f08b-e41a-4477-813c-3cccd7f8fb79",
      "displayName": "",
      "type": "AccessPackageCatalog",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "",
      "type": "Directory",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Create access package assignment policy

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records the creation of an assignment policy for an access package in entitlement management, which defines who can request or be assigned the package and any approval and lifecycle requirements. Permissive request or approval policies can enable unexpected standing-access grants.

References #

Create access package assignment user update request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records the creation of a request, submitted for a user, to update an existing access package assignment in entitlement management. The record reflects a change request raised against a user's current access package assignment within the entitlement-management request model.

References #

Create access package catalog

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records the creation of a catalog in Microsoft Entra entitlement management, the container that holds access packages and the resources they grant. Catalogs are used for delegation, letting designated individuals create and own access packages, so their creation is part of access-governance monitoring.

Example Audit Log Entry #

{
  "AADOperationType": "CreateEntitlementCatalog",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-03T03:16:32.6582203Z",
  "ActivityDisplayName": "Create access package catalog",
  "AdditionalDetails": [
    {
      "key": "DisplayName",
      "value": "dw-apptest-cat2"
    },
    {
      "key": "Status",
      "value": "Published"
    },
    {
      "key": "IsExternallyVisible",
      "value": "False"
    },
    {
      "key": "IsDeleted",
      "value": "False"
    },
    {
      "key": "tid",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "oid",
      "value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "key": "ipaddr",
      "value": null
    }
  ],
  "Category": "EntitlementManagement",
  "CorrelationId": "0aaed24a-a1bd-4b96-ab6d-c6730378d4ed",
  "DurationMs": "0",
  "Id": "Entitlement Management_0aaed24a-a1bd-4b96-ab6d-c6730378d4ed_F3JPV_37015",
  "Identity": "dw-activity-gen",
  "InitiatedBy": {
    "app": {
      "appId": null,
      "displayName": "dw-activity-gen",
      "servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    }
  },
  "LoggedByService": "Entitlement Management",
  "OperationName": "Create access package catalog",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "80eb1f2a-a2e0-45d4-89c4-1e4e885e92cc",
      "displayName": "dw-apptest-cat2",
      "type": "AccessPackageCatalog",
      "modifiedProperties": [
        {
          "displayName": "DisplayName",
          "oldValue": "\"\"",
          "newValue": "\"dw-apptest-cat2\""
        },
        {
          "displayName": "Status",
          "oldValue": "\"\"",
          "newValue": "\"Published\""
        },
        {
          "displayName": "IsExternallyVisible",
          "oldValue": "\"\"",
          "newValue": "\"False\""
        },
        {
          "displayName": "IsDeleted",
          "oldValue": "\"\"",
          "newValue": "\"False\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "",
      "type": "Directory",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Create connected organization

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A connected organization was created in entitlement management, representing an external Microsoft Entra directory or domain whose users are allowed to request access packages. It broadens the population of external identities that can be granted access, so it is relevant to reviewing external-collaboration and B2B onboarding scope.

References #

Create custom extension

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A custom extension was created in entitlement management, configuring a callout to an Azure Logic App that runs at defined access-package lifecycle events such as request or grant. It introduces an external automation code path into governance workflows, so a new one is worth reviewing.

References #

Create incompatible access package

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Another access package was designated as incompatible with an access package under entitlement management separation-of-duties, so a user who already holds an assignment to the named package cannot request this one. Changes to separation-of-duties constraints are relevant to access-governance monitoring.

References #

Create incompatible group

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A group was designated as incompatible with an access package under entitlement management separation-of-duties, preventing members of that group from requesting the access package. Changes to separation-of-duties constraints are relevant to access-governance monitoring.

References #

Create resource environment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records the creation of a resource environment in Microsoft Entra entitlement management, a container representing an external origin-system instance (for example a specific SharePoint Online environment) under which catalog resources are organized.

References #

Create resource remove request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records a request to remove a resource (such as a group, application, or SharePoint site) from a Microsoft Entra entitlement management catalog so that it is no longer available to that catalog's access packages.

References #

Create resource request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records a request to add a resource (such as a group, application, or SharePoint site) to a Microsoft Entra entitlement management catalog so that the resource's roles can be used in the catalog's access packages. Adding resources broadens what access packages can grant, so unexpected requests are worth reviewing.

