The Audit Dashboard displays a visual summary of the most important metrics of the Microsoft 365 and Microsoft Entra activity in your organization. The information is updated in real time, allowing you to quickly gain valuable insights into the activity taking place in your organization. You can also refresh the data by selecting the refresh icon in the top right of the dashboard.
The dashboard displays:
The indicators at the top of the dashboard allow you to quickly see if there has been a change in risky activity over a specific period of time. A red sidebar indicates an increase in activity; while a green sidebar indicates a reduction.
You can then easily delve further into the details, by clicking the indicator to view an associated search.
|
|
NOTE: The indicators are updated each time that you open the dashboard or refresh the view. |
The following indicators are available:
Cloud-only Microsoft Entra users created in the last 7 days
AD account lockouts in the last 24 hours
If you do not have a configured Change Auditor integration, the Microsoft Entra critical directory role changes in the last 7 days indicator displays instead.
Microsoft Entra risk events in the last 7 days
This indicator displays when you have an Microsoft Entra ID Premium (P2) license.
If you do not have the required license to audit risky events and Change Auditor integration is configured, the On-premises and Microsoft Entra failed sign-ins in the last 24 hours indicator displays instead.
If you do not have the required license to audit risky events and have not configured a Change Auditor integration, the Microsoft Entra failed sign-ins in the last 24 hours indicator displays.
The Audit Health tile allows you to easily see the status of your auditing configuration, identify any issues, and make the required updates to ensure you are keeping informed of the vital and critical changes to your organization.
From here, you can grant required consent for the tenant, view subscription information, view the auditing configuration settings, view results in a search, and subscribe to the built-in notification templates.
|
|
NOTE: Specific permissions are required for the following actions:
|
|
|
NOTE:
|
Possible issues that may be identified include:
No Microsoft 365 events have been received from the tenant in the last 24 hours
Configure SpecterOps BloodHound Enterprise integration
SpecterOps BloodHound Enterprise configuration was removed
SpecterOps BloodHound Enterprise connection failed
Subscribe to Tier Zero notification template
To subscribe to a notification template from the Audit Health tile in the dashboard: