Microsoft Entra ID (Azure AD) Full Course 2026 Entra ID Sign-in & Audit Logs Explained — Hands-On Lab
Entra ID Sign-in & Audit Logs Explained — Hands-On Lab Transcript and Lesson Notes
Azure Entra ID Audit & Sign-in Logs — deep dive hands-on lab to find, analyze and export SigninLogs and AuditLogs using the Azure portal, Log Analytics (KQL), Microsoft Graph and PowerShell. Learn real queries, detection
Quick Summary
Azure Entra ID Audit & Sign-in Logs — deep dive hands-on lab to find, analyze and export SigninLogs and AuditLogs using the Azure portal, Log Analytics (KQL), Microsoft Graph and PowerShell. Learn real queries, detection
Key Takeaways
- Review the core idea: Azure Entra ID Audit & Sign-in Logs — deep dive hands-on lab to find, analyze and export SigninLogs and AuditLogs using the Azure portal, Log Analytics (KQL), Microsoft Graph and PowerShell. Learn real queries, detection
- Understand how audit logs fits into Entra ID Sign-in & Audit Logs Explained — Hands-On Lab.
- Understand how sign in fits into Entra ID Sign-in & Audit Logs Explained — Hands-On Lab.
- Understand how logs fits into Entra ID Sign-in & Audit Logs Explained — Hands-On Lab.
- Understand how conditional access policy block legacy authentication fits into Entra ID Sign-in & Audit Logs Explained — Hands-On Lab.
Key Concepts
Full Transcript
Azure Entra ID Audit & Sign-in Logs — deep dive hands-on lab to find, analyze and export SigninLogs and AuditLogs using the Azure portal, Log Analytics (KQL), Microsoft Graph and PowerShell. Learn real queries, detection patterns, export pipelines and alerting. n this lab I walk you through everything you need to find, understand and act on Entra ID sign-in and audit logs: portal walkthrough, Log Analytics (KQL) queries you can reuse, Microsoft Graph and PowerShell examples, export/ingest pipelines (Storage / Event Hub / Log Analytics), conditional access & troubleshooting scenarios, and production best practices. What you'll learn Difference between Sign-in logs and Audit logs How to locate logs in the Azure portal and connect to Log Analytics Practical KQL queries for failed sign-ins, conditional access failures, risky sign-ins and top apps Exporting logs (Storage / Event Hubs / Log Analytics) and retention considerations Querying with Microsoft Graph and PowerShell Real troubleshooting patterns and how to create alerts & workbooks Prerequisites Azure subscription with Entra ID access Reader/Monitoring role on Log Analytics or Global Reader + AuditLog.Read.All (for Graph) Optional: Microsoft.Graph PowerShell module installed #CloudKnowledge #Azure #AWS #CloudSecurity #IAM #CloudComputing #DevOps #AzureAD #CloudTutorials
Lesson FAQs
What is Entra ID Sign-in & Audit Logs Explained — Hands-On Lab about?
Azure Entra ID Audit & Sign-in Logs — deep dive hands-on lab to find, analyze and export SigninLogs and AuditLogs using the Azure portal, Log Analytics (KQL), Microsoft Graph and PowerShell. Learn real queries, detection
What key concepts are covered in this lesson?
The lesson covers audit logs, sign in, logs, conditional access policy block legacy authentication, conditional access.
What should I learn before Entra ID Sign-in & Audit Logs Explained — Hands-On Lab?
Review the previous lessons in Microsoft Entra ID (Azure AD) Full Course 2026, then use the transcript and key concepts on this page to fill any gaps.
How can I practice after this lesson?
Practice by applying the main concepts: audit logs, sign in, logs, conditional access policy block legacy authentication.
Does this lesson include a transcript?
Yes. The full transcript is visible on this page in indexable HTML sections.
Is this lesson free?
Yes. CourseHive lessons and courses are available to learn online for free.
