Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: GroupManagement
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add group | A new group was created. | Y | N |
| Add member to group | A principal was added as a member of a group (including role-assignable groups). | Y | Y |
| Add owner to group | An owner was added to a group. | Y | Y |
| Delete group | A group was deleted. | Y | Y |
| Remove member from group | A principal was removed from a group. | Y | Y |
| Update group | A group's properties were modified. | Y | Y |
| Add app role assignment to group | A group was assigned an application app role, granting its members access to that application or role. | Y | N |
| Add eligible member to role in PIM canceled (renew) | A request to renew an eligible PIM-for-Groups membership was canceled. | N | N |
| Add eligible member to role in PIM canceled (timebound) | A request to add a time-bound eligible PIM-for-Groups membership was canceled. | N | N |
| Add eligible member to role in PIM completed (timebound) | A time-bound eligible PIM-for-Groups membership assignment was created. | N | N |
| Add eligible member to role in PIM requested (permanent) | A request to add a permanently eligible PIM-for-Groups membership was submitted. | N | N |
| Add eligible member to role in PIM requested (renew) | A request to renew an eligible PIM-for-Groups membership was submitted. | N | N |
| Add eligible member to role in PIM requested (timebound) | A request to add a time-bound eligible PIM-for-Groups membership was submitted. | N | Y |
| Add member to role canceled (PIM activation) | A pending PIM activation request for an eligible Entra role was canceled. | N | N |
| Add member to role in PIM canceled (permanent) | A request to add a permanent (no-expiration) Entra role assignment in PIM was canceled. | N | N |
| Add member to role in PIM canceled (renew) | A request to renew an expiring Entra role assignment in PIM was canceled. | N | N |
| Add member to role in PIM canceled (timebound) | A request to add a time-bound (expiring) Entra role assignment in PIM was canceled. | N | N |
| Add member to role in PIM completed (permanent) | A permanent (no-expiration) Entra role assignment was completed through PIM. | N | N |
| Add member to role in PIM requested (renew) | A renewal of an expiring Entra role assignment was requested in PIM. | N | N |
| Add member to role request approved (PIM activation) | An approver approved a pending PIM activation request for an eligible Entra role. | N | N |
| Add member to role requested (PIM activation) | A PIM (for Groups) just-in-time request to activate eligible group membership. | N | N |
| Approval_ | An approver acted on (approved/denied) a self-service group membership approval request. | N | N |
| Approval_ | Retrieval of a single self-service group membership approval request. | N | N |
| Approval_ | Self-service group membership approval requests were enumerated (e.g. an approver's pending queue); despite the _GetAll name, first-party capture shows the record logs with AADOperationType Update. | Y | N |
| Approval | Creation of a notification for a pending self-service group membership approval request. | N | N |
| Approvals_ | A self-service group membership approval request/decision was submitted (posted). | N | N |
| Approve a pending request to join a group | A group owner approved a user's pending request to join a self-service-managed group, adding them as a member. | N | N |
| Assign label to group | A sensitivity label was assigned to a Microsoft 365 group, which can change its privacy and external-sharing settings. | N | N |
| Bulk import group members - finished (bulk) | A bulk job that adds members to a group from an uploaded CSV completed. | N | N |
| Bulk remove group members - finished (bulk) | A bulk job that removes members from a group via an uploaded CSV completed. | N | N |
| Cancel a pending request to join a group | A user canceled their pending request to join an owner-approved self-service group. | N | N |
| Cancel request for role removal | A pending PIM request to remove a role assignment was cancelled before processing. | N | N |
| Cancel request for role update | A pending PIM request to update a role assignment was cancelled before processing. | N | N |
| Create group settings | Creation of a group/directory settings object configuring Microsoft 365 group behavior (naming, guest access, classification). | N | N |
| Create lifecycle management policy | A group lifecycle/expiration policy was created for Microsoft 365 groups. | N | N |
| Delete a pending request to join a group | Deletion/withdrawal of a pending self-service request to join a group (before owner approval). | N | N |
| Delete group settings | Deletion of a directory group settings object, reverting group-level settings such as a naming policy to defaults. | N | N |
| Delete lifecycle management policy | Deletes the Microsoft 365 group expiration/lifecycle policy that auto-expires inactive groups. | N | N |
| Device_ | A Device_Create operation (device-object creation) was logged under GroupManagement / self-service group management. | N | N |
| Device_ | Self-service group management deletes a device object (GroupManagement category; no official per-operation doc). | N | N |
| Device_ | Self-service group management reads a single device object (GroupManagement category; no official per-operation doc). | N | N |
| Device_ | Self-service group management enumerates all device objects (GroupManagement category; no official per-operation doc). | N | N |
| Download group members - finished (bulk) | A bulk export of a group's membership list to a CSV file finished. | N | N |
| Download groups - finished (bulk) | A bulk export of the tenant's groups list to a CSV file finished. | N | N |
| Features_ | Internal self-service group management call that reads feature flags; background process, not a user change. | N | N |
| Features_ | Internal self-service group management call checking whether a feature flag is enabled; background, not a user change. | N | N |
| Features_ | Internal self-service group management call that updates feature configuration (undocumented specifics). | N | N |
| Finish applying group based license to user | Group-based licensing finished applying a group's inherited product license to a user member. | N | N |
| Grant contextual consent to application | Consent granted to an application (per the name); exact semantics undocumented, GroupManagement/Core Directory category atypical for app consent. | N | N |
| Group_ | A member was added to a group via self-service group management. | N | N |
| Group_ | An owner was added to a group via self-service group management. | N | N |
| Group_ | Batch validation of a group's dynamic membership rule against selected users/devices (read-only evaluation). | N | N |
| Group_ | A group was created via self-service group management. | N | N |
| Group_ | Records deletion of a group via self-service group management; can remove an access-control boundary. | N | N |
| Group_ | Records a read of a single group's properties by self-service group management (read-only). | N | N |
| Group_ | Records a bulk enumeration of groups by self-service group management (read-only). | N | N |
| Group_ | Records a read of a group's dynamic membership configuration and rule (read-only). | N | N |
| Group_ | Records a read of selectable device attributes for authoring device-based dynamic membership rules (read-only). | N | N |
| Group_ | Records a read of supported dynamic membership rule operators (read-only). | N | N |
| Group_ | Records a read of selectable user attributes for the dynamic membership rule builder (read-only). | N | N |
| Group_ | Records a read of a group's expiration and renewal notification date (read-only). | N | N |
| Group_ | Records a read of a group's member list by self-service group management (read-only). | N | N |
| Group_ | Records a read of a group's owner list by self-service group management (read-only). | N | N |
| Group_ | Records removal of a member from a group via self-service group management; changes who holds group access. | N | N |
| Group_ | Records removal of an owner from a group via self-service group management; changes who can manage the group. | N | N |
| Group_ | A soft-deleted group was restored to an active state within the 30-day window. | N | N |
| Group_ | A group object's properties were updated in the directory. | N | N |
| Group_ | A group's dynamic membership rule was validated against sample users or devices. | N | N |
| Group | A group was added to the Microsoft 365 group expiration (lifecycle) policy. | N | N |
| Group | The Microsoft 365 group expiration (lifecycle) policy settings were accessed; despite the _Get name, first-party capture shows the record logs with AADOperationType Update. | Y | N |
| Group | A group was removed from the Microsoft 365 group expiration (lifecycle) policy. | N | N |
| Groups_ | A directory link (relationship) was created on a group object. | N | N |
| Groups_ | One or more group objects were read via the directory API. | N | N |
| Groups | A group's dynamic membership rule was evaluated for specified users or devices. | N | N |
| Groups | One or more group objects were read via the OData v4 directory endpoint. | N | N |
| Groups | The group expiration (lifecycle) policies were read via the OData v4 endpoint. | N | N |
| Hard Delete group | Permanent, unrecoverable deletion of an Entra group. | N | N |
| Lcm | A read of the Microsoft 365 group lifecycle (expiration) policy configuration. | N | N |
| Lcm | A Microsoft 365 group was renewed under the lifecycle (expiration) policy, extending its expiration. | N | N |
| Offboarded resource from PIM | A resource (likely a group) was offboarded from Privileged Identity Management governance. | N | N |
| Onboarded resource to PIM | A Microsoft Entra group was brought under PIM (PIM for Groups) for governed just-in-time membership/ownership. | N | N |
| Process request | PIM processed a membership or activation request for a privileged access group role. | N | N |
| Process role removal request | PIM processed a request to remove a privileged access group role assignment. | N | N |
| Reject a pending request to join a group | A pending self-service request to join a group was rejected by an owner or approver. | N | N |
| Remove app role assignment from group | An app role assignment was removed from a group, revoking the group's assignment to an application. | Y | N |
| Remove eligible member from group | A user's eligible group-membership assignment (PIM for Groups) was removed. | N | N |
| Remove eligible member from role in PIM completed (permanent) | PIM completed removal of a permanent (no-expiry) eligible member assignment (PIM for Groups). | N | N |
| Remove eligible member from role in PIM completed (timebound) | PIM completed removal of a time-bound (expiring) eligible member assignment (PIM for Groups). | N | N |
| Remove eligible member from role in PIM requested (permanent) | A PIM request was submitted to remove a permanent (no-expiry) eligible member assignment (PIM for Groups). | N | N |
| Remove eligible member from role in PIM requested (timebound) | A PIM request was submitted to remove a time-bound (expiring) eligible member assignment (PIM for Groups). | N | N |
| Remove eligible owner from group | A user's eligible owner assignment for a group (PIM for Groups) was removed. | N | N |
| Remove label from group | A sensitivity label was removed from a group, clearing its label-enforced settings. | N | N |
| Remove member from role (PIM activation expired) | PIM automatically removed a user's active role assignment because its activation period expired (end of just-in-time access). | N | N |
| Remove member from role completed (PIM deactivate) | PIM completed removing a user's active role assignment after the user manually deactivated it before expiry. | N | N |
| Remove member from role in PIM completed (permanent) | PIM completed removal of a member's permanent (non-expiring) role assignment. | N | N |
| Remove member from role in PIM requested (permanent) | Request submitted in PIM to remove a member's permanent (non-expiring) role assignment. | N | N |
| Remove member from role in PIM requested (timebound) | Request submitted in PIM to remove a member's time-bound (expiring) role assignment. | N | N |
| Remove member from role requested (PIM deactivate) | Request submitted in PIM to deactivate a user's active role assignment (precedes the completed removal). | N | N |
| Remove owner from group | An owner was removed from a Microsoft Entra group, revoking their ability to manage its membership and settings. | N | N |
| Remove permanent direct role assignment | A permanent (non-expiring) active, directly assigned PIM role/membership was removed. | N | N |
| Remove permanent eligible role assignment | A permanent (non-expiring) eligible PIM role/membership was removed, revoking the ability to activate it. | N | N |
| Renew group | A Microsoft 365 group was renewed under the expiration policy, resetting its expiration timer. | N | N |
| Request to join a group | A user submitted a self-service request to join a group via the My Groups portal (owner-approved or auto-accepted). | N | N |
| Resource updated | A group resource managed by Privileged Identity Management was updated. | N | N |
| Restore eligible member from role in PIM completed | PIM completed restoring a member's eligible assignment to a PIM-managed group role. | N | N |
| Restore group | A soft-deleted Microsoft 365 or cloud security group was restored. | N | N |
| Restore member from role | PIM restored a member's active assignment to a PIM-managed group role. | N | N |
| Restore member from role in PIM completed | PIM completed restoring a member's active assignment to a PIM-managed group role. | N | N |
| Restore permanent direct role assignment | A permanent, directly assigned (standing/active) role assignment was restored through Privileged Identity Management. | N | N |
| set dynamic group properties | The dynamic-membership properties (such as the membership rule) of a group were set or modified. | N | N |
| Set group license | A license was assigned to or configured on a group for group-based licensing. | N | N |
| Set group to be managed by user | A group was set to be managed by a user. | N | N |
| Settings_ | Self-service group management settings were accessed; despite the _Get name, first-party capture shows the record logs with AADOperationType Update. | Y | N |
| Start applying group based license to users | Group-based licensing began applying a group-assigned license to its member users. | N | N |
| Trigger group license recalculation | Manually triggered reprocessing/recalculation of a group's member license assignments. | N | N |
| Update eligible member in PIM canceled (extend) | An extend request for an eligible PIM-for-Groups membership was canceled. | N | N |
| Update eligible member in PIM requested (extend) | An extend was requested for an eligible PIM-for-Groups membership. | N | N |
| Update group settings | Directory group settings (e.g. naming policy, guest access, classifications for Microsoft 365 groups) were updated. | N | N |
| Update lifecycle management policy | Change to the Microsoft 365 group expiration/lifecycle policy (lifetime, auto-renewal, expiration). | N | N |
| Update member in PIM approved by admin (extend/renew) | Admin approved a request to extend or renew a member's PIM for Groups assignment. | N | N |
| Update member in PIM canceled (extend) | A request to extend a member's PIM for Groups assignment was canceled. | N | N |
| Update member in PIM denied by admin (extend/renew) | An admin denied a request to extend or renew a PIM for Groups membership assignment. | N | N |
| Update member in PIM requested (extend) | A user requested to extend an expiring PIM for Groups membership assignment. | N | N |
| User_ | Self-service group management service User_Create operation; a GroupManagement background-process activity. | N | N |
| User_ | Self-service group management service User_Delete operation; a GroupManagement background-process activity. | N | N |
| User_ | Self-service group management read of a user object; a GroupManagement background-process read, not a change. | N | N |
| User_ | Self-service group management enumeration of user objects; a GroupManagement background-process read, not a change. | N | N |
| User_ | Self-service group management read of a user's group memberships (memberOf); a GroupManagement background read. | N | N |
| User_ | Self-service group management read of objects a user owns (ownedObjects); a GroupManagement background read. | N | N |
| Approval | Deletion of a self-service group membership approval notification (the delete-pair of ApprovalNotification_Create), e.g. once the pending request is approved, denied, or withdrawn. | Y | N |
Add group
#Description
A new group was created.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:17.2776205Z",
"ActivityDisplayName": "Add group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "GroupManagement",
"CorrelationId": "e873fe43-be40-477a-84a4-e3b9489c732f",
"DurationMs": "0",
"Id": "Directory_e873fe43-be40-477a-84a4-e3b9489c732f_8RFCI_150627422",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "5df79817-5976-4c4a-bd9c-77df6e5786ad",
"displayName": "dw-harness-ara-cf516524",
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [
{
"displayName": "DisplayName",
"oldValue": [],
"newValue": [
"dw-harness-ara-cf516524"
]
},
{
"displayName": "MailEnabled",
"oldValue": [],
"newValue": [
false
]
},
{
"displayName": "MailNickname",
"oldValue": [],
"newValue": [
"dwharacf516524"
]
},
{
"displayName": "RenewedDateTime",
"oldValue": [],
"newValue": [
"2026-07-24T03:21:17Z"
]
},
{
"displayName": "SecurityEnabled",
"oldValue": [],
"newValue": [
true
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"DisplayName, MailEnabled, MailNickname, RenewedDateTime, SecurityEnabled\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Add member to group
#Description
A principal was added as a member of a group (including role-assignable groups).
