Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: RoleManagement
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add eligible member (eligible) | A principal was assigned eligible for a role through PIM. | N | Y |
| Add eligible member (permanent) | A principal was assigned a permanent eligible role through PIM. | N | Y |
| Add eligible member to role | A principal was made eligible for a directory role via PIM. | N | Y |
| Add eligible member to role in PIM completed (permanent) | A permanent PIM role-eligibility assignment completed. | N | Y |
| Add member to role | A principal was added as a permanent member of a directory role (privileged role assignment). | Y | Y |
| Add member to role completed (PIM activation) | A PIM-eligible role activation completed, granting the role for the activation window. | N | Y |
| Add member to role in PIM completed (timebound) | A time-bound PIM role assignment completed. | N | Y |
| Add member to role in PIM requested (permanent) | A permanent PIM role assignment was requested. | N | Y |
| Add member to role outside of PIM (permanent) | A permanent directory-role assignment was made directly, bypassing PIM (no just-in-time activation). | N | Y |
| Add member to role request denied (PIM activation) | A PIM role activation request was denied. | N | Y |
| Add role definition | A custom directory role definition was created. | Y | N |
| Remove member from role | A principal was removed from a directory role. | Y | N |
| Update role definition | A custom directory role definition was modified. | Y | N |
| Update role setting in PIM | PIM role settings (activation duration, approval, MFA requirement) were changed. | N | Y |
| Add Eligible | An eligible role assignment was added to a Microsoft Entra role definition (a principal made eligible for a directory role). | N | N |
| Add member to role scoped over Restricted Management Administrative Unit | A directory role was assigned with scope over a restricted management administrative unit (RMAU). | N | N |
| Add role assignment to role definition | Creates an Entra role assignment binding a principal to a role definition, granting that role's permissions. | N | N |
| Add role from template | Activates a built-in directory role in the tenant from its role template, making the role assignable. | Y | N |
| Add scoped member to role | Adds a member to a directory role scoped to an administrative unit (scopedRoleMembership). | N | Y |
| Delete role definition | Deletion of a Microsoft Entra (RBAC) role definition: a collection of directory permissions. | Y | N |
| Refresh PIM alert | A Privileged Identity Management security alert was refreshed, re-evaluating it against current role state. | N | N |
| Remove eligible member from role | A principal's eligible assignment to a Microsoft Entra directory role (PIM) was removed. | N | N |
| Remove Eligible | An eligible role assignment was removed from a Microsoft Entra role definition (PIM eligibility). | N | N |
| Remove member from role scoped over Restricted Management Administrative Unit | Removal of a role assignment scoped to a restricted management administrative unit, changing who can manage its protected objects. | N | N |
| Remove role assignment from role definition | A role assignment was removed from a Microsoft Entra role definition, revoking the principal's directory role. | N | N |
| Remove scoped member from role | A scoped (administrative-unit) role member was removed from a Microsoft Entra role, revoking the principal's scoped role. | N | N |
| Update PIM alert setting | A PIM security-alert setting for Microsoft Entra roles was updated. | N | N |
| Update role | A directory role object was updated (role definition or properties changed). | Y | N |
Add eligible member (eligible)
#Description
A principal was assigned eligible for a role through PIM.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
RoleName (kusto rule field) | contains | admin | 1 rule | kusto |
displayName (kusto rule field) | eq | role.displayname | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004↳ also matches Add eligible member (permanent) Kusto #
T1078, T1078.004↳ also matches Add eligible member (permanent), Add member to role
References #
Add eligible member (permanent)
#Description
A principal was assigned a permanent eligible role through PIM.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
RoleName (kusto rule field) | contains | admin | 1 rule | kusto |
displayName (kusto rule field) | eq | role.displayname | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004↳ also matches Add eligible member (eligible) Kusto #
T1078, T1078.004↳ also matches Add eligible member (eligible), Add member to role
References #
Add eligible member to role
#Description
A principal was made eligible for a directory role via PIM.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
GroupName (kusto rule field) | in | privilegedauthenticationadmins | 2 rules | kusto |
GroupName (kusto rule field) | in | privilegedroleadmins | 2 rules | kusto |
GroupName (kusto rule field) | in | tenantadmins | 2 rules | kusto |
GroupName (kusto rule field) | in | useraccountadmins | 2 rules | kusto |
displayName (kusto rule field) | eq | role.wellknownobjectname | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1098.003↳ also matches Add member to role, Add scoped member to role Kusto #
T1078, T1098↳ also matches Add member to role T1078, T1098↳ also matches Add member to role
References #
Add eligible member to role in PIM completed (permanent)
#Description
A permanent PIM role-eligibility assignment completed.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.auditlogs.properties.category (elastic rule field) | eq | rolemanagement | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003↳ also matches Add member to role in PIM completed (timebound)
References #
Add member to role
#Description
A principal was added as a permanent member of a directory role (privileged role assignment).
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:25.4700984Z",
"ActivityDisplayName": "Add member to role",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "d4fbecff-ca91-4e4f-bee6-d3544d0f7ec5",
"DurationMs": "0",
"Id": "Directory_d4fbecff-ca91-4e4f-bee6-d3544d0f7ec5_ATINI_154963444",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add member to role",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Role.ObjectID",
"oldValue": null,
"newValue": "\"ba4b3989-6c3a-4095-bec6-a973070cfa28\""
},
{
"displayName": "Role.DisplayName",
"oldValue": null,
"newValue": "\"Directory Readers\""
},
{
"displayName": "Role.TemplateId",
"oldValue": null,
"newValue": "\"88d8e3e3-8f55-4a1e-953a-9b9898b8876b\""
},
{
"displayName": "Role.WellKnownObjectName",
"oldValue": null,
"newValue": "\"DirectoryReaders\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "ba4b3989-6c3a-4095-bec6-a973070cfa28",
"displayName": null,
"type": "Role",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 5 rules | kusto |
GroupName (kusto rule field) | in | privilegedroleadmins | 3 rules | kusto |
GroupName (kusto rule field) | in | tenantadmins | 3 rules | kusto |
GroupName (kusto rule field) | in | useraccountadmins | 3 rules | kusto |
GroupName (kusto rule field) | in | privilegedauthenticationadmins | 2 rules | kusto |
displayName (kusto rule field) | eq | role.wellknownobjectname | 3 rules | kusto |
displayName (kusto rule field) | eq | role.displayname | 1 rule | kusto |
Identity (kusto rule field) | ne | MS-PIM | 2 rules | kusto |
Identity (kusto rule field) | ne | MS-PIM-Fairfax | 2 rules | kusto |
azure_ad::logged_by_service (kusto rule field) | eq | core directory | 2 rules | kusto |
isprvilegedadrole (splunk rule field) | eq | true | 2 rules | splunk |
RoleName (kusto rule field) | contains | admin | 1 rule | kusto |
azure.auditlogs.properties.category (elastic rule field) | eq | rolemanagement | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1098, T1098.003T1098, T1098.003↳ also matches Add eligible member to role, Add scoped member to role Elastic #
T1098, T1098.003Splunk #
T1098, T1098.003T1098, T1098.003T1003, T1003.002Kusto #
T1078, T1078.004T1078, T1078.004T1078, T1098↳ also matches Add member to role in PIM requested (permanent) YARA-L #
T1098, T1098.003T1098, T1098.003↳ also matches Add user
References #
Add member to role completed (PIM activation)
#Description
A PIM-eligible role activation completed, granting the role for the activation window.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098, T1098.003Kusto #
T1078, T1078.004
References #
Add member to role in PIM completed (timebound)
#Description
A time-bound PIM role assignment completed.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.auditlogs.properties.category (elastic rule field) | eq | rolemanagement | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003↳ also matches Add eligible member to role in PIM completed (permanent)
References #
Add member to role in PIM requested (permanent)
#Description
A permanent PIM role assignment was requested.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
GroupName (kusto rule field) | in | privilegedroleadmins | 1 rule | kusto |
GroupName (kusto rule field) | in | tenantadmins | 1 rule | kusto |
GroupName (kusto rule field) | in | useraccountadmins | 1 rule | kusto |
displayName (kusto rule field) | eq | role.wellknownobjectname | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1098↳ also matches Add member to role
References #
Add member to role outside of PIM (permanent)
#Description
A permanent directory-role assignment was made directly, bypassing PIM (no just-in-time activation).
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1098, T1098.003
References #
Add member to role request denied (PIM activation)
#Description
A PIM role activation request was denied.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | role | 3 rules | kusto |
user (kusto rule field) | is_not_null | | 3 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004T1078, T1078.004T1078, T1078.004
References #
Add role definition
#Description
A custom directory role definition was created.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:51.283922Z",
"ActivityDisplayName": "Add role definition",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "a377d513-0a87-4e77-bb23-7def95c95ad9",
"DurationMs": "0",
"Id": "Directory_a377d513-0a87-4e77-bb23-7def95c95ad9_V8SQ4_147870800",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add role definition",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "ff657eed-4940-4bcf-96ac-79e9076c4914",
"displayName": "dw-harness-role-cf516524",
"type": "Other",
"modifiedProperties": [
{
"displayName": "DisplayName",
"oldValue": [],
"newValue": [
"dw-harness-role-cf516524"
]
},
{
"displayName": "GrantedPermissions",
"oldValue": [],
"newValue": [
{
"Actions": [
{
"ResourceCategory": "AadDirectory",
"ResourceType": "Group",
"TaskType": "Read",
"ReadPropertySet": "Basic",
"WritePropertySet": "None",
"TaskTypeSubsetName": null
}
],
"Condition": null,
"ScopeConstraints": [],
"IsPrivileged": false
}
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"DisplayName, GrantedPermissions\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Remove member from role
#Description
A principal was removed from a directory role.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:26.5914353Z",
"ActivityDisplayName": "Remove member from role",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "af76e9f3-236c-4363-b45a-6adfeea779be",
"DurationMs": "0",
"Id": "Directory_af76e9f3-236c-4363-b45a-6adfeea779be_A7FWW_151245055",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove member from role",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Role.ObjectID",
"oldValue": "\"ba4b3989-6c3a-4095-bec6-a973070cfa28\"",
"newValue": null
},
{
"displayName": "Role.DisplayName",
"oldValue": "\"Directory Readers\"",
"newValue": null
},
{
"displayName": "Role.TemplateId",
"oldValue": "\"88d8e3e3-8f55-4a1e-953a-9b9898b8876b\"",
"newValue": null
},
{
"displayName": "Role.WellKnownObjectName",
"oldValue": "\"DirectoryReaders\"",
"newValue": null
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "ba4b3989-6c3a-4095-bec6-a973070cfa28",
"displayName": null,
"type": "Role",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Update role definition
#Description
A custom directory role definition was modified.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:52.1117475Z",
"ActivityDisplayName": "Update role definition",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "1b09278d-6791-4e2f-b1c0-d3a6e7965676",
"DurationMs": "0",
"Id": "Directory_1b09278d-6791-4e2f-b1c0-d3a6e7965676_KR8EX_154762087",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update role definition",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "ff657eed-4940-4bcf-96ac-79e9076c4914",
"displayName": "dw-harness-role-cf516524",
"type": "Other",
"modifiedProperties": [
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Update role setting in PIM
#Description
PIM role settings (activation duration, approval, MFA requirement) were changed.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004Elastic #
T1078, T1098, T1098.003
References #
Add EligibleRoleAssignment to RoleDefinition
#Description
An eligible role assignment was added to a Microsoft Entra role definition, making a principal eligible for that directory role. Eligible assignments require activation (typically through Privileged Identity Management) before the role's privileges apply, and granting eligibility to a privileged role is a privilege-escalation and persistence vector.
References #
Add member to role scoped over Restricted Management Administrative Unit
#Description
Records a directory role assignment granted with scope over a restricted management administrative unit (RMAU), giving the assigned principal management rights over the objects in that unit. Because RMAUs shield their members from tenant-level administrators, a scoped role grant over an RMAU widens who can manage otherwise-protected accounts and warrants review.
References #
Add role assignment to role definition
#Description
Records creation of a Microsoft Entra role assignment that binds a principal (user, group, or service principal) to a role definition, granting that role's permissions. New assignments to privileged roles are a primary privilege-escalation and persistence signal.
References #
Add role from template
#Description
Records activation of a built-in directory (administrator) role in the tenant from its directoryRoleTemplate, which makes the role available so that members can be assigned to it. Only Company Administrator is active by default, so activating other privileged role templates can precede privilege escalation.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-06-29T17:56:22.1017155Z",
"ActivityDisplayName": "Add role from template",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "bb4cb77c-88d0-40a9-9155-55b9ed0df680",
"DurationMs": "0",
"Id": "Directory_bb4cb77c-88d0-40a9-9155-55b9ed0df680_PUEU2_136849831",
"Identity": "",
"InitiatedBy": {
"user": {
"displayName": null,
"agentType": "notAgentic",
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": []
}
},
"Level": "",
"Location": "",
"LoggedByService": "Core Directory",
"OperationName": "Add role from template",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"ResourceProvider": "",
"Result": "success",
"ResultDescription": "",
"ResultReason": "",
"ResultSignature": "None",
"ResultType": "",
"SourceSystem": "Azure AD",
"TargetResources": [
{
"id": "d0d8ab1f-38e0-4911-96ba-2a01f139862b",
"displayName": "User",
"type": "Role",
"modifiedProperties": [
{
"displayName": "TargetId.RoleTemplateId",
"oldValue": null,
"newValue": "\"a0b1b346-4d3e-4e8b-98f8-753987be4970\""
},
{
"displayName": "TargetId.RoleWellKnownObjectName",
"oldValue": null,
"newValue": "\"Users\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
],
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:56:22.1017155Z",
"Type": "AuditLogs"
}
References #
Add scoped member to role
#Description
Records the addition of a principal as a member of a directory role scoped to an administrative unit (a scopedRoleMembership), granting that role's permissions only over the members of that administrative unit. Scoped administrator grants are privilege-escalation relevant within the unit.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1098.003↳ also matches Add eligible member to role, Add member to role
References #
Delete role definition
#Description
Records the deletion of a Microsoft Entra role definition, a named collection of directory permissions; custom role definitions can be deleted. Changes to RBAC role definitions are security-relevant to privilege management.
Example Audit Log Entry #
{
"AADOperationType": "Delete",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:53.0227512Z",
"ActivityDisplayName": "Delete role definition",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "70b23317-c794-4d65-84a2-54d22425695b",
"DurationMs": "0",
"Id": "Directory_70b23317-c794-4d65-84a2-54d22425695b_708EK_122407154",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Delete role definition",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "ff657eed-4940-4bcf-96ac-79e9076c4914",
"displayName": "dw-harness-role-cf516524",
"type": "Other",
"modifiedProperties": [
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Refresh PIM alert
#Description
A Privileged Identity Management security alert was refreshed, prompting PIM to re-evaluate the alert and update its results against the current state of Microsoft Entra role assignments and activity. It is a routine PIM alert-management operation, not a role or privilege change.
References #
Remove eligible member from role
#Description
Records removal of a principal's eligible assignment to a Microsoft Entra directory role, the PIM eligibility that lets the principal activate the role when needed instead of holding it permanently. Changes to eligible role assignments are privilege-relevant.
References #
Remove EligibleRoleAssignment from RoleDefinition
#Description
Records removal of an eligible role assignment associated with a Microsoft Entra role definition, the directory-side record of deleting a PIM eligibility for that role. Eligible role assignments let a principal activate the role rather than hold it standing.
References #
Remove member from role scoped over Restricted Management Administrative Unit
#Description
Records removal of a Microsoft Entra role assignment that was scoped to a restricted management administrative unit (RoleManagement category). Because only administrators explicitly assigned at that scope can manage the unit's protected objects, removing such an assignment changes who is able to administer those sensitive objects.
References #
Remove role assignment from role definition
#Description
A role assignment linking a principal to a Microsoft Entra role definition was removed, revoking that principal's directory role at the assigned scope. Removal of privileged role assignments is relevant to monitoring directory privilege changes and to spotting an actor de-provisioning roles to cover tracks after misuse.
References #
Remove scoped member from role
#Description
A scoped role member was removed from a Microsoft Entra role whose assignment was scoped to an administrative unit, revoking that principal's administrative-unit-scoped role. Changes to scoped role membership are relevant to tracking delegated administrative privilege confined to specific administrative units.
References #
Update PIM alert setting
#Description
A Privileged Identity Management security-alert setting for Microsoft Entra roles was updated. Disabling or weakening a PIM alert reduces monitoring of suspicious privileged-role activity (defense evasion).
References #
Update role
#Description
A directory role object was updated, such as a change to a role definition's properties or permissions in the Core Directory. Modifications to privileged roles are relevant to detecting privilege escalation and unauthorized administrative tampering.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:42.7822092Z",
"ActivityDisplayName": "Update role",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "RoleManagement",
"CorrelationId": "eb2285f2-995b-4971-b6f8-b6aed5198e07",
"DurationMs": "0",
"Id": "Directory_eb2285f2-995b-4971-b6f8-b6aed5198e07_H2DJ9_135895596",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update role",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "d0d8ab1f-38e0-4911-96ba-2a01f139862b",
"displayName": "User",
"type": "Role",
"modifiedProperties": [
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"\""
},
{
"displayName": "TargetId.RoleTemplateId",
"oldValue": null,
"newValue": "\"a0b1b346-4d3e-4e8b-98f8-753987be4970\""
},
{
"displayName": "TargetId.RoleWellKnownObjectName",
"oldValue": null,
"newValue": "\"Users\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.