Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: UserManagement
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add user | A new user account was created in the directory. | Y | Y |
| Admin deleted security info | An admin removed a user's security info. | N | Y |
| Admin registered security info | An admin registered security info on behalf of a user (e.g. Temporary Access Pass). | Y | Y |
| Admin updated security info | An admin modified a user's security info. | N | Y |
| Bulk invite users - started (bulk) | A bulk guest-invite operation was started. | N | Y |
| Change user password | A user changed their own password. | N | N |
| Delete user | A user account was deleted. | Y | Y |
| Disable account | A user account was disabled. | N | N |
| Disable Strong Authentication | Strong authentication (MFA) was disabled for a user. | N | Y |
| Enable account | A user account was enabled. | N | Y |
| Invite external user | A guest (B2B) user was invited to the tenant. | Y | Y |
| Invite external user with reset invitation status | A guest user invitation was re-sent/reset. | N | Y |
| Redeem external user invite | A guest user redeemed their B2B invitation. | N | Y |
| Reset user password | An administrator reset a user's password. | Y | N |
| Restore user | A soft-deleted user account was restored. | N | N |
| Risky user | A user was flagged as risky by Identity Protection. | N | N |
| Set force change user password | A user was flagged to change password at next sign-in. | N | N |
| Suspicious activity reported | Suspicious activity was reported for a user (e.g. MFA fraud report). | N | Y |
| Update Sts | A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks. | Y | N |
| Update user | A user account attribute was modified. | Y | Y |
| User changed default security info | A user changed their default authentication method. | N | Y |
| User deleted security info | A user removed one of their authentication methods. | N | Y |
| User registered security info | A user registered an authentication method (MFA/SSPR security info). | N | Y |
| User reviewed security info | A user reviewed their registered security info. | N | Y |
| User Risk Detection | Identity Protection raised a user-risk detection. | N | N |
| Add Passkey (device-bound) | A device-bound passkey (FIDO2) credential was registered for a user. | Y | N |
| Add passwordless phone sign-in credential | A passwordless phone sign-in (Authenticator) credential was registered for a user. | N | N |
| Add platform credential | A platform credential (Secure Enclave hardware-bound SSO key) was registered for a user. | N | N |
| Add user sponsor | Adds a sponsor (a user or group responsible for the account) to a user. | Y | N |
| Add Windows Hello for Business credential | Registers a Windows Hello for Business (key-based passwordless) credential for a user. | N | N |
| Admin started password reset | An administrator initiated a password reset on behalf of a user via Entra authentication methods. | N | N |
| Apply review | The results of a completed access review were applied, removing access for denied users. | N | N |
| Approve all requests in business flow | Bulk approval of all pending decisions in an access review (business flow), continuing access for the reviewed users. | N | N |
| Auto apply review | An access review's results were automatically applied to the resource, removing denied users' access. | N | N |
| Auto review | A system-generated (automatic) access review decision was recorded for a user. | N | N |
| Blocked from self-service password reset | A user was throttled and blocked from self-service password reset after too many reset attempts (5/hour, then a 24-hour wait). | N | N |
| Bulk create users - finished (bulk) | Completion of an administrator bulk create-users operation from a CSV upload. | N | N |
| Bulk delete users - finished (bulk) | A bulk job that deletes multiple user accounts from an uploaded CSV completed in the Entra admin center. | N | N |
| Bulk invite users - finished (bulk) | A bulk job that sends B2B guest invitations from an uploaded CSV completed. | N | N |
| Bulk restore deleted users - finished (bulk) | A bulk job that restores soft-deleted user accounts from an uploaded CSV completed. | N | N |
| Change password (self-service) | A user changed their own password via self-service password management. | N | N |
| Change user license | The product licenses assigned to a user were changed. | Y | N |
| Convert federated user to managed | A user account was converted from federated to managed (cloud) authentication. | N | N |
| Create application password for user | An app password was created for a user, letting a legacy client sign in without completing MFA. | N | N |
| Create business flow | A business flow was created in Entra access reviews (internal access-review configuration; exact object undocumented). | N | N |
| Create governance policy template | Creation of a tenant-governance policy template: a reusable blueprint mapping built-in roles to a group for cross-tenant governance. | N | N |
| Delete application password for user | An app-password credential was deleted for a user, revoking a legacy non-MFA sign-in credential. | N | N |
| Delete business flow | A business flow object within Microsoft Entra access reviews was deleted. | N | N |
| Delete external user | Deletion of an external B2B guest user from the directory, revoking that guest's tenant access. | N | N |
| Delete governance policy template | Deletion of an access reviews governance policy template. | N | N |
| Delete Passkey (device-bound) | Deletes a user's device-bound passkey (FIDO2) authentication method, removing a phishing-resistant credential. | N | N |
| Delete passwordless phone sign-in credential | Deletes a user's passwordless phone sign-in credential in Azure AD B2C. | N | N |
| Delete platform credential | Removal of a macOS Platform Credential (secure-enclave hardware-bound SSO key) from a registered Mac. | N | N |
| Delete Windows Hello for Business credential | Removes a Windows Hello for Business credential from a user account. | N | N |
| Deny all decisions | All pending decisions in an access review were denied at once. | N | N |
| Deny all requests in business flow | All requests within an access-review business flow were denied. | N | N |
| Email not sent, user unsubscribed | An invited-user email was suppressed because the recipient had previously unsubscribed. | N | N |
| Enable Strong Authentication | Records strong authentication (multifactor authentication) being enabled for a directory user. | N | N |
| Fraud reported - no action taken | User reported an MFA prompt as fraud (legacy Fraud Alert); account was not blocked. | N | N |
| Fraud reported - user is blocked for MFA | User reported an MFA prompt as fraud (legacy Fraud Alert); account was blocked for MFA. | N | N |
| Get passkey creation options | Retrieval of WebAuthn passkey (FIDO2) creation options at the start of passkey registration in Entra ID. | N | N |
| Hard Delete user | Permanent, non-recoverable removal of a user object from the tenant. | N | N |
