Chat now with support
Chat with Support

Change Auditor 7.5 - Microsoft 365 and Microsoft Entra ID Auditing User Guide

Microsoft 365 and Microsoft Entra ID Auditing Overview Configuring Microsoft 365 and Microsoft Entra ID auditing Reports and Searches

Microsoft Entra auditing page

The Microsoft Entra auditing page contains a list of auditing templates that define the directory to audit.

The following information is displayed for each template:

Create a Microsoft Entra auditing template

The following section describes how to create a template and the required web application so you can begin to audit the Microsoft Entra ID activity. After the template is created, Change Auditor starts collecting events that are available on your tenant.

NOTE:  
2
Click Auditing.
3
Select Microsoft Entra (under Directories).
4
Click Add to open the auditing wizard.
5
Under Authentication Configuration, select to Create a new web application or Use existing web application.
g
Enter the Microsoft Entra Directory Name.
To apply the consent to all the users in your organization, click to enable Consent on behalf of your organization and click Accept.
b
Enter the Microsoft Entra Directory Name, Application ID, and Application key. See Microsoft documentation for details on integrating applications with Microsoft Entra ID and creating a web application.

Ensure the following permissions are assigned to the web application:

Microsoft Graph application permissions:

If the app will also be used for Microsoft 365 templates, ensure that the following permissions are also set:

Office 365 Management APIs application permissions:

Office 365 Exchange Online APIs application permissions:

For required configuration, see Using an existing web application.

Once the required permissions are applied, click Grant admin consent for… and confirm with Yes.

Audit Logs: Audits Microsoft Entra user, group, application, and directory activity. A Change Auditor for Active Directory license is required.
Sign-ins: Audits Microsoft Entra user sign-in and sign-in risk event activity. A Change Auditor for Logon Activity User license is required.
7
Click Select agent to view available agents and whether they are assigned to an auditing template. The Microsoft Entra cell contains ‘None’ if an agent is not assigned to a template, or ‘Auditing’ if it is assigned to a template. From this list, select the agent to capture the events and click OK.
NOTE:  
8
Click Finish to create the template.

Edit a Microsoft Entra auditing template

This section describes how to add or remove Microsoft Entra activity to audit.

To select a new agent, you must create a new template or use the Set-CAAzureADTemplate command through PowerShell. (See the Change Auditor PowerShell Command Guide for details.)

2
Click Auditing button.
3
Select Microsoft Entra (under Directories).
4
Select the template and click Edit to open the auditing wizard.
5
Under Authentication Configuration, select to Create a new web application or Use existing web application.
To apply the consent to all the users in your organization, click to enable Consent on behalf of your organization and click Accept.
If you select to use an existing web application, enter the Application ID and Application key. See Microsoft documentation for details on integrating applications with Microsoft Entra ID and creating a web application.

Ensure the following permissions are assigned to the web application:

Microsoft Graph application permissions:

If the app will also be used for Microsoft 365 templates, ensure that the following permissions are also set:

Office 365 Management APIs application permissions:

Office 365 Exchange Online APIs application permissions:

For required configuration, see Using an existing web application.

Once the required permissions are applied, click Grant admin consent for… and confirm with Yes.

Audit Logs audits Microsoft Entra user, group, application, and directory activity. A Change Auditor for Active Directory license is required.
Sign-ins: Audits Microsoft Entra user sign-in and sign-in risk event activity. A Change Auditor for Logon Activity User license is required.
7
Click Finish to apply the updates.

Disable a template

Disabling a template temporarily stops auditing activities without having to remove the template.

Place your cursor in the Status cell for the auditing template to disable, click the arrow control, and select Disabled.
The entry in the Status column for the template changes to ‘Disabled’.
2
To re-enable the auditing template, use the Enable option in either the Status cell or right-click menu.
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating