Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: IdentityProtection

OperationNameDescriptionSampleRule
Update IdentityProtectionPolicyConfiguration change to an Entra ID Protection risk policy (sign-in or user risk).NN
Update NotificationSettingsNotification settings for the hybrid authentication subsystem were updated.NN

Update IdentityProtectionPolicy

#
Source
Microsoft Entra ID audit log
Audit Category
IdentityProtection

Description

Records a configuration change to a Microsoft Entra ID Protection risk policy (sign-in risk or user risk) that governs automated responses such as requiring MFA or blocking access. Weakening or disabling these policies reduces protection against risky sign-ins and can aid defense evasion.

References #

Update NotificationSettings

#
Source
Microsoft Entra ID audit log
Audit Category
IdentityProtection

Description

Notification settings within the hybrid authentication subsystem were updated, for example the email-alert configuration that notifies administrators when the on-premises hybrid identity infrastructure is unhealthy. The exact feature behind this audit operation was not confirmed against a single Learn doc.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.