Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Azure Monitor

Microsoft Graph Activity Logs, Entra Audit Logs, and Microsoft 365 Audit Logs

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The current Azure Monitor table is EnrichedMicrosoft365AuditLogs, not EnrichedOffice365AuditLogs. It is also distinct from MicrosoftGraphActivityLogs, which records Microsoft Graph API requests, and AADGraphActivityLogs, which covers the legacy Azure AD Graph API. Choose the source based on whether you need a directory change, an API request, or an audit operation across Microsoft 365 workloads.

Choose the log source that answers your question

“Azure AD” is the former product name; Microsoft Entra ID is the current name. Older scripts and documentation may still use Azure AD terminology. “Activity logs” is also an umbrella phrase, so identify the actual source and destination before writing a query.

Source What it records Best question to answer
Microsoft Entra audit logs Administrative and directory activity, such as changes to users, groups, applications, roles, and policies. Who changed this tenant object or setting?
MicrosoftGraphActivityLogs Requests processed by Microsoft Graph, including request metadata and response details. Which identity or application called which Graph endpoint, and what response did it receive?
EnrichedMicrosoft365AuditLogs Enriched Microsoft 365 audit activity, with workload, operation, actor, result, and object context. What operation occurred in a Microsoft 365 workload, and who or what performed it?
AADGraphActivityLogs Requests to the older Azure Active Directory Graph API. Which applications may still be using the legacy API?
Azure subscription Activity Log Azure resource and subscription events; exported records appear in AzureActivity. What happened to an Azure resource or subscription?

These sources complement rather than replace one another. A Graph request is not automatically the same record as the resulting directory audit event, and there is no guaranteed one-to-one join between them. Microsoft documents schema differences between Azure Monitor logs and Microsoft Graph data: Entra activity-log schemas. Azure subscription events are a separate stream: Azure Activity Log.

What MicrosoftGraphActivityLogs contains

Use this table when the investigation depends on the API call itself: application or service principal, endpoint, HTTP method, status code, request duration, or response size. Microsoft describes the stream as requests made to Microsoft Graph by application clients, SDK-based applications, Microsoft applications, admin portals, and other clients connected to Graph: Microsoft Graph activity logs overview.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • ABIS BOOK

The current Azure Monitor table reference lists fields including TimeGenerated, AadTenantId, AppId, ServicePrincipalId, UserId, RequestMethod, RequestUri, RequestId, ClientRequestId, OperationId, ResponseStatusCode, ResponseSizeBytes, DurationMs, IPAddress, ClientAuthMethod, IdentityProvider, Scopes, Roles, DeviceId, SessionId, and UniqueTokenId. Microsoft currently lists support for Basic and Auxiliary/Lake table plans and ingestion-time DCRs; check the live table reference for current capabilities: MicrosoftGraphActivityLogs table reference.

Interpret request and identity fields carefully

  • RequestId identifies an individual request. OperationId can identify a batch, so multiple requests may share it.
  • ClientRequestId is optional; when a client does not provide one, it can equal the operation identifier. Do not treat these identifiers as interchangeable universal join keys.
  • ResponseStatusCode is an HTTP status. Investigate authorization failures, throttling, malformed requests, and server errors separately instead of collapsing all non-success responses into one cause.
  • AppId and ServicePrincipalId help identify application context; the presence of an application identity does not, by itself, establish whether its behavior is expected.
  • RequestUri can reveal endpoint use but may include identifiers or query parameters. Normalize it for aggregation where appropriate, and restrict access to logs that expose operational or identity details.

Microsoft warns against placing passwords, credentials, access tokens, refresh tokens, connection strings, or other secrets in directory attributes that can be exposed through Microsoft Graph.

What EnrichedMicrosoft365AuditLogs contains

The current documented table name is EnrichedMicrosoft365AuditLogs. Treat EnrichedOffice365AuditLogs as a possible historical, connector-specific, or mistaken name unless your own workspace schema confirms otherwise. This table is for enriched Microsoft 365 audit activity, not a complete record of every Graph API request.

