How to audit admin activities in Microsoft Entra ID?
Microsoft Entra ID audit logs track what admin actions happen in Azure Active Directory. This includes managing users and groups, updating policies, assigning applications, and changing directory settings and more. These logs help you ensure compliance, enhance security, and troubleshoot issues within the Microsoft 365 environment.
Follow the below steps to monitor admin activities in Microsoft Entra admin center
- Login to the Microsoft Entra admin center.
- Navigate to the Audit logs page residing under Monitoring & health section and use the filters below:
- Date range - This filter lets you define a particular timeframe to examine log entries, helping you focus on relevant activities within a defined period. Select the desired date range to filter the audit logs according to when the activities took place.
- Category - Filter based on the type of event, such as authentication, authorization, or provisioning. Choose All to include all admin activities in the audit log.
- Service - The service filter in Microsoft Entra audit logs enables you to narrow down results based on specific Azure AD services like Core Directory, Azure MFA, B2B Auth, B2C, Application, and Agreement. Select All services to include logs from all services or components.
- Activity - Describes the specific action or event recorded within the service, such as file deletion, user creation, password reset, or permission changes. Choose All activities to include logs of all types of activities performed.
- Click the date field in the audit log entry to see more details like Modified Properties.
- To export the log as a CSV file, click the download button.