| Invitation Email | A B2B collaboration invitation email was sent to an invited external user. | N | N |
| Invite internal user to B2 | An existing internal user was invited into B2B collaboration to sign in with an external email identity. | N | N |
| Redeem extern user invite | An external (B2B collaboration) guest user redeemed an invitation to the tenant. | N | N |
| Remove app role assignment from user | An app role assignment was removed from a user, revoking the user's assignment to an application. | Y | N |
| Remove Organizational | Removal of the organizational-unit association assigned to a user object in the directory (distinct from administrative units). | N | N |
| Remove user sponsor | A sponsor was removed from a user's Sponsors attribute (the users/groups that vouch for that user). | N | N |
| Request approved | An access request reviewed in an access review was approved (access granted or retained). | N | N |
| Request denied | A reviewer denied a user's continued access in an access review; applying results removes their membership or assignment. | N | N |
| Reset password | A password was reset on a user account in the directory. | N | N |
| Reset password (by admin) | An administrator reset another user's password on their behalf. | N | Y |
| Reset password (self-service) | A user reset their own password through Microsoft Entra self-service password reset (SSPR). | N | N |
| Restore multifactor authentication on all remembered devices | An admin restored MFA on a user's remembered devices, forcing re-verification at next sign-in. | N | N |
| Security info saved for self-service password reset | A user saved or updated the security info (phone, alternate email, or questions) used for self-service password reset. | N | N |
| Self-service password reset flow activity progress | Records each step a user passes through (such as a password reset authentication gate) during the SSPR flow. | N | N |
| Set user manager | The manager attribute of a user was set or updated. | Y | N |
| Takeover user cloned | A user was cloned into the managed tenant during admin takeover of an unmanaged directory. | N | N |
| Unlock user account (self-service) | A user unlocked their own account via self-service password reset (SSPR). | N | N |
| Update business flow | Update to a business flow object used by Microsoft Entra access reviews. | N | N |
| Update governance policy template | A Tenant Governance policy template (cross-tenant delegated admin roles and multitenant apps) was updated. | N | N |
| Update My | A My Staff configuration value governing delegated user management was changed. | N | N |
| Update Organizational | The organizational unit assigned to a user account was changed. | N | N |
| Update per-user multifactor authentication state | A user's legacy per-user MFA state (Disabled/Enabled/Enforced) was changed. | N | N |
| Updated Converged | A tenant-level directory feature flag 'ConvergedUXV2' value (internal Entra feature toggle) was changed. | N | N |
| Updated My | A tenant-level directory feature flag 'MyApps' value (My Apps portal feature toggle) was changed. | N | N |
| Updated Sign | A tenant-level directory feature flag 'SignInReports' value (sign-in reporting feature toggle) was changed. | N | N |
| Updated SSPRConvergence feature value | A tenant-level directory feature flag 'SSPRConvergence' value (SSPR/MFA combined-registration toggle) was changed. | N | N |
| User canceled security info registration | User exited combined MFA/SSPR security info registration without completing it. | N | N |
| User Password Registration | User registered authentication methods for self-service password reset via MIM. | N | N |
| User Password Reset | User reset their own password via MIM self-service password reset. | N | N |
| User registered all required security info | User completed registering all MFA/SSPR security info required by tenant policy. | N | Y |
| User started password change | User initiated a self-service password change, supplying the current password to set a new one (voluntary or forced). | N | N |
| user started password reset | User initiated a self-service password reset for a forgotten password via the Entra password reset portal. | N | N |
| User started security info registration | User began registering security info (MFA/SSPR authentication methods) via combined security info registration. | N | Y |
| User updated security info | User modified their registered security info (the MFA/SSPR authentication methods on their account). | N | N |
| Update Password | Y | N | |
| Create Temporary Access Pass method for user | N | Y |
Add user
#Description
A new user account was created in the directory.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:20.000974Z",
"ActivityDisplayName": "Add user",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "4abcd032-2a4f-4c54-9f6f-ff886773f36b",
"DurationMs": "0",
"Id": "Directory_4abcd032-2a4f-4c54-9f6f-ff886773f36b_O4VOL_159399491",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add user",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
"displayName": null,
"type": "User",
"userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "AccountEnabled",
"oldValue": [],
"newValue": [
true
]
},
{
"displayName": "DisplayName",
"oldValue": [],
"newValue": [
"dw harness manager user"
]
},
{
"displayName": "MailNickname",
"oldValue": [],
"newValue": [
"dwhmgrcf516524"
]
},
{
"displayName": "StsRefreshTokensValidFrom",
"oldValue": [],
"newValue": [
"2026-07-24T03:20:19Z"
]
},
{
"displayName": "UserPrincipalName",
"oldValue": [],
"newValue": [
"dwharn-manager-cf516524@example.onmicrosoft.com"
]
},
{
"displayName": "UserType",
"oldValue": [],
"newValue": [
"Member"
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"AccountEnabled, DisplayName, MailNickname, StsRefreshTokensValidFrom, UserPrincipalName, UserType\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Result (kusto rule field) | eq | success | 3 rules | kusto |
Status (sigma rule field) | eq | success | 1 rule | sigma |
type (kusto rule field) | eq | User | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078↳ also matches Delete user Kusto #
T1136, T1136.003T1136, T1136.003T1136, T1136.003YARA-L #
T1098, T1098.003↳ also matches Add member to role
References #
Admin deleted security info
#Description
An admin removed a user's security info.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 3 rules | kusto |
Target (kusto rule field) | eq | vipusers | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098↳ also matches Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User reviewed security info T1078, T1078.004, T1556, T1556.006↳ also matches Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User registered all required security info, User started security info registration T1098↳ also matches Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User reviewed security info
References #
Admin registered security info
#Description
An admin registered security info on behalf of a user (e.g. Temporary Access Pass).
Example Audit Log Entry #
{
"AADOperationType": "ServiceApi",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-06-29T17:35:05.3981186Z",
"ActivityDisplayName": "Admin registered security info",
"AdditionalDetails": [
{
"key": "InitiatedFrom",
"value": "Microsoft Azure CLI (04b07795-8ddb-461a-bbee-02f9e1bf7b46)"
}
],
"Category": "UserManagement",
"CorrelationId": "c06851d2-f93d-494f-99bb-5729c784f0bc",
"DurationMs": "0",
"Id": "Authentication Methods_c06851d2-f93d-494f-99bb-5729c784f0bc_E84SE_119687324",
"Identity": "Admin User",
"InitiatedBy": {
"app": {
"appId": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"displayName": "Microsoft Azure CLI",
"servicePrincipalId": null,
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
},
"user": {
"displayName": "Admin User",
"agentType": "notAgentic",
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"userType": "Member"
}
},
"Level": "",
"Location": "",
"LoggedByService": "Authentication Methods",
"OperationName": "Admin registered security info",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"ResourceProvider": "",
"Result": "clientError",
"ResultDescription": "Admin failed to register phone method for user",
"ResultReason": "Admin failed to register phone method for user",
"ResultSignature": "None",
"ResultType": "",
"SourceSystem": "Azure AD",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000014",
"displayName": "zzcap user 002",
"type": "User",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic",
"userPrincipalName": "zzcap-user-002@example.onmicrosoft.com"
}
],
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:35:05.3981186Z",
"Type": "AuditLogs"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 3 rules | kusto |
Target (kusto rule field) | eq | vipusers | 2 rules | kusto |
azure_ad::target_user_upn (kusto rule field) | eq | admin_users | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004Elastic #
T1078, T1078.004, T1550↳ also matches User registered security info, Create Temporary Access Pass method for user Kusto #
T1098↳ also matches Admin deleted security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User reviewed security info T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User registered all required security info, User started security info registration T1078, T1078.004
References #
Admin updated security info
#Description
An admin modified a user's security info.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 3 rules | kusto |
Target (kusto rule field) | eq | vipusers | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098↳ also matches Admin deleted security info, Admin registered security info, User changed default security info, User deleted security info, User registered security info, User reviewed security info T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin registered security info, User changed default security info, User deleted security info, User registered security info, User registered all required security info, User started security info registration T1098↳ also matches Admin deleted security info, Admin registered security info, User changed default security info, User deleted security info, User registered security info, User reviewed security info
References #
Bulk invite users - started (bulk)
#Description
A bulk guest-invite operation was started.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004, T1087, T1087.004, T1136, T1136.003↳ also matches Invite external user, Invite external user with reset invitation status
References #
Delete user
#Description
A user account was deleted.
Example Audit Log Entry #
{
"AADOperationType": "Delete",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:23.205928Z",
"ActivityDisplayName": "Delete user",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "fd89b99b-8898-496c-baeb-234058b0ee12",
"DurationMs": "0",
"Id": "Directory_fd89b99b-8898-496c-baeb-234058b0ee12_M2FKB_152361561",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Delete user",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
"displayName": null,
"type": "User",
"userPrincipalName": "c1149e7adad247579f06580700c96bd3dwharn-manager-cf516524@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Is Hard Deleted",
"oldValue": null,
"newValue": "\"False\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | User | 2 rules | kusto |
Status (sigma rule field) | eq | success | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078↳ also matches Add user Kusto #
T1078, T1078.004T1078, T1078.004↳ also matches Add user T1078, T1078.004↳ also matches Add user
References #
Disable Strong Authentication
#Description
Strong authentication (MFA) was disabled for a user.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.auditlogs.properties.additional_details.key (elastic rule field) | eq | authenticationmethod | 1 rule | elastic |
category (splunk rule field) | eq | auditlogs | 1 rule | splunk |
properties.result (sigma rule field) | eq | success | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1556Elastic #
T1556, T1556.006↳ also matches User deleted security info Splunk #
T1556, T1556.006, T1586, T1586.003Kusto #
T1098, T1556
References #
Enable account
#Description
A user account was enabled.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098↳ also matches Update user, Reset password (by admin)
References #
Invite external user
#Description
A guest (B2B) user was invited to the tenant.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-06-29T18:29:23.1665391Z",
"ActivityDisplayName": "Invite external user",
"AdditionalDetails": [
{
"key": "oid",
"value": "aaaaaaaa-0000-0000-0000-000000000001"
},
{
"key": "tid",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "ipaddr",
"value": "203.0.113.10"
},
{
"key": "wids",
"value": "62e90394-69f5-4237-9190-012177145e10"
},
{
"key": "InvitationId",
"value": "d620c1cb-65b9-49ad-aefd-274ad23167a0"
},
{
"key": "invitedUserEmailAddress",
"value": "guest002@example.com"
}
],
"Category": "UserManagement",
"CorrelationId": "3e26f73e-0052-4894-aa30-324724991533",
"DurationMs": "0",
"Id": "Invited Users_3e26f73e-0052-4894-aa30-324724991533_JCNB8_1326807",
"Identity": "Microsoft Azure CLI",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"userType": "Member",
"agentType": "notAgentic"
},
"app": {
"appId": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"displayName": "Microsoft Azure CLI",
"servicePrincipalId": null,
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
}
},
"Level": "",
"Location": "",
"LoggedByService": "Invited Users",
"OperationName": "Invite external user",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"ResourceProvider": "",
"Result": "success",
"ResultDescription": "",
"ResultReason": "",
"ResultSignature": "None",
"ResultType": "",
"SourceSystem": "Azure AD",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000018",
"displayName": "zzcap.guest002",
"type": "User",
"userPrincipalName": "guest002_example.com#EXT#@example.onmicrosoft.com",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
],
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:29:23.1665391Z",
"Type": "AuditLogs"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Result (kusto rule field) | eq | success | 3 rules | kusto |
AADOperationType (kusto rule field) | in | assign | 1 rule | kusto |
AADOperationType (kusto rule field) | in | assigneligiblerole | 1 rule | kusto |
Initiator (kusto rule field) | ne | MS-PIM | 1 rule | kusto |
Initiator (kusto rule field) | ne | MS-PIM-Fairfax | 1 rule | kusto |
RoleName (kusto rule field) | contains | admin | 1 rule | kusto |
displayName_ (kusto rule field) | eq | role.displayname | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004Elastic #
T1078, T1136, T1136.003Splunk #
T1136, T1136.003Kusto #
T1078, T1078.004T1098, T1098.001↳ also matches Redeem external user invite T1534, T1566, T1587Panther #
T1078
References #
Invite external user with reset invitation status
#Description
A guest user invitation was re-sent/reset.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004, T1087, T1087.004, T1136, T1136.003↳ also matches Bulk invite users - started (bulk), Invite external user
References #
Redeem external user invite
#Description
A guest user redeemed their B2B invitation.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
AADOperationType (kusto rule field) | in | assign | 1 rule | kusto |
AADOperationType (kusto rule field) | in | assigneligiblerole | 1 rule | kusto |
Initiator (kusto rule field) | ne | MS-PIM | 1 rule | kusto |
Initiator (kusto rule field) | ne | MS-PIM-Fairfax | 1 rule | kusto |
RoleName (kusto rule field) | contains | admin | 1 rule | kusto |
displayName_ (kusto rule field) | eq | role.displayname | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098, T1098.001↳ also matches Invite external user
References #
Reset user password
#Description
An administrator reset a user's password.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:19:43.0295193Z",
"ActivityDisplayName": "Reset user password",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "38111001-2905-4c38-9395-32161a8d352f",
"DurationMs": "0",
"Id": "Directory_38111001-2905-4c38-9395-32161a8d352f_ATINI_154922994",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Reset user password",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c0c0ae41-eb18-4c87-a4ff-bea4bcd7bfd4",
"displayName": null,
"type": "User",
"userPrincipalName": "dwharn-cf516524@example.onmicrosoft.com",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Set force change user password
#Description
A user was flagged to change password at next sign-in.
References #
Suspicious activity reported
#Description
Suspicious activity was reported for a user (e.g. MFA fraud report).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.auditlogs.properties.additional_details.key (elastic rule field) | eq | authenticationmethod | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004, T1621
References #
Update StsRefreshTokenValidFrom Timestamp
#Description
A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:19:43.0305196Z",
"ActivityDisplayName": "Update StsRefreshTokenValidFrom Timestamp",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "38111001-2905-4c38-9395-32161a8d352f",
"DurationMs": "0",
"Id": "Directory_38111001-2905-4c38-9395-32161a8d352f_ATINI_154923002",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update StsRefreshTokenValidFrom Timestamp",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c0c0ae41-eb18-4c87-a4ff-bea4bcd7bfd4",
"displayName": null,
"type": "User",
"userPrincipalName": "dwharn-cf516524@example.onmicrosoft.com",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Update user
#Description
A user account attribute was modified.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:21.6826996Z",
"ActivityDisplayName": "Update user",
"AdditionalDetails": [
{
"key": "UserType",
"value": "Member"
},
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "78d9f525-1015-4dbb-a287-2d4667a8a99c",
"DurationMs": "0",
"Id": "Directory_78d9f525-1015-4dbb-a287-2d4667a8a99c_JANDY_146277434",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update user",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
"displayName": null,
"type": "User",
"userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "TargetId.UserType",
"oldValue": null,
"newValue": "\"Member\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Result (kusto rule field) | eq | success | 3 rules | kusto |
Tactics (kusto rule field) | contains | exfiltration | 1 rule | kusto |
Value (kusto rule field) | eq | False | 1 rule | kusto |
azure_ad::logged_by_service (sigma rule field) | eq | core directory | 1 rule | sigma |
type (kusto rule field) | eq | User | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004Elastic #
T1098Splunk #
T1098, T1098.005T1098T1098↳ also matches Enable account, Reset password (by admin) Kusto #
T1078, T1078.004T1567, T1629T1078, T1078.004
References #
User changed default security info
#Description
A user changed their default authentication method.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 3 rules | kusto |
Target (kusto rule field) | eq | vipusers | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User deleted security info, User registered security info, User reviewed security info T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User deleted security info, User registered security info, User registered all required security info, User started security info registration T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User deleted security info, User registered security info, User reviewed security info
References #
User deleted security info
#Description
A user removed one of their authentication methods.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 3 rules | kusto |
Target (kusto rule field) | eq | vipusers | 2 rules | kusto |
azure.auditlogs.properties.additional_details.key (elastic rule field) | eq | authenticationmethod | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1556, T1556.006↳ also matches Disable Strong Authentication Kusto #
T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User registered security info, User reviewed security info T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User registered security info, User registered all required security info, User started security info registration T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User registered security info, User reviewed security info
References #
User registered security info
#Description
A user registered an authentication method (MFA/SSPR security info).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type (kusto rule field) | eq | user | 3 rules | kusto |
Target (kusto rule field) | eq | vipusers | 2 rules | kusto |
azure_ad::logged_by_service | eq | authentication methods | 2 rules | kusto, sigma |
category (splunk rule field) | eq | auditlogs | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1556Elastic #
T1078, T1078.004, T1550↳ also matches Admin registered security info, Create Temporary Access Pass method for user Splunk #
T1556, T1556.006Kusto #
T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User reviewed security info T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered all required security info, User started security info registration T1098
References #
User reviewed security info
#Description
A user reviewed their registered security info.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Target (kusto rule field) | eq | vipusers | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info T1098↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info
References #
Add Passkey (device-bound)
#Description
Records the registration of a device-bound passkey (FIDO2) credential for a user, where the private key is created and stored on a single security key or platform authenticator and never leaves that device. The addition of a strong phishing-resistant credential can reflect routine onboarding or attacker-driven MFA persistence.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-15T15:10:21.1205644Z",
"ActivityDisplayName": "Add Passkey (device-bound)",
"AdditionalDetails": [
{
"key": "AdditionalInfo",
"value": "Successfully provisioned webauthn key with identifier OtHIhp90hGxT0bsHiAOJwU3A3KQozU9trqA0kkL/9TpqUJ77RI1ynZ0C+k8ecTTT for user aaaaaaaa-0000-0000-0000-000000000001. Details: none"
},
{
"key": "AAGuid",
"value": "a25342c0-3cdc-4414-8e46-f4807fca511c"
}
],
"Category": "UserManagement",
"CorrelationId": "3f6c1d84-9b52-4ea7-ae98-208f9c51ba05",
"DurationMs": "0",
"Id": "Device Registration Service_3f6c1d84-9b52-4ea7-ae98-208f9c51ba05_VAY7G_2342815329",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Device Registration Service",
"OperationName": "Add Passkey (device-bound)",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": null,
"displayName": "OtHIhp90hGxT0bsHiAOJwU3A3KQozU9trqA0kkL/9TpqUJ77RI1ynZ0C+k8ecTTT",
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "searchableDeviceKey",
"oldValue": [],
"newValue": [
{
"usage": "FIDO",
"keyIdentifier": "OtHIhp90hGxT0bsHiAOJwU3A3KQozU9trqA0kkL/9TpqUJ77RI1ynZ0C+k8ecTTT",
"creationTime": "7/15/2026 3:10:20 PM +00:00",
"deviceId": "00000000-0000-0000-0000-000000000000",
"customKeyInformation": {
"Version": 1,
"Attestation": 0,
"VolumeType": 0,
"SupportsNotification": 0,
"WipKeyVersion": 0,
"KeyStrength": 0,
"KeyFormat": 3,
"Platform": 0,
"SyncType": 1,
"ExtendedCustomKeyInformationVersion": 0,
"ExtendedCustomKeyInfo": null
}
}
]
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Add passwordless phone sign-in credential
#Description
Records the registration of a passwordless phone sign-in credential through Microsoft Authenticator, creating a device-bound, key-based credential unlocked by the user's PIN or biometric. New authentication credentials can indicate legitimate MFA registration or unauthorized account-persistence activity.
References #
Add platform credential
#Description
Records the registration of a platform credential (such as Platform Credential for macOS provisioned through Platform SSO), which creates a Secure Enclave, hardware-bound cryptographic key used for phishing-resistant single sign-on to Microsoft Entra ID. A newly provisioned device-bound credential can reflect legitimate device enrollment or attacker persistence.
References #
Add user sponsor
#Description
Records the addition of a sponsor (a user or group designated as responsible for the account) to a user, typically a guest. Sponsors support accountability and entitlement-management approval flows and do not by themselves grant administrative rights.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-06-29T17:35:12.4382064Z",
"ActivityDisplayName": "Add user sponsor",
"AdditionalDetails": [],
"Category": "UserManagement",
"CorrelationId": "bffde0a9-6cc8-4919-89bd-b10d75dae179",
"DurationMs": "0",
"Id": "Directory_bffde0a9-6cc8-4919-89bd-b10d75dae179_GLKEV_154284491",
"Identity": "Microsoft B2B Admin Worker",
"InitiatedBy": {
"app": {
"appId": null,
"displayName": "Microsoft B2B Admin Worker",
"servicePrincipalId": "f29c763c-fa37-416a-8390-2cac9442ab0c",
"servicePrincipalName": null,
"agentType": "notAgentic",
"blueprintId": null
}
},
"Level": "",
"Location": "",
"LoggedByService": "Core Directory",
"OperationName": "Add user sponsor",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"ResourceProvider": "",
"Result": "success",
"ResultDescription": "",
"ResultReason": "",
"ResultSignature": "None",
"ResultType": "",
"SourceSystem": "Azure AD",
"TargetResources": [
{
"id": "12ee7630-8380-4213-b85f-ae1525aa9857",
"displayName": null,
"type": "User",
"modifiedProperties": [
{
"displayName": "User.ObjectID",
"oldValue": null,
"newValue": "\"aaaaaaaa-0000-0000-0000-000000000001\""
},
{
"displayName": "User.UPN",
"oldValue": null,
"newValue": "\"adminuser@example.onmicrosoft.com\""
},
{
"displayName": "User.PUID",
"oldValue": null,
"newValue": "\"10000000AAAAAAAA\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic",
"userPrincipalName": "zzcap.guest001_gmail.com#EXT#@example.onmicrosoft.com"
},
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic",
"userPrincipalName": "adminuser@example.onmicrosoft.com"
}
],
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:35:12.4382064Z",
"Type": "AuditLogs"
}
References #
Add Windows Hello for Business credential
#Description
Records the registration of a Windows Hello for Business credential, a key-based passwordless authentication credential, for a user account. Registration of a new authentication credential can be a persistence technique when performed by an attacker on a compromised account.
References #
Admin started password reset
#Description
Records that an administrator initiated a password reset on behalf of a user through Microsoft Entra authentication methods / self-service password management. Unexpected admin-initiated resets are relevant to account-takeover and persistence monitoring.
References #
Apply review
#Description
Records that the results of a completed access review were applied, enacting all reviewer decisions for the review so that identities denied access have their group membership or application assignment removed.
References #
Approve all requests in business flow
#Description
Records a bulk action that approves all pending decisions within a Microsoft Entra access review (referred to as a business flow), continuing access for every reviewed user in a single operation. Access-review approvals certify continued access, so bulk approvals can mask individual decisions and are worth scrutiny.
References #
Auto apply review
#Description
Records the automatic application of a completed access review's results to the target resource (for example, removing access for users who were denied) when the review has 'Auto apply results to resource' enabled, rather than an administrator manually applying the results.
References #
Auto review
#Description
Records a system-generated decision on a user's access within an access review, applied automatically by the access reviews engine rather than by a human reviewer (for example, applying recommendations or the configured default decision when reviewers don't respond by the review end date).
References #
Blocked from self-service password reset
#Description
Records that a user was throttled and temporarily blocked from self-service password reset after too many attempts. Microsoft throttles after five attempts within an hour to validate a phone number, to use the security-questions gate, or to reset the same account's password, after which the user must wait 24 hours; repeated blocks can indicate password-reset abuse or an account-takeover attempt.
References #
Bulk create users - finished (bulk)
#Description
Records completion of an administrator-initiated bulk user-creation operation from an uploaded CSV template in the Microsoft Entra admin center; the 'finished (bulk)' marker denotes the batch job completing. Mass account creation can indicate bulk provisioning of unauthorized or persistence accounts.
References #
Bulk delete users - finished (bulk)
#Description
Records that a bulk operation to delete multiple user accounts, submitted as a CSV in the Microsoft Entra admin center, finished. Mass account deletion can indicate destructive activity or defense evasion through removal of identities.
References #
Bulk invite users - finished (bulk)
#Description
Records that a bulk operation to send B2B collaboration (guest) invitations from an uploaded CSV finished. A surge of external guest invitations can indicate unsanctioned external collaboration or guest-account persistence.
References #
Bulk restore deleted users - finished (bulk)
#Description
Records that a bulk operation to restore soft-deleted user accounts from the recycle bin, using an uploaded CSV, finished. Restoring previously deleted accounts can re-establish access and serve as a persistence mechanism.
References #
Change password (self-service)
#Description
A user changed their own password through Microsoft Entra self-service password management. This is the self-service change-password flow, distinct from the separate self-service or administrator password-reset activities listed in the same service section.
References #
Change user license
#Description
The product licenses assigned to a user were changed in the directory (licenses added, removed, or modified). License changes can grant or revoke access to services and capabilities tied to a SKU.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-01T20:32:12.9796029Z",
"ActivityDisplayName": "Change user license",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "83479b0d-4e3f-469d-9ed9-794cd4d1370e",
"DurationMs": "0",
"Id": "Directory_83479b0d-4e3f-469d-9ed9-794cd4d1370e_S03BN_113612636",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Change user license",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"modifiedProperties": [
{
"displayName": "LicenseAssignmentDetail",
"oldValue": [
{
"ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
"Status": 0,
"AccountId": "11111111-1111-1111-1111-111111111111",
"SkuId": "b126b073-72db-4a9d-87a4-b17afe41d4ab",
"Error": 0,
"StatusUpdateTimestamp": "2026-06-30T14:23:04.6932105Z",
"DisabledPlans": [],
"EncodingVersion": 2
},
{
"ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
"Status": 0,
"AccountId": "11111111-1111-1111-1111-111111111111",
"SkuId": "c7df2760-2c81-4ef7-b578-5b5392b571df",
"Error": 0,
"StatusUpdateTimestamp": "2026-06-30T14:23:04.6932105Z",
"DisabledPlans": [],
"EncodingVersion": 2
}
],
"newValue": [
{
"ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
"Status": 0,
"AccountId": "11111111-1111-1111-1111-111111111111",
"SkuId": "c7df2760-2c81-4ef7-b578-5b5392b571df",
"Error": 0,
"StatusUpdateTimestamp": "2026-07-01T20:32:12.8837518Z",
"DisabledPlans": [],
"EncodingVersion": 2
},
{
"ReferenceObjectId": "aaaaaaaa-0000-0000-0000-000000000001",
"Status": 0,
"AccountId": "11111111-1111-1111-1111-111111111111",
"SkuId": "b126b073-72db-4a9d-87a4-b17afe41d4ab",
"Error": 0,
"StatusUpdateTimestamp": "2026-07-01T20:32:12.8837518Z",
"DisabledPlans": [],
"EncodingVersion": 2
}
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"LicenseAssignmentDetail\""
},
{
"displayName": "TargetId.UserType",
"oldValue": null,
"newValue": "\"Member\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic",
"userPrincipalName": "adminuser@example.onmicrosoft.com"
}
]
}
References #
Convert federated user to managed
#Description
Records the conversion of an individual user account from federated authentication to managed (cloud) authentication, as occurs when a domain is migrated from federation to cloud authentication. Changes to domain and user authentication configuration are worth monitoring because federation tampering is a known persistence and defense-evasion vector.
References #
Create application password for user
#Description
An app password was created for a user. App passwords let legacy, non-browser clients that cannot complete multifactor authentication sign in with an automatically generated secret, so their creation is a potential MFA-bypass or persistence vector worth monitoring.
References #
Create business flow
#Description
A business flow was created in Microsoft Entra access reviews. Current access-reviews documentation does not define a standalone 'business flow' object, so this most likely represents an internal configuration element of an access review (defining what is reviewed and by whom); the precise meaning is unconfirmed.
References #
Create governance policy template
#Description
A governance policy template was created in Microsoft Entra Tenant Governance, a reusable blueprint that defines a cross-tenant governance relationship by mapping selected built-in roles to a group in the governing tenant. Applied to governance relationships, it grants that group standing access in governed tenants, so it is relevant to cross-tenant privilege review.
References #
Delete application password for user
#Description
Records the deletion of an app-password credential belonging to a user. App passwords let legacy, non-browser clients that cannot satisfy a multifactor authentication prompt sign in, so deleting one revokes that MFA-bypass credential and causes any legacy app still using it to fail authentication; the event can reflect benign cleanup or credential tampering.
References #
Delete business flow
#Description
Records the deletion of a business flow object within Microsoft Entra access reviews. In the access-reviews feature a business flow is a construct used to scope a review (for example, to the type of resource being reviewed); its exact schema is not detailed in the public audit reference, so it is interpreted conservatively as removal of an access-review configuration object.
References #
Delete external user
#Description
An external (B2B guest) user was deleted from the directory. The Invited users service handles B2B collaboration guest accounts, and removing a guest revokes that external identity's access to the tenant.
References #
Delete governance policy template
#Description
A governance policy template associated with Microsoft Entra access reviews was deleted. Access reviews use policy definitions to schedule and govern recurring reviews of access, but the precise template object is not fully established from the operation name and service alone.
References #
Delete Passkey (device-bound)
#Description
Records deletion of a device-bound passkey (FIDO2) authentication method registered to a user, removing a phishing-resistant credential. Removing a user's strong authentication method can precede account takeover or be used to clean up after attacker-registered credentials, so it warrants review.
References #
Delete passwordless phone sign-in credential
#Description
Records deletion of a passwordless phone sign-in credential from a user in Azure AD B2C, where a phone number plus SMS one-time passcode can serve as the primary sign-in method. The cited doc grounds the B2C phone sign-in feature but not the specific credential-deletion audit event.
References #
Delete platform credential
#Description
Records the removal of a Platform Credential for macOS, a secure-enclave-backed, hardware-bound cryptographic key provisioned through the Microsoft Enterprise single sign-on extension and used for single sign-on and authentication from a registered Mac. Deletion removes a device-bound credential tied to the user and device.
References #
Delete Windows Hello for Business credential
#Description
Records removal of a Windows Hello for Business credential from a user account under the B2C service (UserManagement category). Deletion of this key-based credential is relevant to credential-management monitoring, since it changes a user's available strong-authentication methods.
References #
Deny all decisions
#Description
Records denying all pending decisions in a Microsoft Entra access review at once, recommending that the affected users lose the access under review. The reference also lists a separate Policy-category 'Bulk Deny decisions' activity, which is distinct from this UserManagement 'Deny all decisions'.
References #
Deny all requests in business flow
#Description
Records the bulk denial of all pending requests grouped under a single access-review business flow, so the affected users do not retain the access under review. 'Business flow' is the grouping term used by the older access-review/governance-policy model.
References #
Email not sent, user unsubscribed
#Description
An invitation or notification email to an invited (B2B guest) user was not sent because the recipient had previously unsubscribed from these emails. This is an email-delivery status event rather than a security-relevant configuration change.
References #
Enable Strong Authentication
#Description
Records that strong authentication, the legacy directory term for multifactor authentication (the strongAuthentication* user properties/claims), was enabled for a user account. Changes to a user's strong-authentication state affect MFA enforcement and are relevant to account-takeover and MFA-bypass monitoring.
References #
Fraud reported - no action taken
#Description
A user reported a multifactor authentication prompt as fraudulent under the legacy MFA Fraud Alert feature, and because automatic blocking was not enabled, the account was not blocked. A fraud report can signal MFA prompt bombing or an adversary holding valid credentials and attempting to satisfy an MFA challenge.
References #
Fraud reported - user is blocked for MFA
#Description
A user reported a multifactor authentication prompt as fraudulent under the legacy MFA Fraud Alert feature with automatic blocking enabled, so the account was blocked from further MFA until an administrator unblocks it. A fraud report can indicate MFA prompt bombing or an attacker attempting to authenticate with stolen credentials.
References #
Get passkey creation options
#Description
Records retrieval of WebAuthn passkey (FIDO2) creation options, the challenge and parameters issued to a user's authenticator at the start of passkey registration in Microsoft Entra ID. It precedes enrollment of a new passkey authentication method, which is relevant to monitoring for unauthorized strong-auth method registration (persistence).
References #
Hard Delete user
#Description
Records the permanent, non-recoverable removal of a user object from the tenant, either an administrator permanently deleting a soft-deleted user or the automatic purge after the 30-day soft-delete window. A hard-deleted user cannot be restored by administrators or Microsoft, so the event can indicate destruction of an account and its associated evidence (defense evasion).
References #
Invitation Email
#Description
Records that a Microsoft Entra B2B collaboration invitation email was sent to an invited external (guest) user, the message that carries the redemption/redirect link the recipient uses to accept the invitation and gain external access.
References #
Invite internal user to B2B collaboration
#Description
Records that an existing internal user was invited into Microsoft Entra B2B collaboration. The invitation requires the user's Mail property be set to the external email they will use; when the user redeems it, the existing internal user object is converted to a B2B user and must thereafter sign in with external credentials.
References #
Redeem extern user invite
#Description
An external B2B collaboration user redeemed an invitation to the tenant, completing guest-account onboarding. New guest redemptions are relevant to monitoring external access and initial onboarding of outside identities.
References #
Remove app role assignment from user
#Description
An app role assignment was removed from a user, revoking that user's assignment to an application and any app role it conferred. Changes to user application access are relevant to access-governance monitoring.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:19.2082777Z",
"ActivityDisplayName": "Remove app role assignment from user",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "UserManagement",
"CorrelationId": "5ceb6d0e-4890-44ed-9f7b-5fff2bed91fd",
"DurationMs": "0",
"Id": "Directory_5ceb6d0e-4890-44ed-9f7b-5fff2bed91fd_K3LZP_11973335",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove app role assignment from user",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AppRole.Id",
"oldValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\"",
"newValue": null
},
{
"displayName": "AppRole.Value",
"oldValue": null,
"newValue": null
},
{
"displayName": "AppRole.DisplayName",
"oldValue": null,
"newValue": null
},
{
"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": "\"2026-07-24T03:21:18.1619889Z\"",
"newValue": null
},
{
"displayName": "AppRoleAssignment.LastModifiedDateTime",
"oldValue": "\"2026-07-24T03:21:18.1619889Z\"",
"newValue": null
},
{
"displayName": "User.ObjectID",
"oldValue": "\"aaaaaaaa-0000-0000-0000-000000000001\"",
"newValue": null
},
{
"displayName": "User.UPN",
"oldValue": "\"adminuser@example.onmicrosoft.com\"",
"newValue": null
},
{
"displayName": "User.PUID",
"oldValue": "\"1111111111111111\"",
"newValue": null
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Remove OrganizationalUnit assigned to a user
#Description
Records removal of the organizational-unit association assigned to a user object in the Core Directory (UserManagement category). This is an uncommon directory-management activity referring to the directory's organizational-unit construct, which is distinct from administrative units.
References #
Remove user sponsor
#Description
A sponsor was removed from a user's Sponsors attribute. Sponsors are the users or groups designated to manage and vouch for a (typically guest) user's lifecycle and can serve as approvers in entitlement management, so removal severs that accountability link.
References #
Request approved
#Description
An approval decision was recorded in the context of Microsoft Entra access reviews, marking a reviewed access request as approved so the user's access is granted or retained. Reviewer approve and deny decisions are written to the Entra audit logs as the review's audit trail.
References #
Request denied
#Description
Records a deny decision in a Microsoft Entra access review, where a reviewer denied a user's continued access to the reviewed group or application. When the review results are applied, Microsoft Entra removes the denied user's membership or application assignment, so these entries are relevant to access-governance and least-privilege monitoring.
References #
Reset password
#Description
Records a password reset performed on a user account in the directory. Because a password reset can enable account takeover or persistence, these entries are worth correlating against the target account and the actor that performed the reset.
References #
Reset password (by admin)
#Description
Records that an administrator reset another user's password on that user's behalf. Admin-initiated resets of accounts the admin does not own are relevant to account-takeover and persistence detection.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098↳ also matches Enable account, Update user
References #
Reset password (self-service)
#Description
Records that a user successfully reset their own password through Microsoft Entra self-service password reset (SSPR).
References #
Restore multifactor authentication on all remembered devices
#Description
Records the per-user MFA administrative action that restores multifactor authentication on all of a user's remembered (trusted) devices, revoking the remembered-device bypass so the user must complete MFA again at the next sign-in on those devices. It is a remediation action used when an account or a trusted device may be compromised.
References #
Security info saved for self-service password reset
#Description
Records that a user saved or updated the security (authentication) information, such as a mobile phone, alternate email, or security questions, used to reset their password through self-service password reset. Changes to account-recovery contact information are a known account-takeover persistence vector and warrant review when unexpected.
References #
Self-service password reset flow activity progress
#Description
Records each specific step a user proceeds through, such as passing a particular password reset authentication gate, as part of the self-service password reset process. A success entry indicates the step completed, while a failure entry carries a status reason explaining why that step of the reset flow failed.
References #
Set user manager
#Description
The manager attribute of a user was set or updated, linking the user to a manager in the directory. The manager value can drive dynamic group membership and approval/lifecycle workflows.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:22.0427163Z",
"ActivityDisplayName": "Set user manager",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "78d9f525-1015-4dbb-a287-2d4667a8a99c",
"DurationMs": "0",
"Id": "Directory_78d9f525-1015-4dbb-a287-2d4667a8a99c_JANDY_146277731",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Set user manager",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
"displayName": null,
"type": "User",
"userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "New Manager",
"oldValue": null,
"newValue": "\"None\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Takeover user cloned
#Description
Records that a user from an unmanaged ('shadow') Microsoft Entra directory was cloned into a managed tenant during an admin takeover of that directory's domain. Admin takeover lets an organization assume control of a self-service-created unmanaged directory and bring its users into the managed tenant.
References #
Unlock user account (self-service)
#Description
Records that a user unlocked their own account through Microsoft Entra self-service password reset (SSPR), with no administrator or help-desk involvement. Repeated self-service unlocks against an account can accompany password-spray or brute-force activity.
References #
Update business flow
#Description
Records a modification to a business flow object within Microsoft Entra access reviews. Access-review configuration changes are written to the audit log under UserManagement, so this entry is relevant when monitoring tampering with access-certification governance, though the specific 'business flow' construct is not defined in current product documentation.
References #
Update governance policy template
#Description
A Microsoft Entra Tenant Governance governance policy template was updated. A governance policy template is a reusable blueprint for cross-tenant governance relationships that defines cross-tenant delegated administration roles (Entra built-in roles granted to a governing tenant, provisioned as GDAP) and managed multitenant applications, so changes are privilege-relevant because they set what cross-tenant administrative access a relationship can grant.
References #
Update MyStaff feature value
#Description
A My Staff configuration value was changed. My Staff delegates scoped user-management tasks (such as password resets and phone-number management within an administrative unit) to local managers, so changes to its settings affect who can perform delegated account actions.
References #
Update OrganizationalUnit assigned to a user
#Description
The organizational unit assigned to a user account in the Microsoft Entra Core Directory was changed. The exact directory feature behind this assignment was not confirmed against a Learn doc.
References #
Update per-user multifactor authentication state
#Description
A user's legacy per-user multifactor authentication state (Disabled, Enabled, or Enforced) was changed. Moving a user to Disabled removes them from per-user MFA enrollment and can weaken authentication assurance (defense evasion).
References #
Updated ConvergedUXV2 feature value
#Description
Records a change to the tenant-level 'ConvergedUXV2' Microsoft Entra directory feature flag value. The audit record captures that this internal feature toggle was set to a new value; the operation name alone does not document the exact behavior the flag controls.
References #
Updated MyApps feature value
#Description
Records a change to the tenant-level 'MyApps' Microsoft Entra directory feature flag value, an internal feature toggle whose name references the My Apps end-user portal. The audit record captures the value change; the operation name alone does not document the exact behavior toggled.
References #
Updated SignInReports feature value
#Description
Records a change to the tenant-level 'SignInReports' Microsoft Entra directory feature flag value, an internal feature toggle whose name references sign-in reporting. The audit record captures the value change; the exact behavior toggled is not documented by the operation name alone.
References #
Updated SSPRConvergence feature value
#Description
Records a change to the tenant-level 'SSPRConvergence' Microsoft Entra directory feature flag value, an internal feature toggle whose name references self-service password reset (SSPR) registration convergence (the combined security-info registration of SSPR and MFA methods). The audit record captures the value change; the exact behavior is not documented by the operation name alone.
References #
User canceled security info registration
#Description
Records that a user exited the combined security information registration experience (MFA and SSPR methods) without completing it, leaving the required authentication methods unregistered. These combined-registration events are logged under the Authentication Methods service.
References #
User Password Registration
#Description
Records that a user registered for self-service password reset through Microsoft Identity Manager (MIM), supplying the authentication methods (such as a mobile phone number or security questions) later used to reset their password. MIM exports this activity to Microsoft Entra, where it surfaces in the audit logs under the MIM Service category.
References #
User Password Reset
#Description
Records that a user reset their own password using Microsoft Identity Manager (MIM) self-service password reset, including the gates or methods used to authenticate. MIM exports this activity to Microsoft Entra, where it surfaces in the audit logs under the MIM Service category.
References #
User registered all required security info
#Description
Records that a user completed combined registration by registering all the security information required by the tenant's multifactor authentication and SSPR policies, making the account compliant for both MFA and self-service password reset. These events are logged under the Authentication Methods service.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User started security info registration
References #
User started password change
#Description
Records that a user initiated a self-service password change, supplying their current password to set a new one (a voluntary change, or one forced because the password expired). Marks the start of the change flow rather than its completion.
References #
user started password reset
#Description
Records that a user initiated a self-service password reset for a forgotten password through the Microsoft Entra password reset portal. A surge of these events can accompany account-takeover attempts.
References #
User started security info registration
#Description
Records that a user began registering security info, the authentication methods used for multifactor authentication and self-service password reset, through combined security info registration. Newly added authentication methods are a common account-takeover persistence vector, so unexpected registrations warrant review.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.004, T1556, T1556.006↳ also matches Admin deleted security info, Admin registered security info, Admin updated security info, User changed default security info, User deleted security info, User registered security info, User registered all required security info
References #
User updated security info
#Description
Records that a user modified their registered security info, that is the authentication methods used for multifactor authentication and self-service password reset. Unexpected changes to a user's MFA methods are a frequent post-compromise persistence technique and are worth alerting on.
References #
Update PasswordProfile
#Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:19.7349749Z",
"ActivityDisplayName": "Update PasswordProfile",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "UserManagement",
"CorrelationId": "4abcd032-2a4f-4c54-9f6f-ff886773f36b",
"DurationMs": "0",
"Id": "Directory_4abcd032-2a4f-4c54-9f6f-ff886773f36b_O4VOL_159399257",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update PasswordProfile",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "c1149e7a-dad2-4757-9f06-580700c96bd3",
"displayName": null,
"type": "User",
"userPrincipalName": "dwharn-manager-cf516524@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "ForceChangePassword",
"oldValue": "\"False\"",
"newValue": "\"True\""
},
{
"displayName": "Password",
"oldValue": null,
"newValue": null
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Create Temporary Access Pass method for user
#Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004, T1550↳ also matches Admin registered security info, User registered security info
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.