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:19:46.1894794Z",
"ActivityDisplayName": "Add member to group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "GroupManagement",
"CorrelationId": "61c04a77-5126-4f2c-84a1-f3aca38309b7",
"DurationMs": "0",
"Id": "Directory_61c04a77-5126-4f2c-84a1-f3aca38309b7_X47R8_4063656",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add member to group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Group.ObjectID",
"oldValue": null,
"newValue": "\"8184e228-f3d3-43d9-9cf3-09665fb9cd8d\""
},
{
"displayName": "Group.DisplayName",
"oldValue": null,
"newValue": "\"dw-harness-cf516524\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "8184e228-f3d3-43d9-9cf3-09665fb9cd8d",
"displayName": null,
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004, T1087, T1087.004, T1136, T1136.003↳ also matches Add owner to group T1556, T1556.009↳ also matches Add named location, Delete conditional access policy, Remove member from group, Update conditional access policy, Update named location
References #
Add owner to group
#Description
An owner was added to a group.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:19:51.5116163Z",
"ActivityDisplayName": "Add owner to group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "GroupManagement",
"CorrelationId": "5301c94e-6c3e-4cf0-ae8e-11e2c62b2a2c",
"DurationMs": "0",
"Id": "Directory_5301c94e-6c3e-4cf0-ae8e-11e2c62b2a2c_YYFAW_3646618",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add owner to group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Group.ObjectID",
"oldValue": null,
"newValue": "\"3016e04a-149a-496f-aab9-b09966542ba9\""
},
{
"displayName": "Group.DisplayName",
"oldValue": null,
"newValue": "\"dw-harness-owner-cf516524\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "3016e04a-149a-496f-aab9-b09966542ba9",
"displayName": null,
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004, T1087, T1087.004, T1136, T1136.003↳ also matches Add member to group
References #
Delete group
#Description
A group was deleted.
Example Audit Log Entry #
{
"AADOperationType": "Delete",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:24.1726196Z",
"ActivityDisplayName": "Delete group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "GroupManagement",
"CorrelationId": "9296befc-0d42-4441-8e6e-47d96e31546e",
"DurationMs": "0",
"Id": "Directory_9296befc-0d42-4441-8e6e-47d96e31546e_3U00I_146365977",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Delete group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "5df79817-5976-4c4a-bd9c-77df6e5786ad",
"displayName": "dw-harness-ara-cf516524",
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [
{
"displayName": "DeletionType",
"oldValue": "\"SoftDelete\"",
"newValue": null
},
{
"displayName": "GroupType",
"oldValue": "\"Security group with static membership\"",
"newValue": null
},
{
"displayName": "CreatedDateTime",
"oldValue": "\"2026-07-24T03:21:17Z\"",
"newValue": null
},
{
"displayName": "LastUpdatedDateTime",
"oldValue": "\"2026-07-24T03:21:17Z\"",
"newValue": null
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Remove member from group
#Description
A principal was removed from a group.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:19:46.9631371Z",
"ActivityDisplayName": "Remove member from group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "GroupManagement",
"CorrelationId": "2f5bd815-ab6b-4f33-8996-da5a01de0350",
"DurationMs": "0",
"Id": "Directory_2f5bd815-ab6b-4f33-8996-da5a01de0350_V5X8A_147610754",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove member from group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Group.ObjectID",
"oldValue": "\"8184e228-f3d3-43d9-9cf3-09665fb9cd8d\"",
"newValue": null
},
{
"displayName": "Group.DisplayName",
"oldValue": "\"dw-harness-cf516524\"",
"newValue": null
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "8184e228-f3d3-43d9-9cf3-09665fb9cd8d",
"displayName": null,
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1548, T1556Kusto #
T1556, T1556.009↳ also matches Add member to group, Add named location, Delete conditional access policy, Update conditional access policy, Update named location
References #
Update group
#Description
A group's properties were modified.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:19:47.7368214Z",
"ActivityDisplayName": "Update group",
"AdditionalDetails": [
{
"key": "GroupType",
"value": ""
},
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "GroupManagement",
"CorrelationId": "185ceae3-cdc2-4d77-ab3c-1d724ead2818",
"DurationMs": "0",
"Id": "Directory_185ceae3-cdc2-4d77-ab3c-1d724ead2818_L0ZAX_143093841",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "8184e228-f3d3-43d9-9cf3-09665fb9cd8d",
"displayName": "dw-harness-cf516524",
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [
{
"displayName": "Description",
"oldValue": [],
"newValue": [
"updated"
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"Description\""
},
{
"displayName": "TargetId.GroupType",
"oldValue": null,
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1484
References #
Add app role assignment to group
#Description
A group was assigned an application app role, granting the group's members the associated access to (or role within) the application or service principal. Assigning a group to a privileged app role can broaden access for many users at once and is relevant to access-expansion and persistence monitoring.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:20.2336243Z",
"ActivityDisplayName": "Add app role assignment to group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "GroupManagement",
"CorrelationId": "301d696a-7894-4d35-9d93-1581729c5893",
"DurationMs": "0",
"Id": "Directory_301d696a-7894-4d35-9d93-1581729c5893_GGUBC_10747604",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add app role assignment to group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AppRole.Id",
"oldValue": null,
"newValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\""
},
{
"displayName": "AppRole.Value",
"oldValue": null,
"newValue": "\"dwharness\""
},
{
"displayName": "AppRole.DisplayName",
"oldValue": null,
"newValue": "\"dwharness\""
},
{
"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": null,
"newValue": "\"2026-07-24T03:21:20.0076225Z\""
},
{
"displayName": "AppRoleAssignment.LastModifiedDateTime",
"oldValue": null,
"newValue": "\"2026-07-24T03:21:20.0076225Z\""
},
{
"displayName": "Group.ObjectID",
"oldValue": null,
"newValue": "\"5df79817-5976-4c4a-bd9c-77df6e5786ad\""
},
{
"displayName": "Group.DisplayName",
"oldValue": null,
"newValue": "\"dw-harness-ara-cf516524\""
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "5df79817-5976-4c4a-bd9c-77df6e5786ad",
"displayName": null,
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Add eligible member to role in PIM canceled (renew)
#Description
A request to renew an eligible membership (the group's Member role) for a PIM-managed group was canceled before completion. PIM for Groups eligible assignments grant just-in-time membership that the principal must activate, and renew extends an existing eligible assignment.
References #
Add eligible member to role in PIM canceled (timebound)
#Description
A request to add a time-bound (expiring) eligible membership (the group's Member role) for a PIM-managed group was canceled before completion. Eligible PIM for Groups membership confers no standing access until the principal activates it.
References #
Add eligible member to role in PIM completed (timebound)
#Description
A time-bound (expiring) eligible membership (the group's Member role) for a PIM-managed group was successfully created. The principal can then activate the membership during the bounded window; granting eligibility to privileged groups, especially groups that elevate into Microsoft Entra roles, is a persistence and privilege-escalation vector.
References #
Add eligible member to role in PIM requested (permanent)
#Description
A request was submitted to add a permanent (non-expiring) eligible membership (the group's Member role) for a PIM-managed group. Permanently eligible principals can activate the group membership at any time, so requests targeting privileged groups warrant review.
References #
Add eligible member to role in PIM requested (renew)
#Description
A request was submitted to renew an eligible membership (the group's Member role) for a PIM-managed group, extending an existing eligible assignment. The renewal takes effect only after any required approval and processing complete.
References #
Add eligible member to role in PIM requested (timebound)
#Description
A request was submitted to add a time-bound (expiring) eligible membership (the group's Member role) for a PIM-managed group. The eligible assignment takes effect after any required approval; the principal must then activate it to use the membership.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Operation (kusto rule field) | eq | add-mailboxpermission | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1548
References #
Add member to role canceled (PIM activation)
#Description
A pending Privileged Identity Management activation request for an eligible Microsoft Entra role was canceled before it completed. Detection relevance: a canceled activation can mark an aborted or mistaken privilege-elevation attempt.
References #
Add member to role in PIM canceled (permanent)
#Description
A request to create a permanent (no-expiration) Microsoft Entra role assignment through Privileged Identity Management was canceled before completion.
References #
Add member to role in PIM canceled (renew)
#Description
A request to renew or extend an expiring Microsoft Entra role assignment through Privileged Identity Management was canceled before completion.
References #
Add member to role in PIM canceled (timebound)
#Description
A request to create a time-bound (expiring) Microsoft Entra role assignment through Privileged Identity Management was canceled before completion.
References #
Add member to role in PIM completed (permanent)
#Description
A permanent (no-expiration) Microsoft Entra role assignment was successfully created through Privileged Identity Management. Detection relevance: permanent role assignments grant standing privilege and are a common persistence and privilege-escalation target.
References #
Add member to role in PIM requested (renew)
#Description
A request was submitted through Privileged Identity Management to renew or extend an expiring Microsoft Entra role assignment.
References #
Add member to role request approved (PIM activation)
#Description
A designated approver approved a pending Privileged Identity Management activation request for an eligible Microsoft Entra role, allowing the just-in-time elevation to proceed. Detection relevance: approval is the control gate for just-in-time privilege elevation, so approver identity and timing are key signals for spotting collusion or approval abuse.
References #
Add member to role requested (PIM activation)
#Description
Records a Privileged Identity Management (PIM) just-in-time activation request in which the requestor asks to be added as a member of an eligible assignment. The GroupManagement category indicates the PIM-for-Groups variant, where a user activates eligible membership of a Microsoft Entra security or Microsoft 365 group; because such groups can govern access to roles, Azure resources, and applications, unexpected or frequent activation requests warrant review.
References #
Approval_Act
#Description
Records an action taken on a self-service group management approval, such as an approver approving or denying a pending self-service group membership request. This is an internal operation name in the self-service group management approval workflow.
References #
Approval_Get
#Description
Records retrieval of a single self-service group management approval request, for example loading the details of one pending group membership approval. Internal operation name in the self-service group management approval workflow; a read operation with low standalone detection value.
References #
Approval_GetAll
#Description
Records the internal Approval_GetAll operation in the self-service group management approval workflow, named as a retrieval of all approval requests (such as listing an approver's pending group membership approval queue). Despite the _GetAll name, first-party capture shows the record carries AADOperationType Update, so filters that classify operations by AADOperationType bucket it with directory updates, not reads. Low standalone detection value.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-03T02:51:16.1780577Z",
"ActivityDisplayName": "Approval_GetAll",
"AdditionalDetails": [],
"Category": "GroupManagement",
"CorrelationId": "657dfd0b-18f6-4933-8eea-0e5131de229d",
"DurationMs": "0",
"Id": "SSGM_657dfd0b-18f6-4933-8eea-0e5131de229d_QFMOD_97457922",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Self-service Group Management",
"OperationName": "Approval_GetAll",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultDescription": "OK",
"ResultReason": "OK",
"ResultSignature": "None",
"TargetResources": [
{
"id": "00000000-0000-0000-0000-000000000000",
"displayName": null,
"type": "N/A",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
ApprovalNotification_Create
#Description
Records creation of a notification for a self-service group management approval request, such as notifying an approver that a group membership request is awaiting their decision. Internal operation name in the self-service group management approval workflow.
References #
Approvals_Post
#Description
Records a create/submit operation against the self-service group management approval endpoint, such as a self-service group membership approval request or decision being posted. Internal operation name in the self-service group management approval workflow; the exact object is not individually documented.
References #
Approve a pending request to join a group
#Description
Records a group owner approving a user's pending request to join a self-service-managed security or Microsoft 365 group, which adds the requester as a member. Because group membership can confer access to applications and resources, unexpected approvals into privileged groups are worth reviewing.
References #
Assign label to group
#Description
Records the assignment of a sensitivity label to a Microsoft 365 group. Sensitivity labels can govern a group's privacy, guest and external-sharing behavior, and related access settings, so a label change can alter the group's security posture.
References #
Bulk import group members - finished (bulk)
#Description
Records that a bulk operation to add members to a group from an uploaded CSV finished. Mass additions to an access-granting or privileged group can indicate privilege escalation.
References #
Bulk remove group members - finished (bulk)
#Description
Records that a bulk operation to remove members from a group using an uploaded CSV finished. Mass removal from a security or access group can disrupt legitimate access or be used to obscure membership changes.
References #
Cancel a pending request to join a group
#Description
Records that a user canceled their own pending request to join a self-service-managed group whose membership requires owner approval.
References #
Cancel request for role removal
#Description
A pending Privileged Identity Management (PIM) request to remove a role assignment was cancelled before it was processed. The GroupManagement audit category scopes this activity to PIM for Groups (PIM also emits the same activity under RoleManagement and ResourceManagement for directory roles and Azure resource roles).
References #
Cancel request for role update
#Description
A pending Privileged Identity Management (PIM) request to update (modify) a role assignment was cancelled before it was processed. The GroupManagement audit category scopes this activity to PIM for Groups (PIM also emits the same activity under RoleManagement and ResourceManagement for directory roles and Azure resource roles).
References #
Create group settings
#Description
A group settings (directory settings) object was created to configure Microsoft 365 group behavior, instantiated from the Group.Unified or Group.Unified.Guest template. These settings control behaviors such as group naming policy, guest access, and classification or sensitivity labeling, applied tenant-wide or to a specific group.
References #
Create lifecycle management policy
#Description
A group lifecycle (expiration) policy was created, defining the lifetime, expiration, and renewal behavior applied to Microsoft 365 groups in the tenant.
References #
Delete a pending request to join a group
#Description
Records deletion/withdrawal of a pending self-service group-management request to join a group, before a group owner has approved or denied it. Self-service group management lets users request to join security or Microsoft 365 groups subject to owner approval.
References #
Delete group settings
#Description
A directory group settings object was deleted. Group settings are directorySetting objects created from a template such as Group.Unified that configure tenant-wide or group-level behavior; because tenant defaults apply when no settings object exists, deleting one reverts those behaviors to defaults, for example removing a group naming policy.
References #
Delete lifecycle management policy
#Description
Records deletion of the Microsoft 365 group expiration (lifecycle) policy, which automatically expires and soft-deletes inactive groups that are not renewed within the configured period. Removing it stops automated cleanup of stale, self-service-created groups.
References #
Device_Create
#Description
A Device_Create operation logged under GroupManagement in the self-service group management activity set, recording creation of a device object through that portal/API surface. It appears alongside Device_Delete, Device_Get, and Device_GetAll; the reference notes many activities in this set are background processes tied to a user's portal activity, so the entry does not by itself confirm an interactive administrative change.
References #
Device_Delete
#Description
Records the deletion of a device object by the Microsoft Entra self-service group management service, logged under the GroupManagement audit category. It appears to be an internal/background operation of the self-service group management feature rather than a directly initiated administrative action.
References #
Device_Get
#Description
Records a read/retrieval of a single device object by the Microsoft Entra self-service group management service, logged under the GroupManagement audit category. It appears to be an internal/background read operation of the self-service group management feature rather than a directly initiated administrative action.
References #
Device_GetAll
#Description
Records an enumeration/retrieval of all device objects by the Microsoft Entra self-service group management service, logged under the GroupManagement audit category. It appears to be an internal/background read operation of the self-service group management feature rather than a directly initiated administrative action.
References #
Download group members - finished (bulk)
#Description
A bulk operation that exports a group's membership list to a CSV file from the Microsoft Entra admin center finished.
References #
Download groups - finished (bulk)
#Description
A bulk operation that exports the tenant's list of groups to a CSV file from the Microsoft Entra admin center finished.
References #
Features_GetFeaturesAsync
#Description
Records an internal self-service group management call that reads feature configuration/flags. It is a background/system call and does not by itself indicate a user-initiated change.
References #
Features_IsFeatureEnabledAsync
#Description
Records an internal self-service group management call that checks whether a specific feature flag is enabled. It is a background/system call and does not by itself indicate a user-initiated change.
References #
Features_UpdateFeaturesAsync
#Description
Records an internal self-service group management call that writes or updates feature configuration. Microsoft does not document which settings it changes, and community guidance characterizes the Features_* calls as internal operations rather than direct user actions, so any apparent write here should be verified before being treated as a meaningful configuration change.
References #
Finish applying group based license to user
#Description
The group-based licensing engine finished applying a group's product license assignment to a user who is a member of a licensed group, completing propagation of the inherited license. Microsoft Entra automatically manages these license modifications in response to group membership changes, so the operation reflects an automated background process rather than an interactive administrator action.
References #
Grant contextual consent to application
#Description
The operation name indicates that consent was granted to an application. Microsoft Learn does not document this exact operation name, and its GroupManagement category with Core Directory service is atypical for an application-consent operation: the documented app-consent audit operation is 'Consent to application' under ApplicationManagement. If this does record an application-consent grant, such grants authorize the OAuth permissions (scopes) an app requests and are a known illicit-consent and OAuth-abuse vector.
References #
Group_AddOwner
#Description
Records that an owner was added to a group through self-service group management. Because group owners can manage membership, adding an owner grants administrative control over the group and is relevant to privilege escalation and persistence.
References #
Group_BatchValidateDynamicMembership
#Description
Records a batch validation of a group's dynamic membership rule against a selected set of users or devices, confirming whether each would be included by the rule (the portal allows up to 20 per validation). A read-only evaluation that does not itself change group membership.
References #
Group_Create
#Description
Records that a group was created through self-service group management. By default the creating user becomes the group's owner and can add members; unexpected or bulk group creation can support access staging or lateral movement.
References #
Group_Delete
#Description
Records the deletion of a group through Microsoft Entra self-service group management. Because groups commonly gate access to resources, applications, and Conditional Access policies, deletion of an access-granting group can disrupt access or remove an access-control boundary, making it relevant to destruction and defense-evasion monitoring.
References #
Group_Get
#Description
Records a read of a single group's properties by the Microsoft Entra self-service group management service. As a read-only retrieval it does not change directory state and carries limited standalone detection value.
References #
Group_GetAll
#Description
Records a bulk read that enumerates groups through the Microsoft Entra self-service group management service. As a read-only enumeration it does not modify the directory, though group enumeration can be associated with discovery and reconnaissance of access relationships.
References #
Group_GetDynamicGroupProperties
#Description
Records retrieval of a group's dynamic membership configuration, including the dynamic membership rule and related properties, within self-service group management. It is a read-only metadata call that supports authoring of a dynamic membership group rule and does not change group state.
References #
Group_GetDynamicMembershipDeviceAttributes
#Description
Records retrieval of the device attributes available for building a device-based dynamic membership rule (for example deviceOSType, deviceManufacturer, and deviceTrustType). It is a read-only metadata call that surfaces the selectable device-attribute choices when authoring a device-based dynamic membership rule.
References #
Group_GetDynamicMembershipOperators
#Description
Records retrieval of the expression operators supported in dynamic membership rules (for example -eq, -ne, -contains, and -startsWith). It is a read-only metadata call that populates the operator choices in the dynamic membership rule builder.
References #
Group_GetDynamicMembershipUserBaseAttributes
#Description
Records retrieval of the user attributes available for building a user-based dynamic membership rule (for example department, city, and userType). It is a read-only metadata call that populates the user-attribute choices in the dynamic membership rule builder.
References #
Group_GetExpiryNotificationDate
#Description
Records retrieval of a group's expiration notification date, the value associated with Microsoft Entra group expiration and renewal. It is a read-only metadata retrieval and does not change group state.
References #
Group_GetMembers
#Description
Records a read of a group's membership list through the Microsoft Entra self-service group management service. As a read-only retrieval it does not modify the directory, though enumerating group membership can appear during reconnaissance of access relationships.
References #
Group_GetOwners
#Description
Records a read of a group's owner list through the Microsoft Entra self-service group management service. Because owners control a group's membership, enumerating owners can be part of mapping who can modify a group, but the operation itself is read-only.
References #
Group_RemoveMember
#Description
Records removal of a member from a group through Microsoft Entra self-service group management. Removing a member from an access-granting or role-assignable group changes who holds that access, so the operation can revoke access or disrupt legitimate access.
References #
Group_RemoveOwner
#Description
Records removal of an owner from a group through Microsoft Entra self-service group management. Because owners can manage a group's membership, changing group ownership affects who can administer the group and can be relevant to account-takeover and persistence scenarios.
References #
Group_Restore
#Description
Records the restoration of a soft-deleted group back to an active state within the 30-day recovery window before automatic permanent deletion. Restoring a group reinstates the access its membership conferred, so the event can be relevant to persistence or to reversing a defensive removal.
References #
Group_Update
#Description
Records an update to a group object's properties in the directory, such as its display name or description. Changes to a group's configuration can be relevant to detection when they alter how the group governs access.
References #
Group_ValidateDynamicMembership
#Description
Records validation of a group's dynamic membership rule, checking whether selected users or devices match the rule's criteria. It is an administrative test action used when authoring or troubleshooting dynamic group rules and does not itself change membership.
References #
GroupLifecyclePolicies_addGroup
#Description
Records adding a group to the Microsoft 365 group expiration (lifecycle) policy, bringing the group under the configured expiration and renewal schedule.
References #
GroupLifecyclePolicies_Get
#Description
Records the GroupLifecyclePolicies_Get operation against the Microsoft 365 group expiration (lifecycle) policy, whose settings include the group lifetime in days and alternate notification email addresses. Despite the _Get name, first-party capture shows the record carries AADOperationType Update, so filters that classify operations by AADOperationType bucket it with directory updates, not reads.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-02T12:42:06.626196Z",
"ActivityDisplayName": "GroupLifecyclePolicies_Get",
"AdditionalDetails": [],
"Category": "GroupManagement",
"CorrelationId": "d7feedf2-f412-4022-8c8d-78862875590c",
"DurationMs": "0",
"Id": "SSGM_d7feedf2-f412-4022-8c8d-78862875590c_LH0EU_123920572",
"InitiatedBy": {
"user": {
"displayName": null,
"agentType": "notAgentic",
"id": "0a019885-4e71-49eb-8290-0977a254d286",
"userPrincipalName": null,
"ipAddress": "203.0.113.10",
"roles": []
}
},
"LoggedByService": "Self-service Group Management",
"OperationName": "GroupLifecyclePolicies_Get",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultDescription": "OK",
"ResultReason": "OK",
"ResultSignature": "None",
"TargetResources": [
{
"id": "00000000-0000-0000-0000-000000000000",
"displayName": null,
"type": "N/A",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
GroupLifecyclePolicies_removeGroup
#Description
Records removing a group from the Microsoft 365 group expiration (lifecycle) policy, so the group is no longer governed by the configured expiration and renewal schedule.
References #
Groups_CreateLink
#Description
Records the creation of a directory relationship (link) on a group object, associating it with a related object such as a member, owner, or parent group. Because associating a member or owner can confer access, such link-creation events can be relevant to privilege-escalation or persistence detection.
References #
Groups_Get
#Description
Records a read or retrieval of one or more group objects via the directory API. Read operations can be relevant to detection as reconnaissance or enumeration of a tenant's groups.
References #
GroupsODataV4_evaluateDynamicMembership
#Description
Records an evaluation of a group's dynamic membership rule through the OData v4 directory endpoint, determining whether specified users or devices satisfy the rule. It is a test/troubleshooting action and does not by itself modify group membership.
References #
GroupsODataV4_Get
#Description
Records a read or retrieval of one or more group objects through the OData v4 directory endpoint. As with other read operations, it can indicate enumeration or reconnaissance of tenant groups.
References #
GroupsODataV4_GetgroupLifecyclePolicies
#Description
Records a read of the Microsoft 365 group expiration (lifecycle) policies through the OData v4 directory endpoint, returning the configured expiration and renewal settings.
References #
Hard Delete group
#Description
Records the permanent (hard) deletion of a group from the Microsoft Entra tenant. For Microsoft 365 and cloud security groups this is the irreversible hard delete that follows the soft-deleted state (after 30 days or an explicit permanent delete); hard-deleted groups cannot be restored and must be recreated.
References #
LcmPolicy_Get
#Description
Records a read of the Microsoft 365 group lifecycle-management (expiration) policy configuration. The group expiration policy governs how Microsoft 365 groups expire and are renewed; this operation reflects retrieval of that policy's settings rather than a change to any group.
References #
LcmPolicy_RenewGroup
#Description
Records that a Microsoft 365 group was renewed under the group lifecycle-management (expiration) policy, extending the group's expiration date. Renewal can occur automatically based on group activity across Microsoft 365 services (Outlook, SharePoint, Teams, Viva Engage) or when a group owner renews from an expiration notice.
References #
Offboarded resource from PIM
#Description
Records that a resource managed by Privileged Identity Management was offboarded, removing it from PIM's just-in-time, eligibility-based governance of privileged access. Given the GroupManagement category, this most likely reflects a group being taken out of PIM management; removing a resource from PIM reduces oversight of privileged access and can be relevant to defense evasion or persistence.
References #
Onboarded resource to PIM
#Description
Records that a Microsoft Entra group was brought under Privileged Identity Management management (PIM for Groups), so PIM governs just-in-time eligible and active membership and ownership of the group. The GroupManagement audit category is consistent with a group being onboarded; once a group is managed in PIM it can't be taken back out of management.
References #
Process request
#Description
Records Privileged Identity Management processing a membership or activation request for a privileged access group role (member or owner). PIM activations grant just-in-time privileged access, so these records are relevant to privilege-escalation monitoring.
