Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: PolicyManagement

OperationNameDescriptionSampleRule
Create Filtering PolicyCreation of a Global Secure Access (Internet Access) web-content filtering policy of allow/block rules by FQDN or category.NN
Create Filtering Policy ProfileCreation of a Global Secure Access security profile grouping filtering policies for delivery via Conditional Access.NN
Create Remote NetworkCreation of a Global Secure Access remote network (branch location connected via IPSec tunnel for cloud traffic policy).NN
Create Security Provider PolicyCreation of a Global Secure Access security policy applying network controls (web filtering, threat intel, TLS inspection, cloud firewall).NN
Delete Filtering PolicyDeletion of a Global Secure Access web content filtering policy (FQDN or category allow/block rules).NN
Delete Filtering Policy ProfileDeletion of a Global Secure Access security profile that groups filtering policies and applies them via Conditional Access.NN
Delete Forwarding PolicyDeletion of a Global Secure Access traffic forwarding policy controlling which traffic the client tunnels through the service.NN
Delete Private Access PolicyDeletion of a Global Secure Access Private Access traffic-forwarding policy (ZTNA to internal apps).NN
Delete Remote NetworkDeletion of a Global Secure Access remote network (branch/site IPsec tunnel for traffic forwarding).NN
Delete Security Provider PolicyDeletion of a Global Secure Access security profile/policy (web filtering, threat intel, TLS, firewall controls).NN
Get authenticationEventListenersThe collection of authenticationEventListener objects (custom-extension triggers) was listed.NN
POST UserAuthMethod.SecurityInfoRegistrationCallbackRecords completion of a user's security-info (authentication method) registration via combined MFA/SSPR registration.NN
Update Filtering PolicyA Global Secure Access filtering policy (web-category / FQDN allow-block rules) was updated.NN
Update Filtering Policy ProfileThe association linking a filtering policy to a Global Secure Access security profile was updated.NN
Update Filtering ProfileA Global Secure Access security (filtering) profile that groups filtering policies was updated.NN
Update Forwarding PolicyA Global Secure Access forwarding policy (rules determining which traffic is tunneled) was updated.NN
Update Forwarding ProfileA Global Secure Access traffic forwarding profile (Microsoft 365 / Private / Internet) was updated.NN
Update Forwarding RuleA Global Secure Access forwarding rule (forward/bypass by destination FQDN, IP, or URL) was updated.NN
Update Private Access PolicyA Microsoft Entra Private Access (Global Secure Access) policy was updated.NN
Update Remote NetworkA Global Secure Access remote network configuration was updated.NN
Update Security Provider PolicyA Global Secure Access security policy/profile was updated.NN

Create Filtering Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access filtering policy was created, a set of web-content filtering rules that allow or block by fully qualified domain name or web category and is used by Microsoft Entra Internet Access. Filtering policies are grouped into security profiles and enforced on forwarded internet traffic.

References #

Create Filtering Policy Profile

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access security profile (filtering policy profile) was created, a container that groups one or more filtering policies and is delivered to users through Conditional Access policies. The profile sets evaluation priority and binds its filtering policies to enforcement.

References #

Create Remote Network

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

Records the creation of a Global Secure Access remote network, a remote location (such as a branch office) connected to Global Secure Access over an IPSec tunnel so that its traffic is routed to the cloud for security-policy evaluation.

References #

Create Security Provider Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

Records the creation of a Global Secure Access security policy used to govern traffic routed through Global Secure Access. Such policies apply network security controls (for example web content filtering, threat intelligence, TLS inspection, or cloud firewall rules) to traffic, so their creation is relevant to monitoring changes in network-security posture and potential bypasses.

References #

Delete Filtering Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access web content filtering policy was deleted. These policies allow or block internet traffic by fully qualified domain name, URL, or web category in Microsoft Entra Internet Access, so removing one can drop enforced web restrictions and is relevant to secure web gateway tampering.

References #

Delete Filtering Policy Profile

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access security profile was deleted. Security profiles group web content filtering policies and are delivered to users through Conditional Access session controls, so deleting one removes the grouping that applies the filtering policies.

References #

Delete Forwarding Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access traffic forwarding policy was deleted. Traffic forwarding profiles and their policies define which network traffic the Global Secure Access client captures and tunnels through the service, so removing one can stop traffic from being routed for inspection or control.

References #

Delete Private Access Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

Records the deletion of a Microsoft Entra Private Access policy within the Global Secure Access Private Access traffic-forwarding profile, which routes traffic to private and internal applications and resources (VPN-less, Zero Trust network access) through the service. Removing it changes which internal resources are reachable through Global Secure Access.

References #

Delete Remote Network

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

Records the deletion of a Global Secure Access remote network, a branch or site location connected to the service over an IPsec tunnel so its traffic can be forwarded without a client. Deletion removes that connectivity and its associated traffic-forwarding configuration.

References #

Delete Security Provider Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

Records the deletion of a Global Secure Access security policy or profile that groups filtering controls such as web content filtering, threat intelligence, TLS inspection, or cloud firewall rules applied to traffic routed through the service. Removal reduces inspection and filtering coverage and can serve defense evasion.

References #

Get authenticationEventListeners

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

The collection of authenticationEventListener objects was listed, returning the listeners that bind custom authentication extensions to authentication events. This is a read-only operation.

References #

POST UserAuthMethod.SecurityInfoRegistrationCallback

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

Records the callback completing a user's security-information registration, where the user registers authentication methods through the combined Microsoft Entra multifactor authentication and self-service password reset (SSPR) registration experience. Registration of new authentication methods is a recognized MFA-persistence vector and is worth monitoring.

References #

Update Filtering Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access (Microsoft Entra Internet Access) filtering policy was updated. A filtering policy holds the policy rules (such as web-category and FQDN rules) that allow or block destinations for tunneled internet traffic, so loosening these rules can be a defense-evasion or data-exfiltration enabler.

References #

Update Filtering Policy Profile

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

The link that associates a Global Secure Access filtering policy with a security (filtering) profile was updated. This association controls the policy's priority, state, and logging within the profile that Conditional Access delivers to users, so the change affects which filtering rules take effect and in what order.

References #

Update Filtering Profile

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access security (filtering) profile was updated. A filtering profile is the container that groups one or more filtering policies and is delivered to users through Conditional Access, with properties such as priority and enabled/disabled state, so changes can enable, disable, or reprioritize internet-access security enforcement.

References #

Update Forwarding Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access traffic forwarding policy was updated. A forwarding policy is a set of forwarding rules; forwarding policies are added to a forwarding profile to determine which network traffic is tunneled to the Global Secure Access service, so the change alters which traffic is captured for inspection and enforcement.

References #

Update Forwarding Profile

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access traffic forwarding profile was updated. A forwarding profile (Microsoft 365, Private, or Internet) determines which traffic types are routed through Global Secure Access versus skipped, and carries state, priority, and the associations of users, groups, devices, and remote networks it applies to, so the change can expand, reduce, or disable tunneled-traffic coverage.

References #

Update Forwarding Rule

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access forwarding rule was updated. A forwarding rule selectively forwards (or bypasses) traffic to the Global Secure Access service based on its destination (FQDN, IP, or URL); it is an abstract rule type whose Microsoft 365 and Private Access forwarding-rule variants determine exactly which destinations are tunneled, so the record reflects a change to which traffic is captured.

References #

Update Private Access Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Microsoft Entra Private Access policy in Global Secure Access was updated. Private Access policies govern how private or internal applications and resources are tunneled and accessed.

References #

Update Remote Network

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access remote network configuration was updated. Remote networks connect a site, such as a branch, to Global Secure Access over an IPsec tunnel for traffic forwarding.

References #

Update Security Provider Policy

#
Source
Microsoft Entra ID audit log
Audit Category
PolicyManagement

Description

A Global Secure Access security policy was updated. Global Secure Access security profiles group filtering controls such as web content filtering and threat intelligence policies that are applied to traffic, so a change can alter what network traffic is inspected, allowed, or blocked.

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.