Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: UserManagement

OperationNameDescriptionSampleRule
Add userA new user account was created in the directory.YY
Admin deleted security infoAn admin removed a user's security info.NY
Admin registered security infoAn admin registered security info on behalf of a user (e.g. Temporary Access Pass).YY
Admin updated security infoAn admin modified a user's security info.NY
Bulk invite users - started (bulk)A bulk guest-invite operation was started.NY
Change user passwordA user changed their own password.NN
Delete userA user account was deleted.YY
Disable accountA user account was disabled.NN
Disable Strong AuthenticationStrong authentication (MFA) was disabled for a user.NY
Enable accountA user account was enabled.NY
Invite external userA guest (B2B) user was invited to the tenant.YY
Invite external user with reset invitation statusA guest user invitation was re-sent/reset.NY
Redeem external user inviteA guest user redeemed their B2B invitation.NY
Reset user passwordAn administrator reset a user's password.YN
Restore userA soft-deleted user account was restored.NN
Risky userA user was flagged as risky by Identity Protection.NN
Set force change user passwordA user was flagged to change password at next sign-in.NN
Suspicious activity reportedSuspicious activity was reported for a user (e.g. MFA fraud report).NY
Update StsRefreshTokenValidFrom TimestampA user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks.YN
Update userA user account attribute was modified.YY
User changed default security infoA user changed their default authentication method.NY
User deleted security infoA user removed one of their authentication methods.NY
User registered security infoA user registered an authentication method (MFA/SSPR security info).NY
User reviewed security infoA user reviewed their registered security info.NY
User Risk DetectionIdentity Protection raised a user-risk detection.NN
Add Passkey (device-bound)A device-bound passkey (FIDO2) credential was registered for a user.YN
Add passwordless phone sign-in credentialA passwordless phone sign-in (Authenticator) credential was registered for a user.NN
Add platform credentialA platform credential (Secure Enclave hardware-bound SSO key) was registered for a user.NN
Add user sponsorAdds a sponsor (a user or group responsible for the account) to a user.YN
Add Windows Hello for Business credentialRegisters a Windows Hello for Business (key-based passwordless) credential for a user.NN
Admin started password resetAn administrator initiated a password reset on behalf of a user via Entra authentication methods.NN
Apply reviewThe results of a completed access review were applied, removing access for denied users.NN
Approve all requests in business flowBulk approval of all pending decisions in an access review (business flow), continuing access for the reviewed users.NN
Auto apply reviewAn access review's results were automatically applied to the resource, removing denied users' access.NN
Auto reviewA system-generated (automatic) access review decision was recorded for a user.NN
Blocked from self-service password resetA user was throttled and blocked from self-service password reset after too many reset attempts (5/hour, then a 24-hour wait).NN
Bulk create users - finished (bulk)Completion of an administrator bulk create-users operation from a CSV upload.NN
Bulk delete users - finished (bulk)A bulk job that deletes multiple user accounts from an uploaded CSV completed in the Entra admin center.NN
Bulk invite users - finished (bulk)A bulk job that sends B2B guest invitations from an uploaded CSV completed.NN
Bulk restore deleted users - finished (bulk)A bulk job that restores soft-deleted user accounts from an uploaded CSV completed.NN
Change password (self-service)A user changed their own password via self-service password management.NN
Change user licenseThe product licenses assigned to a user were changed.YN
Convert federated user to managedA user account was converted from federated to managed (cloud) authentication.NN
Create application password for userAn app password was created for a user, letting a legacy client sign in without completing MFA.NN
Create business flowA business flow was created in Entra access reviews (internal access-review configuration; exact object undocumented).NN
Create governance policy templateCreation of a tenant-governance policy template: a reusable blueprint mapping built-in roles to a group for cross-tenant governance.NN
Delete application password for userAn app-password credential was deleted for a user, revoking a legacy non-MFA sign-in credential.NN
Delete business flowA business flow object within Microsoft Entra access reviews was deleted.NN
Delete external userDeletion of an external B2B guest user from the directory, revoking that guest's tenant access.NN
Delete governance policy templateDeletion of an access reviews governance policy template.NN
Delete Passkey (device-bound)Deletes a user's device-bound passkey (FIDO2) authentication method, removing a phishing-resistant credential.NN
Delete passwordless phone sign-in credentialDeletes a user's passwordless phone sign-in credential in Azure AD B2C.NN
Delete platform credentialRemoval of a macOS Platform Credential (secure-enclave hardware-bound SSO key) from a registered Mac.NN
Delete Windows Hello for Business credentialRemoves a Windows Hello for Business credential from a user account.NN
Deny all decisionsAll pending decisions in an access review were denied at once.NN
Deny all requests in business flowAll requests within an access-review business flow were denied.NN
Email not sent, user unsubscribedAn invited-user email was suppressed because the recipient had previously unsubscribed.NN
Enable Strong AuthenticationRecords strong authentication (multifactor authentication) being enabled for a directory user.NN
Fraud reported - no action takenUser reported an MFA prompt as fraud (legacy Fraud Alert); account was not blocked.NN
Fraud reported - user is blocked for MFAUser reported an MFA prompt as fraud (legacy Fraud Alert); account was blocked for MFA.NN
Get passkey creation optionsRetrieval of WebAuthn passkey (FIDO2) creation options at the start of passkey registration in Entra ID.NN
Hard Delete userPermanent, non-recoverable removal of a user object from the tenant.NN
Invitation EmailA B2B collaboration invitation email was sent to an invited external user.NN
Invite internal user to B2B collaborationAn existing internal user was invited into B2B collaboration to sign in with an external email identity.NN
Redeem extern user inviteAn external (B2B collaboration) guest user redeemed an invitation to the tenant.NN
Remove app role assignment from userAn app role assignment was removed from a user, revoking the user's assignment to an application.YN
Remove OrganizationalUnit assigned to a userRemoval of the organizational-unit association assigned to a user object in the directory (distinct from administrative units).NN
Remove user sponsorA sponsor was removed from a user's Sponsors attribute (the users/groups that vouch for that user).NN
Request approvedAn access request reviewed in an access review was approved (access granted or retained).NN
Request deniedA reviewer denied a user's continued access in an access review; applying results removes their membership or assignment.NN
Reset passwordA password was reset on a user account in the directory.NN
Reset password (by admin)An administrator reset another user's password on their behalf.NY
Reset password (self-service)A user reset their own password through Microsoft Entra self-service password reset (SSPR).NN
Restore multifactor authentication on all remembered devicesAn admin restored MFA on a user's remembered devices, forcing re-verification at next sign-in.NN
Security info saved for self-service password resetA user saved or updated the security info (phone, alternate email, or questions) used for self-service password reset.NN
Self-service password reset flow activity progressRecords each step a user passes through (such as a password reset authentication gate) during the SSPR flow.NN
Set user managerThe manager attribute of a user was set or updated.YN
Takeover user clonedA user was cloned into the managed tenant during admin takeover of an unmanaged directory.NN
Unlock user account (self-service)A user unlocked their own account via self-service password reset (SSPR).NN
Update business flowUpdate to a business flow object used by Microsoft Entra access reviews.NN
Update governance policy templateA Tenant Governance policy template (cross-tenant delegated admin roles and multitenant apps) was updated.NN
Update MyStaff feature valueA My Staff configuration value governing delegated user management was changed.NN
Update OrganizationalUnit assigned to a userThe organizational unit assigned to a user account was changed.NN
Update per-user multifactor authentication stateA user's legacy per-user MFA state (Disabled/Enabled/Enforced) was changed.NN
Updated ConvergedUXV2 feature valueA tenant-level directory feature flag 'ConvergedUXV2' value (internal Entra feature toggle) was changed.NN
Updated MyApps feature valueA tenant-level directory feature flag 'MyApps' value (My Apps portal feature toggle) was changed.NN
Updated SignInReports feature valueA tenant-level directory feature flag 'SignInReports' value (sign-in reporting feature toggle) was changed.NN
Updated SSPRConvergence feature valueA tenant-level directory feature flag 'SSPRConvergence' value (SSPR/MFA combined-registration toggle) was changed.NN
User canceled security info registrationUser exited combined MFA/SSPR security info registration without completing it.NN
User Password RegistrationUser registered authentication methods for self-service password reset via MIM.NN
User Password ResetUser reset their own password via MIM self-service password reset.NN
User registered all required security infoUser completed registering all MFA/SSPR security info required by tenant policy.NY
User started password changeUser initiated a self-service password change, supplying the current password to set a new one (voluntary or forced).NN
user started password resetUser initiated a self-service password reset for a forgotten password via the Entra password reset portal.NN
User started security info registrationUser began registering security info (MFA/SSPR authentication methods) via combined security info registration.NY
User updated security infoUser modified their registered security info (the MFA/SSPR authentication methods on their account).NN
Update PasswordProfileYN
Create Temporary Access Pass method for userNY

Add user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A new user account was created in the directory.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:20.000974Z",
  "ActivityDisplayName": "Add user",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "4abcd032-2a4f-4c54-9f6f-ff886773f36b",
  "DurationMs": "0",
  "Id": "Directory_4abcd032-2a4f-4c54-9f6f-ff886773f36b_O4VOL_159399491",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add user",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "AccountEnabled",
          "oldValue": [],
          "newValue": [
            true
          ]
        },
        {
          "displayName": "DisplayName",
          "oldValue": [],
          "newValue": [
            "dw harness manager user"
          ]
        },
        {
          "displayName": "MailNickname",
          "oldValue": [],
          "newValue": [
            "dwhmgrcf516524"
          ]
        },
        {
          "displayName": "StsRefreshTokensValidFrom",
          "oldValue": [],
          "newValue": [
            "2026-07-24T03:20:19Z"
          ]
        },
        {
          "displayName": "UserPrincipalName",
          "oldValue": [],
          "newValue": [
            "dwharn-manager-cf516524@example.onmicrosoft.com"
          ]
        },
        {
          "displayName": "UserType",
          "oldValue": [],
          "newValue": [
            "Member"
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"AccountEnabled, DisplayName, MailNickname, StsRefreshTokensValidFrom, UserPrincipalName, UserType\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Result (kusto rule field)eqsuccess3 ruleskusto
Status (sigma rule field)eqsuccess1 rulesigma
type (kusto rule field)eqUser1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

YARA-L #

References #

Admin deleted security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An admin removed a user's security info.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser3 ruleskusto
Target (kusto rule field)eqvipusers2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Admin registered security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An admin registered security info on behalf of a user (e.g. Temporary Access Pass).

Example Audit Log Entry #

{
  "AADOperationType": "ServiceApi",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-06-29T17:35:05.3981186Z",
  "ActivityDisplayName": "Admin registered security info",
  "AdditionalDetails": [
    {
      "key": "InitiatedFrom",
      "value": "Microsoft Azure CLI (04b07795-8ddb-461a-bbee-02f9e1bf7b46)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "c06851d2-f93d-494f-99bb-5729c784f0bc",
  "DurationMs": "0",
  "Id": "Authentication Methods_c06851d2-f93d-494f-99bb-5729c784f0bc_E84SE_119687324",
  "Identity": "Admin User",
  "InitiatedBy": {
    "app": {
      "appId": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
      "displayName": "Microsoft Azure CLI",
      "servicePrincipalId": null,
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    },
    "user": {
      "displayName": "Admin User",
      "agentType": "notAgentic",
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "userType": "Member"
    }
  },
  "Level": "",
  "Location": "",
  "LoggedByService": "Authentication Methods",
  "OperationName": "Admin registered security info",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "ResourceProvider": "",
  "Result": "clientError",
  "ResultDescription": "Admin failed to register phone method for user",
  "ResultReason": "Admin failed to register phone method for user",
  "ResultSignature": "None",
  "ResultType": "",
  "SourceSystem": "Azure AD",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000014",
      "displayName": "zzcap user 002",
      "type": "User",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic",
      "userPrincipalName": "zzcap-user-002@example.onmicrosoft.com"
    }
  ],
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:35:05.3981186Z",
  "Type": "AuditLogs"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser3 ruleskusto
Target (kusto rule field)eqvipusers2 ruleskusto
azure_ad::target_user_upn (kusto rule field)eqadmin_users1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

References #

Admin updated security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An admin modified a user's security info.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser3 ruleskusto
Target (kusto rule field)eqvipusers2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Bulk invite users - started (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A bulk guest-invite operation was started.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Change user password

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user changed their own password.