References #
Process role removal request
#Description
Records Privileged Identity Management processing a request to remove a role assignment for a privileged access group (member or owner role). Removal of privileged role assignments is relevant to access-governance and tamper monitoring.
References #
Reject a pending request to join a group
#Description
A pending self-service request to join a group was rejected (denied) by a group owner or approver. It records a self-service group-management approval decision in My Groups.
References #
Remove app role assignment from group
#Description
An app role assignment was removed from a group, revoking that group's assignment to an application and any app role it conferred. Changes to application access assignments are relevant to access-governance monitoring.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:21.0562391Z",
"ActivityDisplayName": "Remove app role assignment from group",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "GroupManagement",
"CorrelationId": "d09cdab2-701d-4806-95b5-e3bdbf26c2bc",
"DurationMs": "0",
"Id": "Directory_d09cdab2-701d-4806-95b5-e3bdbf26c2bc_BOAS4_10223860",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove app role assignment from group",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AppRole.Id",
"oldValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\"",
"newValue": null
},
{
"displayName": "AppRole.Value",
"oldValue": null,
"newValue": null
},
{
"displayName": "AppRole.DisplayName",
"oldValue": null,
"newValue": null
},
{
"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": "\"2026-07-24T03:21:20.0076225Z\"",
"newValue": null
},
{
"displayName": "AppRoleAssignment.LastModifiedDateTime",
"oldValue": "\"2026-07-24T03:21:20.0076225Z\"",
"newValue": null
},
{
"displayName": "Group.ObjectID",
"oldValue": "\"5df79817-5976-4c4a-bd9c-77df6e5786ad\"",
"newValue": null
},
{
"displayName": "Group.DisplayName",
"oldValue": "\"dw-harness-ara-cf516524\"",
"newValue": null
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "5df79817-5976-4c4a-bd9c-77df6e5786ad",
"displayName": null,
"type": "Group",
"groupType": "unknownFutureValue",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Remove eligible member from group
#Description
Records removal of a user's eligible membership assignment for a group in Privileged Identity Management (PIM for Groups), where eligibility lets the principal activate group membership on demand rather than holding it standing.
References #
Remove eligible member from role in PIM completed (permanent)
#Description
Records that a Privileged Identity Management request to remove a permanent (no-expiry) eligible member assignment completed and took effect. In this GroupManagement context it applies to PIM for Groups, where the role is the group's member role.
References #
Remove eligible member from role in PIM completed (timebound)
#Description
Records that a Privileged Identity Management request to remove a time-bound (expiring) eligible member assignment completed and took effect, in the PIM for Groups context where the role is the group's member role.
References #
Remove eligible member from role in PIM requested (permanent)
#Description
Records that a request was submitted in Privileged Identity Management to remove a permanent (no-expiry) eligible member assignment; the request precedes the corresponding completed event and may await processing or approval. Applies to PIM for Groups, where the role is the group's member role.
References #
Remove eligible member from role in PIM requested (timebound)
#Description
Records that a request was submitted in Privileged Identity Management to remove a time-bound (expiring) eligible member assignment; the request precedes the corresponding completed event. Applies to PIM for Groups, where the role is the group's member role.
References #
Remove eligible owner from group
#Description
Records removal of a user's eligible owner assignment for a group in Privileged Identity Management (PIM for Groups), where eligibility lets the principal activate group ownership on demand. Group ownership can confer membership and access control, so changes are privilege-relevant.
References #
Remove label from group
#Description
Records removal of a sensitivity label from a group, clearing the label-enforced settings (such as privacy and guest-access controls) that were previously applied to the Microsoft 365 group and its connected workspace.
References #
Remove member from role (PIM activation expired)
#Description
Records Privileged Identity Management automatically removing a user's active role assignment because the activation period it was granted for expired. This is an expected just-in-time privilege-lifecycle event marking the automatic end of activated access rather than an administrator-initiated change.
References #
Remove member from role completed (PIM deactivate)
#Description
Records Privileged Identity Management completing the removal of a user's active role assignment after the user manually deactivated it before its activation period expired. Marks the voluntary end of activated just-in-time access.
References #
Remove member from role in PIM completed (permanent)
#Description
Records Privileged Identity Management completing removal of a member's permanent (non-expiring) role assignment. Removing a standing privileged assignment reduces who holds the role; it pairs with the corresponding 'requested' entry for the same change.
References #
Remove member from role in PIM requested (permanent)
#Description
Records a request submitted in Privileged Identity Management to remove a member's permanent (non-expiring) role assignment. This is the request stage that precedes the matching 'completed' entry.
References #
Remove member from role in PIM requested (timebound)
#Description
Records a request submitted in Privileged Identity Management to remove a member's time-bound (expiring) role assignment, the request stage that precedes the corresponding 'completed' entry.
References #
Remove member from role requested (PIM deactivate)
#Description
Records a request submitted in Privileged Identity Management to deactivate a user's active role assignment. This is the request stage that precedes PIM completing the deactivation and removing the active assignment.
References #
Remove owner from group
#Description
Records that an owner was removed from a Microsoft Entra group, revoking that principal's ability to manage the group's membership and settings. On role-assignable or access-granting groups, unexpected owner removals can indicate tampering with group governance.
References #
Remove permanent direct role assignment
#Description
Records that a permanent (non-expiring) active, directly assigned role or privileged-access-group membership managed through Privileged Identity Management was removed. Removal of privileged assignments can be legitimate cleanup or an attempt to obscure prior access.
References #
Remove permanent eligible role assignment
#Description
Records that a permanent (non-expiring) eligible role or privileged-access-group membership managed through Privileged Identity Management was removed, revoking the principal's ability to activate that role or membership.
References #
Renew group
#Description
A Microsoft 365 group was renewed under the group expiration policy, resetting its expiration timer so the group is not deleted. Renewal can be performed by a group owner or applied automatically by Microsoft Entra based on recent activity.
References #
Request to join a group
#Description
Records a user's self-service request to join a group through the My Groups portal. For owner-approved groups the request is held pending a group owner's approval or denial; for self-service groups configured to auto-accept, membership is granted automatically.
References #
Resource updated
#Description
Records that a resource managed by Privileged Identity Management was updated; the GroupManagement category and PIM service indicate the resource is a group onboarded to PIM for Groups. The entry reflects a change to that managed group's PIM configuration or metadata.
References #
Restore eligible member from role in PIM completed
#Description
Records that Privileged Identity Management completed restoring a member's eligible assignment to a PIM-managed group role. The 'completed' suffix marks the end of the asynchronous PIM restore operation, reinstating the member's eligibility to activate the group role.
References #
Restore group
#Description
Records that a soft-deleted Microsoft 365 group or cloud security group was restored to an active state. Groups are recoverable for 30 days with their properties retained, including memberships and application assignments, so restoring a security group can re-establish the access tied to that group.
References #
Restore member from role
#Description
Records that Privileged Identity Management restored a member's active assignment to a PIM-managed group role, reinstating a previously removed membership in the group's member or owner role.
References #
Restore member from role in PIM completed
#Description
Records that Privileged Identity Management completed restoring a member's active assignment to a PIM-managed group role. The 'completed' suffix marks the end of the asynchronous PIM restore operation that reinstates the membership.
References #
Restore permanent direct role assignment
#Description
A permanent, directly assigned role assignment was restored through Privileged Identity Management, reinstating standing (active) privileged access for the principal rather than mere eligibility. A restored standing role assignment is relevant to privilege-escalation and persistence monitoring.
References #
set dynamic group properties
#Description
The dynamic-membership properties of a group were set or modified, such as the membership rule that determines automatic group membership. Altering a dynamic membership rule can silently change which principals belong to the group, and any access the group grants, which is relevant to access-escalation monitoring.
References #
Set group license
#Description
A license was assigned to or configured on a group for group-based licensing, so members of the group inherit the assigned license plans. Related downstream activities include applying group-based licenses to individual users.
References #
Set group to be managed by user
#Description
A group was set to be managed by a user, assigning user-based management of the group. The operation name alone does not specify the exact management semantics, so this is described conservatively.
References #
Settings_GetSettingsAsync
#Description
Records the internal Settings_GetSettingsAsync operation against the self-service group management settings. Despite the _Get name, first-party capture shows the record carries AADOperationType Update, so filters that classify operations by AADOperationType bucket it with directory updates, not reads. Limited detection value on its own.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-03T02:51:15.3050609Z",
"ActivityDisplayName": "Settings_GetSettingsAsync",
"AdditionalDetails": [],
"Category": "GroupManagement",
"CorrelationId": "679d3de0-35bb-46ad-9c3a-8d55b6e82556",
"DurationMs": "0",
"Id": "SSGM_679d3de0-35bb-46ad-9c3a-8d55b6e82556_WB811_119450004",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Self-service Group Management",
"OperationName": "Settings_GetSettingsAsync",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultDescription": "OK",
"ResultReason": "OK",
"ResultSignature": "None",
"TargetResources": [
{
"id": "00000000-0000-0000-0000-000000000000",
"displayName": null,
"type": "N/A",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Start applying group based license to users
#Description
Records that Microsoft Entra group-based licensing began applying a group-assigned license to the group's member users, propagating the license to each current member. Microsoft Entra processes all existing members when a license is assigned to a group.
References #
Trigger group license recalculation
#Description
Records a manual trigger to reprocess and recalculate group-based license assignments for a group's members, typically used to resolve out-of-sync or errored license states. Microsoft Entra otherwise recalculates group license assignments automatically on membership or license changes.
References #
Update eligible member in PIM canceled (extend)
#Description
A request to extend an eligible group membership in Privileged Identity Management for Groups was canceled.
References #
Update eligible member in PIM requested (extend)
#Description
A user requested to extend an expiring eligible group membership in Privileged Identity Management for Groups.
References #
Update group settings
#Description
Directory-level group settings were updated. Group settings are stored as a directory setting based on a template (for example, Group.Unified for Microsoft 365 groups) and control behaviors such as the group naming policy, guest access, classifications, and group-creation restrictions, so weakening guest or naming controls can affect external-access exposure.
References #
Update lifecycle management policy
#Description
Records a change to the Microsoft 365 group expiration (lifecycle) policy, which controls group lifetime, activity-based automatic renewal, and expiration of unused groups. The policy is administered alongside self-service group management.
References #
Update member in PIM approved by admin (extend/renew)
#Description
Records that an administrator approved a request to extend or renew a member's group assignment in Privileged Identity Management (PIM) for Groups. Approving extension or renewal of privileged group membership prolongs elevated access and is relevant to privileged-access monitoring.
References #
Update member in PIM canceled (extend)
#Description
Records that a request to extend a member's group assignment in Privileged Identity Management (PIM) for Groups was canceled before completion. It marks the abandoned lifecycle event for an eligible or active group membership extension request.
References #
Update member in PIM denied by admin (extend/renew)
#Description
An administrator denied a user's request to extend or renew an eligible or active group membership assignment in Privileged Identity Management (PIM) for Groups. Repeated or unexpected extend/renew denials can flag attempts to retain or regain privileged group access past its expiry.
References #
Update member in PIM requested (extend)
#Description
A user (or group) requested to extend an expiring eligible or active group membership assignment in Privileged Identity Management (PIM) for Groups. The request is recorded for audit and awaits approver action before any extension takes effect.
References #
User_Create
#Description
A User_Create operation emitted by the self-service group management service, listed among its GroupManagement background-process activities. Microsoft documents these self-service group management entries as background processes tied to a user's portal activity that do not necessarily indicate a user-initiated change.
References #
User_Delete
#Description
A User_Delete operation emitted by the self-service group management service, listed among its GroupManagement background-process activities. The documentation frames these self-service group management entries as background processes related to a user's activity that don't necessarily reflect a user-initiated change.
References #
User_Get
#Description
A read operation through which the self-service group management service retrieves a user (directory) object, typically as a background process when a user accesses the My Apps or My Groups portal. Microsoft notes these activities don't indicate that the user made any changes.
References #
User_GetAll
#Description
A read operation through which the self-service group management service enumerates user (directory) objects, typically a background process when a user accesses the My Apps or My Groups portal. Documented as activity that doesn't indicate the user made any changes.
References #
User_GetMemberOf
#Description
A read operation through which the self-service group management service retrieves the groups a user is a member of (the memberOf relationship), typically as a background process when the user views their groups in the My Apps or My Groups portal. Documented as activity that doesn't indicate the user made any changes.
References #
User_GetOwnedObjects
#Description
A read operation through which the self-service group management service retrieves the directory objects a user owns (the ownedObjects relationship), typically a background process when the user accesses the My Apps or My Groups portal. Documented as activity that doesn't indicate the user made any changes.
References #
ApprovalNotification_Delete
#Description
Deletion of a self-service group membership approval notification (the delete-pair of ApprovalNotification_Create), e.g. once the pending request is approved, denied, or withdrawn.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:23.8597623Z",
"ActivityDisplayName": "ApprovalNotification_Delete",
"AdditionalDetails": [
{
"key": "Group Join Request Id",
"value": "b15bef61-3866-45a0-8283-1c7d03075e77"
}
],
"Category": "GroupManagement",
"CorrelationId": "8d4c23a7-6971-4e27-a534-91f5e6ce9dcc",
"DurationMs": "0",
"Id": "SSGM_8d4c23a7-6971-4e27-a534-91f5e6ce9dcc_3IAUC_225103715",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Self-service Group Management",
"OperationName": "ApprovalNotification_Delete",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultDescription": "Created",
"ResultReason": "Created",
"ResultSignature": "None",
"TargetResources": [
{
"id": "00000000-0000-0000-0000-000000000000",
"displayName": null,
"type": "N/A",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.