Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A Microsoft 365 administrator is investigating a compromised user account. The investigation requires gathering detailed information about all logon attempts to the user's account, including source IP addresses, client applications, and authentication methods, over the past 30 days. Which KQL table should the administrator query in Advanced Hunting?

  1. ACloudAppEvents
  2. BIdentityLogonEvents
  3. CEmailEvents
  4. DDeviceLogonEvents
Show answer & explanation

Correct answer: B. IdentityLogonEvents

The `IdentityLogonEvents` table in Advanced Hunting specifically contains information about logon attempts to user identities, including details like `AccountObjectId`, `Application`, `IPAddress`, `AuthenticationMethod`, and `LogonType`. This table is populated by Microsoft Defender for Identity and Azure Active Directory data, making it the most appropriate source for comprehensive logon attempt analysis. `CloudAppEvents` is for cloud app activities, `EmailEvents` for email, and `DeviceLogonEvents` (if it existed as a distinct table for this purpose) would focus on device-level logons, not identity-centric ones across services.

Why the other options are wrong

  • A. This table focuses on activities performed within connected cloud applications, not solely on logon attempts to user identities across all services.
  • C. This table contains email-related events and would not provide the required logon attempt details.
  • D. While a table like this might exist in some contexts, the `IdentityLogonEvents` table is the correct and most comprehensive KQL table in Defender XDR for identity-centric logon attempts, regardless of whether they originate from a device or cloud service.

IdentityLogonEvents KQL Table

The `IdentityLogonEvents` KQL table in Microsoft Defender XDR Advanced Hunting provides detailed information about logon attempts to user identities, including source, client, and authentication method.

  • Populated by Microsoft Defender for Identity and Azure AD data.
  • Records successful and failed logon attempts.
  • Includes details like IP address, application, authentication method, logon type.
  • Crucial for identity compromise investigations.

Memory trick: Remember, for 'Identity' 'Logons', the 'IdentityLogonEvents' table is the 'Key' to 'Logon Investigations'.

More Implement and manage Microsoft Defender XDR questions