Summary
Keywords
Full Transcript
Azure Entra ID Audit & Sign-in Logs — deep dive hands-on lab to find, analyze and export SigninLogs and AuditLogs using the Azure portal, Log Analytics (KQL), Microsoft Graph and PowerShell. Learn real queries, detection patterns, export pipelines and alerting. n this lab I walk you through everything you need to find, understand and act on Entra ID sign-in and audit logs: portal walkthrough, Log Analytics (KQL) queries you can reuse, Microsoft Graph and PowerShell examples, export/ingest pipelines (Storage / Event Hub / Log Analytics), conditional access & troubleshooting scenarios, and production best practices. What you'll learn Difference between Sign-in logs and Audit logs How to locate logs in the Azure portal and connect to Log Analytics Practical KQL queries for failed sign-ins, conditional access failures, risky sign-ins and top apps Exporting logs (Storage / Event Hubs / Log Analytics) and retention considerations Querying with Microsoft Graph and PowerShell Real troubleshooting patterns and how to create alerts & workbooks Prerequisites Azure subscription with Entra ID access Reader/Monitoring role on Log Analytics or Global Reader + AuditLog.Read.All (for Graph) Optional: Microsoft.Graph PowerShell module installed #CloudKnowledge #Azure #AWS #CloudSecurity #IAM #CloudComputing #DevOps #AzureAD #CloudTutorials
