Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A security auditor needs to review all administrative actions performed by users with the Global Administrator role in Azure AD. This review must include who performed the action, what action was taken, and when it occurred. Which Azure AD feature should the auditor use to retrieve this information?
- AAzure AD Risky users report
- BAzure AD Sign-ins logs
- CAzure AD Audit logs
- DAzure AD Provisioning logs
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Audit logs
Azure AD Audit logs record all changes made within the Azure AD tenant, including administrative actions, application management, and directory updates. This is precisely what's needed for an administrative action review.
Why the other options are wrong
- A. Risky users report identifies users whose accounts may be compromised, not a log of administrative actions.
- B. Sign-in logs track user authentication attempts, not administrative actions.
- D. Provisioning logs track user and group provisioning activities between Azure AD and other applications.
Azure AD Audit Logs
Logs that capture all changes made within an Azure Active Directory tenant, including administrative actions, application management, and directory updates.
- Records who, what, when, and where for administrative actions.
- Essential for security auditing and compliance.
- Can be integrated with Azure Monitor for advanced analysis.
Memory trick: Audit logs are like the 'change history' of your directory.