A customer configured Identity Defense and:
However:
The key configuration difference between the environments is that the Basic-Collector Enterprise Application permissions were granted in pre-production but not in production.
The Basic-Collector Enterprise Application is responsible for accessing and collecting Microsoft Entra ID audit and Sign-In event data.
If the required Microsoft Graph permissions are not granted and consented, Identity Defense may be unable to retrieve the full event set, resulting in:
This behavior can occur regardless of whether the customer is using the legacy ODA licensing model integrated into Identity Defense.
Grant the required permissions to the Basic-Collector Enterprise Application and ensure administrative consent has been completed.