Chat now with support
Chat with Support

Change Auditor 7.1.1 - Office 365 and Azure Active Directory User Guide

Azure Active Directory Auditing Wizard

To audit Azure Active Directory you must create an auditing template and select an agent.

The following table provides details on how to create a template and the required web application so you can beginto audit the Azure Active Directory activity and how to edit the audited activities in an existing template.

Credentials, audit activity, and agent selection page

During template creation, use this page to provide the credentials for the accounts that register Change Auditor in the tenant, the activities to audit, and specify the agent.

 

Audit Logs: Audits Azure Active Directory user, group, application, and directory activity.
Sign-ins: Audits Azure Active Directory user sign-in and sign-in risk event activity.
3
Click Select agent to view available agents and whether they are assigned to an Azure Active Directory auditing template.
4
Click Finish to create the template. After the template is created, Change Auditor starts collecting events that are available on your tenant.

 

Audit Logs audits Azure Active Directory user, group, application, and directory activity.
Sign-ins: Audits Azure Active Directory user sign-in and sign-in risk event activity.
3
Click Finish to apply the updates.

Reports and Searches

Introduction to Office 365 and Azure Active Directory reporting

Change Auditor delivers both preconfigured and customizable reports displaying events in one centralized viewer. You can create custom search definitions to locate changes made in Office 365 and Azure Active Directory. Using the available search properties across the bottom of the Searches page, you can define the search criteria and include specific columns to access more tenant details.

When Change Auditor is deployed in a synchronized environment, you can add extra columns to display extra mapping information about synchronized Active Directory users and their cloud identities for Office 365 and Azure Active Directory events. For details, see Auditing in synchronized environments.

Office 365 built-in reports

To see a complete list of built-in reports, see the Change Auditor Built-in Reports Reference Guide.

2
In the explorer view (left pane), expand the Shared | Built-in | Office 365 folder.
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating