Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →The current Azure Monitor table is EnrichedMicrosoft365AuditLogs, not EnrichedOffice365AuditLogs. It is also distinct from MicrosoftGraphActivityLogs, which records Microsoft Graph API requests, and AADGraphActivityLogs, which covers the legacy Azure AD Graph API. Choose the source based on whether you need a directory change, an API request, or an audit operation across Microsoft 365 workloads.
Choose the log source that answers your question
“Azure AD” is the former product name; Microsoft Entra ID is the current name. Older scripts and documentation may still use Azure AD terminology. “Activity logs” is also an umbrella phrase, so identify the actual source and destination before writing a query.
| Source | What it records | Best question to answer |
|---|---|---|
| Microsoft Entra audit logs | Administrative and directory activity, such as changes to users, groups, applications, roles, and policies. | Who changed this tenant object or setting? |
MicrosoftGraphActivityLogs |
Requests processed by Microsoft Graph, including request metadata and response details. | Which identity or application called which Graph endpoint, and what response did it receive? |
EnrichedMicrosoft365AuditLogs |
Enriched Microsoft 365 audit activity, with workload, operation, actor, result, and object context. | What operation occurred in a Microsoft 365 workload, and who or what performed it? |
AADGraphActivityLogs |
Requests to the older Azure Active Directory Graph API. | Which applications may still be using the legacy API? |
| Azure subscription Activity Log | Azure resource and subscription events; exported records appear in AzureActivity. |
What happened to an Azure resource or subscription? |
These sources complement rather than replace one another. A Graph request is not automatically the same record as the resulting directory audit event, and there is no guaranteed one-to-one join between them. Microsoft documents schema differences between Azure Monitor logs and Microsoft Graph data: Entra activity-log schemas. Azure subscription events are a separate stream: Azure Activity Log.
What MicrosoftGraphActivityLogs contains
Use this table when the investigation depends on the API call itself: application or service principal, endpoint, HTTP method, status code, request duration, or response size. Microsoft describes the stream as requests made to Microsoft Graph by application clients, SDK-based applications, Microsoft applications, admin portals, and other clients connected to Graph: Microsoft Graph activity logs overview.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
- ABIS BOOK
The current Azure Monitor table reference lists fields including TimeGenerated, AadTenantId, AppId, ServicePrincipalId, UserId, RequestMethod, RequestUri, RequestId, ClientRequestId, OperationId, ResponseStatusCode, ResponseSizeBytes, DurationMs, IPAddress, ClientAuthMethod, IdentityProvider, Scopes, Roles, DeviceId, SessionId, and UniqueTokenId. Microsoft currently lists support for Basic and Auxiliary/Lake table plans and ingestion-time DCRs; check the live table reference for current capabilities: MicrosoftGraphActivityLogs table reference.
Interpret request and identity fields carefully
RequestIdidentifies an individual request.OperationIdcan identify a batch, so multiple requests may share it.ClientRequestIdis optional; when a client does not provide one, it can equal the operation identifier. Do not treat these identifiers as interchangeable universal join keys.ResponseStatusCodeis an HTTP status. Investigate authorization failures, throttling, malformed requests, and server errors separately instead of collapsing all non-success responses into one cause.AppIdandServicePrincipalIdhelp identify application context; the presence of an application identity does not, by itself, establish whether its behavior is expected.RequestUrican reveal endpoint use but may include identifiers or query parameters. Normalize it for aggregation where appropriate, and restrict access to logs that expose operational or identity details.
Microsoft warns against placing passwords, credentials, access tokens, refresh tokens, connection strings, or other secrets in directory attributes that can be exposed through Microsoft Graph.
What EnrichedMicrosoft365AuditLogs contains
The current documented table name is EnrichedMicrosoft365AuditLogs. Treat EnrichedOffice365AuditLogs as a possible historical, connector-specific, or mistaken name unless your own workspace schema confirms otherwise. This table is for enriched Microsoft 365 audit activity, not a complete record of every Graph API request.
Rank #2
Its documented columns include TimeGenerated, ActorUserType, AdditionalProperties, ClientIp, DeviceId, DeviceOperatingSystem, DeviceOperatingSystemVersion, Id, ObjectId, Operation, OrganizationId, RecordType, ResultStatus, SourceIp, UniqueTokenId, UserId, UserKey, UserType, and Workload. These fields help group events by operation, service, actor, result, and affected object. See the EnrichedMicrosoft365AuditLogs table reference for the current schema.
Do not assume the IP field identifies the end user
Microsoft documents that ClientIp can be null for Azure Active Directory-related events in this table. For other workloads, an IP may represent a trusted service or intermediary rather than the end-user device. A missing or intermediary IP does not prove there was no network source or that the activity was internal.
Microsoft Graph and Azure AD Graph are different APIs
MicrosoftGraphActivityLogs concerns requests to Microsoft Graph, the current API surface. AADGraphActivityLogs concerns requests to the older Azure AD Graph API. Do not use the legacy table as a synonym for current Microsoft Graph logging. It can help identify applications that still call the old endpoint and inform migration work; check its actual workspace schema because it is a legacy source. Reference: AADGraphActivityLogs table reference.
Rank #3
Enable collection and select a destination
Microsoft lists a Microsoft Entra ID P1 or P2 tenant license, a supported administrator role (Security Administrator is the least-privileged listed role for setting up diagnostic settings), an Azure subscription, and a destination resource as prerequisites for Microsoft Graph activity logs. General Entra log integration also requires access to the relevant subscription, resource group, and workspace. License requirements for Graph activity logging should not be generalized to every Entra audit-log scenario; the availability of particular audit features and properties can also depend on the licensed feature.
- Sign in to the Microsoft Entra admin center and open Entra ID.
- Select Monitoring & health, then Diagnostic settings.
- Select + Add diagnostic setting and enter a name.
- Select the log categories you need.
- Under Destination details, select Send to Log Analytics workspace, then choose the Azure subscription and workspace.
- Select Save, allow records to arrive, and verify the expected table in the workspace.
Portal entry points and labels can vary slightly depending on the blade used; Audit Logs and Sign-ins pages can also offer an export-settings route. Microsoft’s setup and access guides are Integrate activity logs with Azure Monitor Logs and Access activity logs.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallMicrosoft Graph activity logs can be routed to Log Analytics for KQL, Azure Storage for archival, or Event Hubs for streaming to an external system. Diagnostic settings do not filter Microsoft Graph activity logs, so plan any filtering downstream, such as in supported workspace transformations or the receiving pipeline. If you need security detections and threat hunting across sources, Microsoft points to Sentinel as an option: Microsoft Sentinel overview.
Query the tables with KQL
Run queries in the Log Analytics workspace that receives the diagnostic setting. Verify the table names and sample rows in your own workspace before relying on a field, value spelling, or schema that may differ by source or change over time.
Check which streams have arrived
union isfuzzy=true
MicrosoftGraphActivityLogs,
EnrichedMicrosoft365AuditLogs,
AADGraphActivityLogs
| summarize
Records=count(),
FirstSeen=min(TimeGenerated),
LastSeen=max(TimeGenerated)
by Type
| order by LastSeen desc
Rank Graph callers and find failed requests
MicrosoftGraphActivityLogs
| summarize
Requests=count(),
Failures=countif(ResponseStatusCode >= 400),
AverageDurationMs=avg(DurationMs)
by AppId, ServicePrincipalId
| order by Requests desc
MicrosoftGraphActivityLogs
| where ResponseStatusCode >= 400
| project
TimeGenerated,
AppId,
ServicePrincipalId,
UserId,
RequestMethod,
RequestUri,
ResponseStatusCode,
DurationMs,
RequestId,
ClientRequestId
| order by TimeGenerated desc
Find throttling and endpoint use
MicrosoftGraphActivityLogs
| where ResponseStatusCode == 429
| summarize
ThrottledRequests=count(),
AverageDurationMs=avg(DurationMs)
by AppId, RequestUri
| order by ThrottledRequests desc
MicrosoftGraphActivityLogs
| extend Uri=tostring(RequestUri)
| summarize Requests=count() by RequestMethod, Uri
| order by Requests desc
Endpoint counts can fragment when URIs contain different IDs, query strings, casing, or batch details. Normalize URI values to match the question you are investigating, and avoid exposing sensitive URI content in broadly shared reports.
Summarize Microsoft 365 operations and investigate one user
EnrichedMicrosoft365AuditLogs
| summarize
Records=count(),
Failures=countif(ResultStatus == "Failed")
by Workload, Operation
| order by Records desc
EnrichedMicrosoft365AuditLogs
| where UserId =~ "[email protected]"
| project
TimeGenerated,
UserId,
ActorUserType,
Workload,
Operation,
ResultStatus,
ObjectId,
SourceIp,
ClientIp,
AdditionalProperties
| order by TimeGenerated desc
Find legacy Azure AD Graph callers
AADGraphActivityLogs
| summarize
Requests=count(),
Failures=countif(ResponseStatusCode >= 400)
by AppId, ApiVersion, RequestUri
| order by Requests desc
If a legacy-table query fails, inspect the table schema before changing field names; the table is a different and older source, not a current Graph table with a guaranteed matching schema.
Recommended Free Tools
Best Value
Plan cost, retention, and destination by use case
Graph activity volume can be substantial. Microsoft gives illustrative estimates of 14 GiB of storage and 15 GiB of Azure Monitor Logs per month for a 1,000-user tenant, and 1,000 GiB of storage and 1,200 GiB of Azure Monitor Logs per month for a 100,000-user tenant. These are estimates, not billing guarantees; actual volume varies with tenant activity, apps, workloads, API patterns, and time of day.
There is no universal dollar price. Azure Monitor costs depend on region, currency, purchasing agreement, log plan, ingestion, retention, query and export usage, and Sentinel configuration. Microsoft’s Azure Monitor pricing page presents estimates and directs customers to the Azure pricing calculator for an account-specific estimate.
| Destination or plan | Best fit | Trade-off to assess |
|---|---|---|
| Log Analytics, Analytics Logs | Frequent interactive KQL investigations, native alerting, and insights. | Broader query capabilities; ingestion and extended retention affect cost. |
| Basic Logs | Lower-cost storage for records that need less frequent investigation. | Interactive-query capabilities are more limited; query charges may apply. |
| Auxiliary Logs / Lake | Lower-cost ingestion or specialized data-lake use cases. | Query capabilities and applicable charges differ from Analytics. |
| Azure Storage | Long-term archive and data-lake processing. | Not as convenient as Log Analytics for routine interactive KQL; costs vary by capacity, tier, redundancy, transactions, retrieval, and transfer. |
| Event Hubs | Streaming to an external SIEM or custom pipeline. | Requires a downstream consumer and introduces capacity, throughput, and processing considerations. |
| Microsoft Sentinel | SOC analytics, threat hunting, detections, incidents, and response. | Usage and configuration affect cost; it is not simply a low-cost archival destination. |
The table reference says MicrosoftGraphActivityLogs supports Basic, Auxiliary/Lake, and ingestion-time DCR capabilities; verify current availability and plan constraints for your workspace. Workspace transformations may reduce ingested data where supported, but diagnostic settings themselves cannot filter Graph requests. Consider keeping frequently investigated security data in Analytics, archiving older or rarely queried records to Storage, and avoiding duplicate routing without a defined need.
Retention is determined by the destination, table plan, workspace configuration, and applicable compliance requirements—not by one universal period for all Entra or Microsoft 365 logs. Azure Monitor can charge for extended retention based on volume and duration; records marked _IsBillable == false are excluded from ingestion and retention charges according to Microsoft’s data retention guidance. Review the live pricing details for Basic and Auxiliary query charges and the Analytics pricing model before selecting a plan.
Use a collection pattern that matches the operating need
- Occasional investigation: Route only the categories needed to Log Analytics, choose a retention period aligned with the investigation requirement, and measure actual ingestion before expanding collection.
- Security operations: Use Log Analytics with Microsoft Sentinel when detections, cross-source hunting, and incident response are needed; keep the frequently queried telemetry in a suitable interactive plan.
- Compliance archive or external SIEM: Route to Storage for long-term retention, or Event Hubs for streaming to an external consumer. Keep recent investigative data in Log Analytics if analysts require interactive KQL.
Troubleshoot empty results and misleading fields
- No records: Confirm diagnostic settings were saved, the correct tenant and workspace were selected, and the selected category actually populates the expected table.
- Wrong table name: Query
EnrichedMicrosoft365AuditLogsrather than assumingEnrichedOffice365AuditLogsexists. Inspect tables and sample records in the workspace if a connector uses a different name. - Wrong time range: Check the query time picker and remember that
TimeGeneratedis the event time represented in the table. - Permissions or licensing: Verify the admin role, workspace access, Azure subscription access, and whether the feature is licensed and in use. Some audit properties can appear as
hiddenwithout the relevant license. - Data not yet available: Allow for ingestion delay and check again with a sufficiently broad time range.
- Unexpectedly sparse data: Check for workspace transformations that removed records or columns, and inspect the source category and actual table schema.
- Null IP: Do not infer that activity lacked a network origin; for Entra-related entries,
ClientIpcan be null by design. - Different schema than expected: Azure Monitor and Microsoft Graph schemas need not have identical names, structures, or event coverage. Validate representative rows before building joins or detections.
Microsoft notes that users can see no results in the Entra admin center or Microsoft Graph and points to diagnostic settings for integration with Azure Monitor. Confirm which interface and destination you are querying rather than assuming that a portal view automatically means records are present in a workspace.
Protect and interpret the data
These logs can expose user identifiers, application identities, request paths, scopes, roles, object identifiers, device details, and operational patterns. Limit workspace and export permissions to appropriate roles, and review what is sent to downstream systems. A successful response code is not proof that an application’s behavior was approved: assess its identity, permissions, endpoint, timing, and related events. Likewise, one request can fail, be retried, or be batched, while an audit record may show the resulting tenant operation without the full raw request context.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