References #

Delete user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user account was deleted.

Example Audit Log Entry #

{
  "AADOperationType": "Delete",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:23.205928Z",
  "ActivityDisplayName": "Delete user",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "fd89b99b-8898-496c-baeb-234058b0ee12",
  "DurationMs": "0",
  "Id": "Directory_fd89b99b-8898-496c-baeb-234058b0ee12_M2FKB_152361561",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Delete user",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "c1149e7adad247579f06580700c96bd3dwharn-manager-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "Is Hard Deleted",
          "oldValue": null,
          "newValue": "\"False\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)eqUser2 ruleskusto
Status (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Disable account

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user account was disabled.

References #

Disable Strong Authentication

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Strong authentication (MFA) was disabled for a user.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.auditlogs.properties.additional_details.key (elastic rule field)eqauthenticationmethod1 ruleelastic
category (splunk rule field)eqauditlogs1 rulesplunk
properties.result (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

Kusto #

References #

Enable account

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user account was enabled.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Invite external user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A guest (B2B) user was invited to the tenant.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-06-29T18:29:23.1665391Z",
  "ActivityDisplayName": "Invite external user",
  "AdditionalDetails": [
    {
      "key": "oid",
      "value": "aaaaaaaa-0000-0000-0000-000000000001"
    },
    {
      "key": "tid",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "ipaddr",
      "value": "203.0.113.10"
    },
    {
      "key": "wids",
      "value": "62e90394-69f5-4237-9190-012177145e10"
    },
    {
      "key": "InvitationId",
      "value": "d620c1cb-65b9-49ad-aefd-274ad23167a0"
    },
    {
      "key": "invitedUserEmailAddress",
      "value": "guest002@example.com"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "3e26f73e-0052-4894-aa30-324724991533",
  "DurationMs": "0",
  "Id": "Invited Users_3e26f73e-0052-4894-aa30-324724991533_JCNB8_1326807",
  "Identity": "Microsoft Azure CLI",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "userType": "Member",
      "agentType": "notAgentic"
    },
    "app": {
      "appId": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
      "displayName": "Microsoft Azure CLI",
      "servicePrincipalId": null,
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    }
  },
  "Level": "",
  "Location": "",
  "LoggedByService": "Invited Users",
  "OperationName": "Invite external user",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "ResourceProvider": "",
  "Result": "success",
  "ResultDescription": "",
  "ResultReason": "",
  "ResultSignature": "None",
  "ResultType": "",
  "SourceSystem": "Azure AD",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000018",
      "displayName": "zzcap.guest002",
      "type": "User",
      "userPrincipalName": "guest002_example.com#EXT#@example.onmicrosoft.com",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ],
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:29:23.1665391Z",
  "Type": "AuditLogs"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Result (kusto rule field)eqsuccess3 ruleskusto
AADOperationType (kusto rule field)inassign1 rulekusto
AADOperationType (kusto rule field)inassigneligiblerole1 rulekusto
Initiator (kusto rule field)neMS-PIM1 rulekusto
Initiator (kusto rule field)neMS-PIM-Fairfax1 rulekusto
RoleName (kusto rule field)containsadmin1 rulekusto
displayName_ (kusto rule field)eqrole.displayname1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID External Guest User Invited source low: Identifies an invitation to an external user in Azure Active Directory (AD). Azure AD is extended to include collaboration, allowing you to invite people from outside your organization to be guest users in your cloud account. Unless there is a business need to provision guest access, it is best practice avoid creating guest users. Guest users could potentially be overlooked indefinitely leading to a potential vulnerability.T1078, T1136, T1136.003

Splunk #

  • Azure AD External Guest User Invited source: The following analytic detects the invitation of an external guest user within Azure AD. It leverages Azure AD AuditLogs to identify events where an external user is invited, using fields such as operationName and initiatedBy. Monitoring…T1136, T1136.003

Kusto #

Panther #

References #

Invite external user with reset invitation status

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A guest user invitation was re-sent/reset.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Redeem external user invite

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A guest user redeemed their B2B invitation.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
AADOperationType (kusto rule field)inassign1 rulekusto
AADOperationType (kusto rule field)inassigneligiblerole1 rulekusto
Initiator (kusto rule field)neMS-PIM1 rulekusto
Initiator (kusto rule field)neMS-PIM-Fairfax1 rulekusto
RoleName (kusto rule field)containsadmin1 rulekusto
displayName_ (kusto rule field)eqrole.displayname1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • New External User Granted Admin Role source medium: This query will detect instances where a newly invited external user is granted an administrative role. By default this query will alert on any granted administrative role, however this can be modified using the roles variable if false positives occur in your environment. The maximum delta between invite and escalation to admin is 60 minues, this can be configured using the deltaBetweenInviteEscalation variable.T1098, T1098.001↳ also matches Invite external user

References #

Reset user password

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An administrator reset a user's password.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:19:43.0295193Z",
  "ActivityDisplayName": "Reset user password",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "38111001-2905-4c38-9395-32161a8d352f",
  "DurationMs": "0",
  "Id": "Directory_38111001-2905-4c38-9395-32161a8d352f_ATINI_154922994",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Reset user password",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c0c0ae41-eb18-4c87-a4ff-bea4bcd7bfd4",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "dwharn-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Restore user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A soft-deleted user account was restored.

References #

Risky user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user was flagged as risky by Identity Protection.

References #

Set force change user password

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user was flagged to change password at next sign-in.

References #

Suspicious activity reported

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Suspicious activity was reported for a user (e.g. MFA fraud report).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.auditlogs.properties.additional_details.key (elastic rule field)eqauthenticationmethod1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Entra ID User Reported Suspicious Activity source medium: Identifies suspicious activity reported by users in Microsoft Entra ID where users have reported suspicious activity related to their accounts, which may indicate potential compromise or unauthorized access attempts. Reported suspicious activity typically occurs during the authentication process and may involve various authentication methods, such as password resets, account recovery, or multi-factor authentication challenges. Adversaries may attempt to exploit user accounts by leveraging social engineering techniques or other methods to gain unauthorized access to sensitive information or resources.T1078, T1078.004, T1621

References #

Update StsRefreshTokenValidFrom Timestamp

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:19:43.0305196Z",
  "ActivityDisplayName": "Update StsRefreshTokenValidFrom Timestamp",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "38111001-2905-4c38-9395-32161a8d352f",
  "DurationMs": "0",
  "Id": "Directory_38111001-2905-4c38-9395-32161a8d352f_ATINI_154923002",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update StsRefreshTokenValidFrom Timestamp",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c0c0ae41-eb18-4c87-a4ff-bea4bcd7bfd4",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "dwharn-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Update user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user account attribute was modified.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:21.6826996Z",
  "ActivityDisplayName": "Update user",
  "AdditionalDetails": [
    {
      "key": "UserType",
      "value": "Member"
    },
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "78d9f525-1015-4dbb-a287-2d4667a8a99c",
  "DurationMs": "0",
  "Id": "Directory_78d9f525-1015-4dbb-a287-2d4667a8a99c_JANDY_146277434",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update user",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "TargetId.UserType",
          "oldValue": null,
          "newValue": "\"Member\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Result (kusto rule field)eqsuccess3 ruleskusto
Tactics (kusto rule field)containsexfiltration1 rulekusto
Value (kusto rule field)eqFalse1 rulekusto
azure_ad::logged_by_service (sigma rule field)eqcore directory1 rulesigma
type (kusto rule field)eqUser1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID Guest Account Promoted to Member source medium: Identifies Entra ID user accounts converted from Guest to Member type via an Update user operation. A Guest-to-Member conversion grants the account full directory read access, removes external-identity Conditional Access restrictions, and makes the account indistinguishable from an internal employee. An attacker who compromises a guest account and promotes it to Member type gains persistent tenant access without triggering role assignment alerts.T1098

Splunk #

Kusto #

  • Suspicious linking of existing user to external User source medium: This query will detect when an attempt is made to update an existing user and link it to an guest or external identity. These activities are unusual and such linking of external identities should be investigated. In some cases you may see internal Entra ID sync accounts (Sync_) do this which may be benignT1078, T1078.004
  • Dataverse - Guest user exfiltration following Power Platform defense impairment source high: Identifies a chain of events starting with disablement of Power Platform tenant isolation and removal of an environment's access security group. These events are correlated with Dataverse exfiltration alerts associated with the impacted environment and recently created Microsoft Entra guest users. Note: Activate other Dataverse analytics rules with the MITRE tactic 'Exfiltration' before enabling this rule.T1567, T1629
  • Suspicious modification of Global Administrator user properties source medium: This query will detect if user properties of Global Administrator are updated by an existing user. Usually only user administrator or other global administrator can update such properties. Investigate if such user change is an attempt to elevate an existing low privileged identity or rogue administrator activityT1078, T1078.004

References #

User changed default security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user changed their default authentication method.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser3 ruleskusto
Target (kusto rule field)eqvipusers2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

User deleted security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user removed one of their authentication methods.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser3 ruleskusto
Target (kusto rule field)eqvipusers2 ruleskusto
azure.auditlogs.properties.additional_details.key (elastic rule field)eqauthenticationmethod1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

References #

User registered security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user registered an authentication method (MFA/SSPR security info).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser3 ruleskusto
Target (kusto rule field)eqvipusers2 ruleskusto
azure_ad::logged_by_serviceeqauthentication methods2 ruleskusto, sigma
category (splunk rule field)eqauditlogs1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

Kusto #

References #

User reviewed security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user reviewed their registered security info.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Target (kusto rule field)eqvipusers1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

User Risk Detection

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Identity Protection raised a user-risk detection.

References #

Add Passkey (device-bound)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the registration of a device-bound passkey (FIDO2) credential for a user, where the private key is created and stored on a single security key or platform authenticator and never leaves that device. The addition of a strong phishing-resistant credential can reflect routine onboarding or attacker-driven MFA persistence.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-15T15:10:21.1205644Z",
  "ActivityDisplayName": "Add Passkey (device-bound)",
  "AdditionalDetails": [
    {
      "key": "AdditionalInfo",
      "value": "Successfully provisioned webauthn key with identifier OtHIhp90hGxT0bsHiAOJwU3A3KQozU9trqA0kkL/9TpqUJ77RI1ynZ0C+k8ecTTT for user aaaaaaaa-0000-0000-0000-000000000001. Details: none"
    },
    {
      "key": "AAGuid",
      "value": "a25342c0-3cdc-4414-8e46-f4807fca511c"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "3f6c1d84-9b52-4ea7-ae98-208f9c51ba05",
  "DurationMs": "0",
  "Id": "Device Registration Service_3f6c1d84-9b52-4ea7-ae98-208f9c51ba05_VAY7G_2342815329",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Device Registration Service",
  "OperationName": "Add Passkey (device-bound)",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": null,
      "displayName": "OtHIhp90hGxT0bsHiAOJwU3A3KQozU9trqA0kkL/9TpqUJ77RI1ynZ0C+k8ecTTT",
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "searchableDeviceKey",
          "oldValue": [],
          "newValue": [
            {
              "usage": "FIDO",
              "keyIdentifier": "OtHIhp90hGxT0bsHiAOJwU3A3KQozU9trqA0kkL/9TpqUJ77RI1ynZ0C+k8ecTTT",
              "creationTime": "7/15/2026 3:10:20 PM +00:00",
              "deviceId": "00000000-0000-0000-0000-000000000000",
              "customKeyInformation": {
                "Version": 1,
                "Attestation": 0,
                "VolumeType": 0,
                "SupportsNotification": 0,
                "WipKeyVersion": 0,
                "KeyStrength": 0,
                "KeyFormat": 3,
                "Platform": 0,
                "SyncType": 1,
                "ExtendedCustomKeyInformationVersion": 0,
                "ExtendedCustomKeyInfo": null
              }
            }
          ]
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Add passwordless phone sign-in credential

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the registration of a passwordless phone sign-in credential through Microsoft Authenticator, creating a device-bound, key-based credential unlocked by the user's PIN or biometric. New authentication credentials can indicate legitimate MFA registration or unauthorized account-persistence activity.

References #

Add platform credential

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the registration of a platform credential (such as Platform Credential for macOS provisioned through Platform SSO), which creates a Secure Enclave, hardware-bound cryptographic key used for phishing-resistant single sign-on to Microsoft Entra ID. A newly provisioned device-bound credential can reflect legitimate device enrollment or attacker persistence.

References #

Add user sponsor

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the addition of a sponsor (a user or group designated as responsible for the account) to a user, typically a guest. Sponsors support accountability and entitlement-management approval flows and do not by themselves grant administrative rights.

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-06-29T17:35:12.4382064Z",
  "ActivityDisplayName": "Add user sponsor",
  "AdditionalDetails": [],
  "Category": "UserManagement",
  "CorrelationId": "bffde0a9-6cc8-4919-89bd-b10d75dae179",
  "DurationMs": "0",
  "Id": "Directory_bffde0a9-6cc8-4919-89bd-b10d75dae179_GLKEV_154284491",
  "Identity": "Microsoft B2B Admin Worker",
  "InitiatedBy": {
    "app": {
      "appId": null,
      "displayName": "Microsoft B2B Admin Worker",
      "servicePrincipalId": "f29c763c-fa37-416a-8390-2cac9442ab0c",
      "servicePrincipalName": null,
      "agentType": "notAgentic",
      "blueprintId": null
    }
  },
  "Level": "",
  "Location": "",
  "LoggedByService": "Core Directory",
  "OperationName": "Add user sponsor",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "ResourceProvider": "",
  "Result": "success",
  "ResultDescription": "",
  "ResultReason": "",
  "ResultSignature": "None",
  "ResultType": "",
  "SourceSystem": "Azure AD",
  "TargetResources": [
    {
      "id": "12ee7630-8380-4213-b85f-ae1525aa9857",
      "displayName": null,
      "type": "User",
      "modifiedProperties": [
        {
          "displayName": "User.ObjectID",
          "oldValue": null,
          "newValue": "\"aaaaaaaa-0000-0000-0000-000000000001\""
        },
        {
          "displayName": "User.UPN",
          "oldValue": null,
          "newValue": "\"adminuser@example.onmicrosoft.com\""
        },
        {
          "displayName": "User.PUID",
          "oldValue": null,
          "newValue": "\"10000000AAAAAAAA\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic",
      "userPrincipalName": "zzcap.guest001_gmail.com#EXT#@example.onmicrosoft.com"
    },
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic",
      "userPrincipalName": "adminuser@example.onmicrosoft.com"
    }
  ],
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:35:12.4382064Z",
  "Type": "AuditLogs"
}

References #

Add Windows Hello for Business credential

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the registration of a Windows Hello for Business credential, a key-based passwordless authentication credential, for a user account. Registration of a new authentication credential can be a persistence technique when performed by an attacker on a compromised account.

References #

Admin started password reset

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that an administrator initiated a password reset on behalf of a user through Microsoft Entra authentication methods / self-service password management. Unexpected admin-initiated resets are relevant to account-takeover and persistence monitoring.

References #

Apply review

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that the results of a completed access review were applied, enacting all reviewer decisions for the review so that identities denied access have their group membership or application assignment removed.

References #

Approve all requests in business flow

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a bulk action that approves all pending decisions within a Microsoft Entra access review (referred to as a business flow), continuing access for every reviewed user in a single operation. Access-review approvals certify continued access, so bulk approvals can mask individual decisions and are worth scrutiny.

References #

Auto apply review

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the automatic application of a completed access review's results to the target resource (for example, removing access for users who were denied) when the review has 'Auto apply results to resource' enabled, rather than an administrator manually applying the results.

References #

Auto review

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a system-generated decision on a user's access within an access review, applied automatically by the access reviews engine rather than by a human reviewer (for example, applying recommendations or the configured default decision when reviewers don't respond by the review end date).

References #

Blocked from self-service password reset

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user was throttled and temporarily blocked from self-service password reset after too many attempts. Microsoft throttles after five attempts within an hour to validate a phone number, to use the security-questions gate, or to reset the same account's password, after which the user must wait 24 hours; repeated blocks can indicate password-reset abuse or an account-takeover attempt.

References #

Bulk create users - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records completion of an administrator-initiated bulk user-creation operation from an uploaded CSV template in the Microsoft Entra admin center; the 'finished (bulk)' marker denotes the batch job completing. Mass account creation can indicate bulk provisioning of unauthorized or persistence accounts.

References #

Bulk delete users - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a bulk operation to delete multiple user accounts, submitted as a CSV in the Microsoft Entra admin center, finished. Mass account deletion can indicate destructive activity or defense evasion through removal of identities.

References #

Bulk invite users - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a bulk operation to send B2B collaboration (guest) invitations from an uploaded CSV finished. A surge of external guest invitations can indicate unsanctioned external collaboration or guest-account persistence.

References #

Bulk restore deleted users - finished (bulk)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a bulk operation to restore soft-deleted user accounts from the recycle bin, using an uploaded CSV, finished. Restoring previously deleted accounts can re-establish access and serve as a persistence mechanism.

References #

Change password (self-service)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user changed their own password through Microsoft Entra self-service password management. This is the self-service change-password flow, distinct from the separate self-service or administrator password-reset activities listed in the same service section.

References #

Change user license

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

The product licenses assigned to a user were changed in the directory (licenses added, removed, or modified). License changes can grant or revoke access to services and capabilities tied to a SKU.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-01T20:32:12.9796029Z",
  "ActivityDisplayName": "Change user license",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "83479b0d-4e3f-469d-9ed9-794cd4d1370e",
  "DurationMs": "0",
  "Id": "Directory_83479b0d-4e3f-469d-9ed9-794cd4d1370e_S03BN_113612636",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Change user license",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "modifiedProperties": [
        {
          "displayName": "LicenseAssignmentDetail",
          "oldValue": [
            {
              "ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
              "Status": 0,
              "AccountId": "11111111-1111-1111-1111-111111111111",
              "SkuId": "b126b073-72db-4a9d-87a4-b17afe41d4ab",
              "Error": 0,
              "StatusUpdateTimestamp": "2026-06-30T14:23:04.6932105Z",
              "DisabledPlans": [],
              "EncodingVersion": 2
            },
            {
              "ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
              "Status": 0,
              "AccountId": "11111111-1111-1111-1111-111111111111",
              "SkuId": "c7df2760-2c81-4ef7-b578-5b5392b571df",
              "Error": 0,
              "StatusUpdateTimestamp": "2026-06-30T14:23:04.6932105Z",
              "DisabledPlans": [],
              "EncodingVersion": 2
            }
          ],
          "newValue": [
            {
              "ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
              "Status": 0,
              "AccountId": "11111111-1111-1111-1111-111111111111",
              "SkuId": "c7df2760-2c81-4ef7-b578-5b5392b571df",
              "Error": 0,
              "StatusUpdateTimestamp": "2026-07-01T20:32:12.8837518Z",
              "DisabledPlans": [],
              "EncodingVersion": 2
            },
            {
              "ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
              "Status": 0,
              "AccountId": "11111111-1111-1111-1111-111111111111",
              "SkuId": "b126b073-72db-4a9d-87a4-b17afe41d4ab",
              "Error": 0,
              "StatusUpdateTimestamp": "2026-07-01T20:32:12.8837518Z",
              "DisabledPlans": [],
              "EncodingVersion": 2
            }
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"LicenseAssignmentDetail\""
        },
        {
          "displayName": "TargetId.UserType",
          "oldValue": null,
          "newValue": "\"Member\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic",
      "userPrincipalName": "adminuser@example.onmicrosoft.com"
    }
  ]
}

References #

Convert federated user to managed

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the conversion of an individual user account from federated authentication to managed (cloud) authentication, as occurs when a domain is migrated from federation to cloud authentication. Changes to domain and user authentication configuration are worth monitoring because federation tampering is a known persistence and defense-evasion vector.

References #

Create application password for user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An app password was created for a user. App passwords let legacy, non-browser clients that cannot complete multifactor authentication sign in with an automatically generated secret, so their creation is a potential MFA-bypass or persistence vector worth monitoring.

References #

Create business flow

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A business flow was created in Microsoft Entra access reviews. Current access-reviews documentation does not define a standalone 'business flow' object, so this most likely represents an internal configuration element of an access review (defining what is reviewed and by whom); the precise meaning is unconfirmed.

References #

Create governance policy template

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A governance policy template was created in Microsoft Entra Tenant Governance, a reusable blueprint that defines a cross-tenant governance relationship by mapping selected built-in roles to a group in the governing tenant. Applied to governance relationships, it grants that group standing access in governed tenants, so it is relevant to cross-tenant privilege review.

References #

Delete application password for user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the deletion of an app-password credential belonging to a user. App passwords let legacy, non-browser clients that cannot satisfy a multifactor authentication prompt sign in, so deleting one revokes that MFA-bypass credential and causes any legacy app still using it to fail authentication; the event can reflect benign cleanup or credential tampering.

References #

Delete business flow

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the deletion of a business flow object within Microsoft Entra access reviews. In the access-reviews feature a business flow is a construct used to scope a review (for example, to the type of resource being reviewed); its exact schema is not detailed in the public audit reference, so it is interpreted conservatively as removal of an access-review configuration object.

References #

Delete external user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An external (B2B guest) user was deleted from the directory. The Invited users service handles B2B collaboration guest accounts, and removing a guest revokes that external identity's access to the tenant.

References #

Delete governance policy template

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A governance policy template associated with Microsoft Entra access reviews was deleted. Access reviews use policy definitions to schedule and govern recurring reviews of access, but the precise template object is not fully established from the operation name and service alone.

References #

Delete Passkey (device-bound)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records deletion of a device-bound passkey (FIDO2) authentication method registered to a user, removing a phishing-resistant credential. Removing a user's strong authentication method can precede account takeover or be used to clean up after attacker-registered credentials, so it warrants review.

References #

Delete passwordless phone sign-in credential

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records deletion of a passwordless phone sign-in credential from a user in Azure AD B2C, where a phone number plus SMS one-time passcode can serve as the primary sign-in method. The cited doc grounds the B2C phone sign-in feature but not the specific credential-deletion audit event.

References #

Delete platform credential

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the removal of a Platform Credential for macOS, a secure-enclave-backed, hardware-bound cryptographic key provisioned through the Microsoft Enterprise single sign-on extension and used for single sign-on and authentication from a registered Mac. Deletion removes a device-bound credential tied to the user and device.

References #

Delete Windows Hello for Business credential

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records removal of a Windows Hello for Business credential from a user account under the B2C service (UserManagement category). Deletion of this key-based credential is relevant to credential-management monitoring, since it changes a user's available strong-authentication methods.

References #

Deny all decisions

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records denying all pending decisions in a Microsoft Entra access review at once, recommending that the affected users lose the access under review. The reference also lists a separate Policy-category 'Bulk Deny decisions' activity, which is distinct from this UserManagement 'Deny all decisions'.

References #

Deny all requests in business flow

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the bulk denial of all pending requests grouped under a single access-review business flow, so the affected users do not retain the access under review. 'Business flow' is the grouping term used by the older access-review/governance-policy model.

References #

Email not sent, user unsubscribed

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An invitation or notification email to an invited (B2B guest) user was not sent because the recipient had previously unsubscribed from these emails. This is an email-delivery status event rather than a security-relevant configuration change.

References #

Enable Strong Authentication

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that strong authentication, the legacy directory term for multifactor authentication (the strongAuthentication* user properties/claims), was enabled for a user account. Changes to a user's strong-authentication state affect MFA enforcement and are relevant to account-takeover and MFA-bypass monitoring.

References #

Fraud reported - no action taken

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user reported a multifactor authentication prompt as fraudulent under the legacy MFA Fraud Alert feature, and because automatic blocking was not enabled, the account was not blocked. A fraud report can signal MFA prompt bombing or an adversary holding valid credentials and attempting to satisfy an MFA challenge.

References #

Fraud reported - user is blocked for MFA

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user reported a multifactor authentication prompt as fraudulent under the legacy MFA Fraud Alert feature with automatic blocking enabled, so the account was blocked from further MFA until an administrator unblocks it. A fraud report can indicate MFA prompt bombing or an attacker attempting to authenticate with stolen credentials.

References #

Get passkey creation options

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records retrieval of WebAuthn passkey (FIDO2) creation options, the challenge and parameters issued to a user's authenticator at the start of passkey registration in Microsoft Entra ID. It precedes enrollment of a new passkey authentication method, which is relevant to monitoring for unauthorized strong-auth method registration (persistence).

References #

Hard Delete user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the permanent, non-recoverable removal of a user object from the tenant, either an administrator permanently deleting a soft-deleted user or the automatic purge after the 30-day soft-delete window. A hard-deleted user cannot be restored by administrators or Microsoft, so the event can indicate destruction of an account and its associated evidence (defense evasion).

References #

Invitation Email

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a Microsoft Entra B2B collaboration invitation email was sent to an invited external (guest) user, the message that carries the redemption/redirect link the recipient uses to accept the invitation and gain external access.

References #

Invite internal user to B2B collaboration

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that an existing internal user was invited into Microsoft Entra B2B collaboration. The invitation requires the user's Mail property be set to the external email they will use; when the user redeems it, the existing internal user object is converted to a B2B user and must thereafter sign in with external credentials.

References #

Redeem extern user invite

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An external B2B collaboration user redeemed an invitation to the tenant, completing guest-account onboarding. New guest redemptions are relevant to monitoring external access and initial onboarding of outside identities.

References #

Remove app role assignment from user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An app role assignment was removed from a user, revoking that user's assignment to an application and any app role it conferred. Changes to user application access are relevant to access-governance monitoring.

Example Audit Log Entry #

{
  "AADOperationType": "Unassign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:19.2082777Z",
  "ActivityDisplayName": "Remove app role assignment from user",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "5ceb6d0e-4890-44ed-9f7b-5fff2bed91fd",
  "DurationMs": "0",
  "Id": "Directory_5ceb6d0e-4890-44ed-9f7b-5fff2bed91fd_K3LZP_11973335",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove app role assignment from user",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "dw-harness-ara-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "AppRole.Id",
          "oldValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\"",
          "newValue": null
        },
        {
          "displayName": "AppRole.Value",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "AppRole.DisplayName",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "AppRoleAssignment.CreatedDateTime",
          "oldValue": "\"2026-07-24T03:21:18.1619889Z\"",
          "newValue": null
        },
        {
          "displayName": "AppRoleAssignment.LastModifiedDateTime",
          "oldValue": "\"2026-07-24T03:21:18.1619889Z\"",
          "newValue": null
        },
        {
          "displayName": "User.ObjectID",
          "oldValue": "\"aaaaaaaa-0000-0000-0000-000000000001\"",
          "newValue": null
        },
        {
          "displayName": "User.UPN",
          "oldValue": "\"adminuser@example.onmicrosoft.com\"",
          "newValue": null
        },
        {
          "displayName": "User.PUID",
          "oldValue": "\"1111111111111111\"",
          "newValue": null
        },
        {
          "displayName": "TargetId.ServicePrincipalNames",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Remove OrganizationalUnit assigned to a user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records removal of the organizational-unit association assigned to a user object in the Core Directory (UserManagement category). This is an uncommon directory-management activity referring to the directory's organizational-unit construct, which is distinct from administrative units.

References #

Remove user sponsor

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A sponsor was removed from a user's Sponsors attribute. Sponsors are the users or groups designated to manage and vouch for a (typically guest) user's lifecycle and can serve as approvers in entitlement management, so removal severs that accountability link.

References #

Request approved

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

An approval decision was recorded in the context of Microsoft Entra access reviews, marking a reviewed access request as approved so the user's access is granted or retained. Reviewer approve and deny decisions are written to the Entra audit logs as the review's audit trail.

References #

Request denied

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a deny decision in a Microsoft Entra access review, where a reviewer denied a user's continued access to the reviewed group or application. When the review results are applied, Microsoft Entra removes the denied user's membership or application assignment, so these entries are relevant to access-governance and least-privilege monitoring.

References #

Reset password

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a password reset performed on a user account in the directory. Because a password reset can enable account takeover or persistence, these entries are worth correlating against the target account and the actor that performed the reset.

References #

Reset password (by admin)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that an administrator reset another user's password on that user's behalf. Admin-initiated resets of accounts the admin does not own are relevant to account-takeover and persistence detection.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Reset password (self-service)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user successfully reset their own password through Microsoft Entra self-service password reset (SSPR).

References #

Restore multifactor authentication on all remembered devices

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records the per-user MFA administrative action that restores multifactor authentication on all of a user's remembered (trusted) devices, revoking the remembered-device bypass so the user must complete MFA again at the next sign-in on those devices. It is a remediation action used when an account or a trusted device may be compromised.

References #

Security info saved for self-service password reset

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user saved or updated the security (authentication) information, such as a mobile phone, alternate email, or security questions, used to reset their password through self-service password reset. Changes to account-recovery contact information are a known account-takeover persistence vector and warrant review when unexpected.

References #

Self-service password reset flow activity progress

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records each specific step a user proceeds through, such as passing a particular password reset authentication gate, as part of the self-service password reset process. A success entry indicates the step completed, while a failure entry carries a status reason explaining why that step of the reset flow failed.

References #

Set user manager

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

The manager attribute of a user was set or updated, linking the user to a manager in the directory. The manager value can drive dynamic group membership and approval/lifecycle workflows.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:22.0427163Z",
  "ActivityDisplayName": "Set user manager",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "78d9f525-1015-4dbb-a287-2d4667a8a99c",
  "DurationMs": "0",
  "Id": "Directory_78d9f525-1015-4dbb-a287-2d4667a8a99c_JANDY_146277731",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Set user manager",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "New Manager",
          "oldValue": null,
          "newValue": "\"None\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Takeover user cloned

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user from an unmanaged ('shadow') Microsoft Entra directory was cloned into a managed tenant during an admin takeover of that directory's domain. Admin takeover lets an organization assume control of a self-service-created unmanaged directory and bring its users into the managed tenant.

References #

Unlock user account (self-service)

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user unlocked their own account through Microsoft Entra self-service password reset (SSPR), with no administrator or help-desk involvement. Repeated self-service unlocks against an account can accompany password-spray or brute-force activity.

References #

Update business flow

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a modification to a business flow object within Microsoft Entra access reviews. Access-review configuration changes are written to the audit log under UserManagement, so this entry is relevant when monitoring tampering with access-certification governance, though the specific 'business flow' construct is not defined in current product documentation.

References #

Update governance policy template

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A Microsoft Entra Tenant Governance governance policy template was updated. A governance policy template is a reusable blueprint for cross-tenant governance relationships that defines cross-tenant delegated administration roles (Entra built-in roles granted to a governing tenant, provisioned as GDAP) and managed multitenant applications, so changes are privilege-relevant because they set what cross-tenant administrative access a relationship can grant.

References #

Update MyStaff feature value

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A My Staff configuration value was changed. My Staff delegates scoped user-management tasks (such as password resets and phone-number management within an administrative unit) to local managers, so changes to its settings affect who can perform delegated account actions.

References #

Update OrganizationalUnit assigned to a user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

The organizational unit assigned to a user account in the Microsoft Entra Core Directory was changed. The exact directory feature behind this assignment was not confirmed against a Learn doc.

References #

Update per-user multifactor authentication state

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

A user's legacy per-user multifactor authentication state (Disabled, Enabled, or Enforced) was changed. Moving a user to Disabled removes them from per-user MFA enrollment and can weaken authentication assurance (defense evasion).

References #

Updated ConvergedUXV2 feature value

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a change to the tenant-level 'ConvergedUXV2' Microsoft Entra directory feature flag value. The audit record captures that this internal feature toggle was set to a new value; the operation name alone does not document the exact behavior the flag controls.

References #

Updated MyApps feature value

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a change to the tenant-level 'MyApps' Microsoft Entra directory feature flag value, an internal feature toggle whose name references the My Apps end-user portal. The audit record captures the value change; the operation name alone does not document the exact behavior toggled.

References #

Updated SignInReports feature value

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a change to the tenant-level 'SignInReports' Microsoft Entra directory feature flag value, an internal feature toggle whose name references sign-in reporting. The audit record captures the value change; the exact behavior toggled is not documented by the operation name alone.

References #

Updated SSPRConvergence feature value

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records a change to the tenant-level 'SSPRConvergence' Microsoft Entra directory feature flag value, an internal feature toggle whose name references self-service password reset (SSPR) registration convergence (the combined security-info registration of SSPR and MFA methods). The audit record captures the value change; the exact behavior is not documented by the operation name alone.

References #

User canceled security info registration

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user exited the combined security information registration experience (MFA and SSPR methods) without completing it, leaving the required authentication methods unregistered. These combined-registration events are logged under the Authentication Methods service.

References #

User Password Registration

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user registered for self-service password reset through Microsoft Identity Manager (MIM), supplying the authentication methods (such as a mobile phone number or security questions) later used to reset their password. MIM exports this activity to Microsoft Entra, where it surfaces in the audit logs under the MIM Service category.

References #

User Password Reset

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user reset their own password using Microsoft Identity Manager (MIM) self-service password reset, including the gates or methods used to authenticate. MIM exports this activity to Microsoft Entra, where it surfaces in the audit logs under the MIM Service category.

References #

User registered all required security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user completed combined registration by registering all the security information required by the tenant's multifactor authentication and SSPR policies, making the account compliant for both MFA and self-service password reset. These events are logged under the Authentication Methods service.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

User started password change

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user initiated a self-service password change, supplying their current password to set a new one (a voluntary change, or one forced because the password expired). Marks the start of the change flow rather than its completion.

References #

user started password reset

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user initiated a self-service password reset for a forgotten password through the Microsoft Entra password reset portal. A surge of these events can accompany account-takeover attempts.

References #

User started security info registration

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user began registering security info, the authentication methods used for multifactor authentication and self-service password reset, through combined security info registration. Newly added authentication methods are a common account-takeover persistence vector, so unexpected registrations warrant review.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

User updated security info

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Description

Records that a user modified their registered security info, that is the authentication methods used for multifactor authentication and self-service password reset. Unexpected changes to a user's MFA methods are a frequent post-compromise persistence technique and are worth alerting on.

References #

Update PasswordProfile

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:19.7349749Z",
  "ActivityDisplayName": "Update PasswordProfile",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "4abcd032-2a4f-4c54-9f6f-ff886773f36b",
  "DurationMs": "0",
  "Id": "Directory_4abcd032-2a4f-4c54-9f6f-ff886773f36b_O4VOL_159399257",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update PasswordProfile",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "ForceChangePassword",
          "oldValue": "\"False\"",
          "newValue": "\"True\""
        },
        {
          "displayName": "Password",
          "oldValue": null,
          "newValue": null
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Create Temporary Access Pass method for user

#
Source
Microsoft Entra ID audit log
Audit Category
UserManagement

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.