References #

Delete access package

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An entitlement management access package was deleted. An access package bundles the groups, applications, and roles users can request together, so deleting one removes that governed access-request path and can indicate tampering with access governance.

Example Audit Log Entry #

{
  "AADOperationType": "DeleteEntitlement",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-03T03:19:13.8069236Z",
  "ActivityDisplayName": "Delete access package",
  "AdditionalDetails": [
    {
      "key": "DisplayName",
      "value": "dw-harness-ap-e6ddf76e"
    },
    {
      "key": "Description",
      "value": "harness"
    },
    {
      "key": "IsDeleted",
      "value": "False"
    },
    {
      "key": "tid",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "oid",
      "value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "key": "ipaddr",
      "value": null
    }
  ],
  "Category": "EntitlementManagement",
  "CorrelationId": "a58338f7-a9c9-4276-8117-331cd24f1861",
  "DurationMs": "0",
  "Id": "Entitlement Management_a58338f7-a9c9-4276-8117-331cd24f1861_W7E59_5689446",
  "Identity": "dw-activity-gen",
  "InitiatedBy": {
    "app": {
      "appId": null,
      "displayName": "dw-activity-gen",
      "servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    }
  },
  "LoggedByService": "Entitlement Management",
  "OperationName": "Delete access package",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "b86c9acb-0bb6-4a07-9207-5b72703ed1c9",
      "displayName": "dw-harness-ap-e6ddf76e",
      "type": "AccessPackage",
      "modifiedProperties": [
        {
          "displayName": "DisplayName",
          "oldValue": "\"dw-harness-ap-e6ddf76e\"",
          "newValue": "\"\""
        },
        {
          "displayName": "Description",
          "oldValue": "\"harness\"",
          "newValue": "\"\""
        },
        {
          "displayName": "IsDeleted",
          "oldValue": "\"False\"",
          "newValue": "\"\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "d2c3f08b-e41a-4477-813c-3cccd7f8fb79",
      "displayName": "dw-harness-cat-e6ddf76e",
      "type": "AccessPackageCatalog",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "",
      "type": "Directory",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Delete access package assignment policy

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An access package assignment policy was deleted. Assignment policies define who can request an access package, any required approvals, and the assignment lifecycle, so removing one eliminates those request, approval, and expiration controls.

References #

Delete access package assignment policy for a deleted user

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An access package assignment policy tied to a user that was deleted from the directory was removed. This is typically automated cleanup that follows deletion of the user account rather than an interactive administrator action.

References #

Delete access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An access package assignment request was deleted. Assignment requests are the per-user requests to receive or remove an access package, so deleting one removes that pending or completed request record.

References #

Delete access package catalog

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An entitlement management catalog was deleted. A catalog is the container that holds access packages and the resources (groups, applications, sites) they grant, so deleting it removes that governance boundary along with its packages.

Example Audit Log Entry #

{
  "AADOperationType": "DeleteEntitlementCatalog",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-03T03:19:45.2943603Z",
  "ActivityDisplayName": "Delete access package catalog",
  "AdditionalDetails": [
    {
      "key": "DisplayName",
      "value": "dw-harness-cat-e6ddf76e"
    },
    {
      "key": "Description",
      "value": "harness"
    },
    {
      "key": "Status",
      "value": "Published"
    },
    {
      "key": "IsExternallyVisible",
      "value": "False"
    },
    {
      "key": "IsDeleted",
      "value": "False"
    },
    {
      "key": "tid",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "oid",
      "value": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "key": "ipaddr",
      "value": null
    }
  ],
  "Category": "EntitlementManagement",
  "CorrelationId": "3128201e-2e66-48c2-beda-78bd5b43af23",
  "DurationMs": "0",
  "Id": "Entitlement Management_3128201e-2e66-48c2-beda-78bd5b43af23_BJMRJ_310025",
  "Identity": "dw-activity-gen",
  "InitiatedBy": {
    "app": {
      "appId": null,
      "displayName": "dw-activity-gen",
      "servicePrincipalId": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    }
  },
  "LoggedByService": "Entitlement Management",
  "OperationName": "Delete access package catalog",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "failure",
  "ResultDescription": "An error occurred while updating the entries. See the inner exception for details.",
  "ResultReason": "An error occurred while updating the entries. See the inner exception for details.",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "d2c3f08b-e41a-4477-813c-3cccd7f8fb79",
      "displayName": "dw-harness-cat-e6ddf76e",
      "type": "AccessPackageCatalog",
      "modifiedProperties": [
        {
          "displayName": "DisplayName",
          "oldValue": "\"dw-harness-cat-e6ddf76e\"",
          "newValue": "\"\""
        },
        {
          "displayName": "Description",
          "oldValue": "\"harness\"",
          "newValue": "\"\""
        },
        {
          "displayName": "Status",
          "oldValue": "\"Published\"",
          "newValue": "\"\""
        },
        {
          "displayName": "IsExternallyVisible",
          "oldValue": "\"False\"",
          "newValue": "\"\""
        },
        {
          "displayName": "IsDeleted",
          "oldValue": "\"False\"",
          "newValue": "\"\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "11111111-1111-1111-1111-111111111111",
      "displayName": "",
      "type": "Directory",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Delete connected organization

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A connected organization was deleted from entitlement management. A connected organization is an external Microsoft Entra directory or domain whose users can request access packages, so its removal revokes that external request relationship.

References #

Delete custom extension

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A custom extension was deleted from entitlement management. Custom extensions are Azure Logic Apps callouts linked to catalogs or access packages that run on access-package events such as request, grant, or approval.

References #

Delete incompatible access package

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records removal of an incompatible-access-package relationship from an access package's separation-of-duties configuration in entitlement management, undoing a constraint that blocked users already assigned to the other package from requesting this one. Loosening a separation-of-duties control can weaken access governance and warrants review.

References #

Delete incompatible group

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records removal of an incompatible group from an access package's separation-of-duties configuration in entitlement management; that constraint had blocked members of the named security group from requesting the access package. Removing it relaxes a governance control.

References #

Deny access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records the denial of a user's request for an access package assignment in entitlement management, so the requested access is not granted. It appears alongside 'Approve access package assignment request' and 'Auto approve access package assignment request', consistent with an approver-side denial.

References #

Entitlement Management creates access package assignment request for user

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that entitlement management created an access package assignment request for a user, a step on the path toward granting that user the resources bundled in the access package (group memberships, application roles, and SharePoint sites). These requests are part of the access-provisioning path and are relevant to monitoring how users obtain bundled access.

References #

Entitlement Management removes access package assignment request for user

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that an access package assignment request for a user was removed. Removing a completed request deletes only the request record and does not revoke the underlying active assignment, so the user keeps access; this distinction matters when reconstructing grant history or investigating cleanup of request trails.

References #

Execute custom extension

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that entitlement management executed a custom extension, a callout to an Azure Logic App triggered by an access package lifecycle event (such as a request being created or approved, or an assignment being granted or removed) to run organization-specific business logic. Because custom extensions invoke external automation inside the access-provisioning path, their executions are relevant to provisioning-integrity monitoring.

References #

Extend access package assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A user's existing access package assignment was extended, pushing its expiration to a later date under the access package's lifecycle policy (which must permit extensions). Recorded under the EntitlementManagement audit category as part of access-package lifecycle governance.

References #

Failed access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An access package assignment request failed and the requested access was not granted (for example the request could not be approved or fulfilled). Recorded under the EntitlementManagement audit category alongside the successful 'Fulfill access package assignment request' counterpart.

References #

Fulfill access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An access package assignment request was fulfilled, granting the requesting user the resource roles bundled in the access package. Recorded under the EntitlementManagement audit category and useful for tracking who was provisioned access to governed resources.

References #

Fulfill access package resource assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

The resource roles bundled in a Microsoft Entra entitlement-management access package were delivered to an assigned user, adding the user to each resource role the package grants. Anomalous fulfillment can indicate over-provisioning or unauthorized access to governed resources.

References #

Partially fulfill access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that an entitlement-management access package assignment request was only partially fulfilled: some of the access package's resource roles were provisioned to the target user while others failed or remain pending (a 'Partially Delivered' request). Such requests can be retried via the reprocess functionality to complete delivery.

References #

Ready to fulfill access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records an entitlement management access package assignment request reaching the 'ready to fulfill' stage, where the request is ready to be delivered ahead of provisioning the access package's resource roles. This sits in the request lifecycle before the delivered state.

References #

Remove access package resource assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A resource assignment was removed from an entitlement-management access package, revoking that resource (and its role) from the package. Identities holding an assignment to the package lose access to the removed resource.

References #

Remove Entitlement Management role assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records removal of a principal from an Entra entitlement-management delegation role, such as catalog owner, catalog reader, access package manager, or access package assignment manager. These roles delegate administration of catalogs and access packages, so a removal reduces the principal's access-governance privileges.

References #

Remove user as external sponsor

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A user was removed from the external sponsors of a connected organization in entitlement management. External sponsors are guest users from the connected (partner) organization, already present in your directory, who serve as a point of contact for that relationship and can be used as approvers for that organization's access-package requests, so removal changes that contact and approver set.

References #

Remove user as internal sponsor

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A user was removed from the internal sponsors of a connected organization in entitlement management. Internal sponsors are member users in your own directory who serve as a point of contact for that connected organization and can be used as approvers for its access-package requests, so removal changes that contact and approver set.

References #

Schedule a future access package assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that an access package assignment in entitlement management was scheduled to take effect at a future start date, granting the target identity the package's linked resource roles when that date arrives. Future-dated access grants can be used for delayed, stealthy persistence, so the scheduled start time is worth correlating against the requestor.

References #

Update access package

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records modification of an access package in Microsoft Entra entitlement management, the bundle of resource roles (groups, applications, and SharePoint sites) that identities can request access to. Changes can alter what resources and roles a successful request grants, which is relevant to access-governance tampering and privilege escalation.

References #

Update access package assignment policy

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records modification of an assignment policy for an entitlement management access package, the rules governing who can request the package, approval and lifecycle settings, and how access is automatically assigned. Weakening approval requirements or broadening who can request access is relevant to privilege escalation and persistence.

References #

Update access package assignment request

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records an update to an access package assignment request in entitlement management, the request object generated when an identity requests, or an administrator directly assigns, access to an access package.

References #

Update access package catalog

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records modification of a catalog in entitlement management, the container that holds access packages and the resources (groups, applications, and SharePoint sites) available to them.

References #

Update access package catalog resource

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records modification of a resource within an entitlement management catalog, such as a group, application, or SharePoint site that has been added to the catalog and made available for inclusion in access packages.

References #

Update connected organization

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records a change to a connected organization in Microsoft Entra entitlement management, which is the directory representation of an external organization whose users can request access to your resources. Modifying a connected organization can alter which external domains or tenants are trusted for access-package requests, relevant to external-access governance monitoring.

References #

Update custom extension

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An entitlement-management custom extension was updated. These extensions trigger an Azure Logic App at access-package lifecycle stages such as request, approval, assignment, or removal.

References #

Update request answers by approver

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

An approver updated the answers attached to an access package assignment request in entitlement management. Requestors answer custom questions at request time, and those answers are surfaced to approvers to inform the approve/deny decision.

References #

Update tenant setting

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

A tenant-wide entitlement management setting was changed, altering the global (tenant-level) configuration for Microsoft Entra ID Governance entitlement management. The change is recorded under the EntitlementManagement audit category.

References #

User requests access package assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records a user requesting an access package assignment in Microsoft Entra entitlement management (through the My Access portal). When the request is received, Entra writes this audit record with category EntitlementManagement and activity 'User requests access package assignment'. Access packages bundle resource roles, so these requests are relevant to access-governance and privilege monitoring.

References #

User requests an access package assignment on behalf of service principal

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records a user requesting an access package assignment on behalf of a service principal (such as an owned or sponsored agent identity), which would grant that non-human identity the bundled resource roles in the access package. Relevant to monitoring delegated and non-human-identity access grants.

References #

User requests to extend access package assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records a user requesting to extend the duration of an existing access package assignment in Microsoft Entra entitlement management, before the assignment expires, where the access package policy permits extension. Logged under the EntitlementManagement category.

References #

User requests to remove access package assignment

#
Source
Microsoft Entra ID audit log
Audit Category
EntitlementManagement

Description

Records that a user submitted a self-service request to remove (cancel) their own Entitlement Management access package assignment, giving up the access that the package granted. Routine access-lifecycle activity that is rarely security-relevant on its own.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.