Its documented columns include TimeGenerated, ActorUserType, AdditionalProperties, ClientIp, DeviceId, DeviceOperatingSystem, DeviceOperatingSystemVersion, Id, ObjectId, Operation, OrganizationId, RecordType, ResultStatus, SourceIp, UniqueTokenId, UserId, UserKey, UserType, and Workload. These fields help group events by operation, service, actor, result, and affected object. See the EnrichedMicrosoft365AuditLogs table reference for the current schema.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not assume the IP field identifies the end user

Microsoft documents that ClientIp can be null for Azure Active Directory-related events in this table. For other workloads, an IP may represent a trusted service or intermediary rather than the end-user device. A missing or intermediary IP does not prove there was no network source or that the activity was internal.

Microsoft Graph and Azure AD Graph are different APIs

MicrosoftGraphActivityLogs concerns requests to Microsoft Graph, the current API surface. AADGraphActivityLogs concerns requests to the older Azure AD Graph API. Do not use the legacy table as a synonym for current Microsoft Graph logging. It can help identify applications that still call the old endpoint and inform migration work; check its actual workspace schema because it is a legacy source. Reference: AADGraphActivityLogs table reference.

Enable collection and select a destination

Microsoft lists a Microsoft Entra ID P1 or P2 tenant license, a supported administrator role (Security Administrator is the least-privileged listed role for setting up diagnostic settings), an Azure subscription, and a destination resource as prerequisites for Microsoft Graph activity logs. General Entra log integration also requires access to the relevant subscription, resource group, and workspace. License requirements for Graph activity logging should not be generalized to every Entra audit-log scenario; the availability of particular audit features and properties can also depend on the licensed feature.

  1. Sign in to the Microsoft Entra admin center and open Entra ID.
  2. Select Monitoring & health, then Diagnostic settings.
  3. Select + Add diagnostic setting and enter a name.
  4. Select the log categories you need.
  5. Under Destination details, select Send to Log Analytics workspace, then choose the Azure subscription and workspace.
  6. Select Save, allow records to arrive, and verify the expected table in the workspace.

Portal entry points and labels can vary slightly depending on the blade used; Audit Logs and Sign-ins pages can also offer an export-settings route. Microsoft’s setup and access guides are Integrate activity logs with Azure Monitor Logs and Access activity logs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Graph activity logs can be routed to Log Analytics for KQL, Azure Storage for archival, or Event Hubs for streaming to an external system. Diagnostic settings do not filter Microsoft Graph activity logs, so plan any filtering downstream, such as in supported workspace transformations or the receiving pipeline. If you need security detections and threat hunting across sources, Microsoft points to Sentinel as an option: Microsoft Sentinel overview.

Query the tables with KQL

Run queries in the Log Analytics workspace that receives the diagnostic setting. Verify the table names and sample rows in your own workspace before relying on a field, value spelling, or schema that may differ by source or change over time.

Check which streams have arrived

union isfuzzy=true
    MicrosoftGraphActivityLogs,
    EnrichedMicrosoft365AuditLogs,
    AADGraphActivityLogs
| summarize
    Records=count(),
    FirstSeen=min(TimeGenerated),
    LastSeen=max(TimeGenerated)
    by Type
| order by LastSeen desc

Rank Graph callers and find failed requests

MicrosoftGraphActivityLogs
| summarize
    Requests=count(),
    Failures=countif(ResponseStatusCode >= 400),
    AverageDurationMs=avg(DurationMs)
    by AppId, ServicePrincipalId
| order by Requests desc
MicrosoftGraphActivityLogs
| where ResponseStatusCode >= 400
| project
    TimeGenerated,
    AppId,
    ServicePrincipalId,
    UserId,
    RequestMethod,
    RequestUri,
    ResponseStatusCode,
    DurationMs,
    RequestId,
    ClientRequestId
| order by TimeGenerated desc

Find throttling and endpoint use

MicrosoftGraphActivityLogs
| where ResponseStatusCode == 429
| summarize
    ThrottledRequests=count(),
    AverageDurationMs=avg(DurationMs)
    by AppId, RequestUri
| order by ThrottledRequests desc
MicrosoftGraphActivityLogs
| extend Uri=tostring(RequestUri)
| summarize Requests=count() by RequestMethod, Uri
| order by Requests desc

Endpoint counts can fragment when URIs contain different IDs, query strings, casing, or batch details. Normalize URI values to match the question you are investigating, and avoid exposing sensitive URI content in broadly shared reports.

Summarize Microsoft 365 operations and investigate one user

EnrichedMicrosoft365AuditLogs
| summarize
    Records=count(),
    Failures=countif(ResultStatus == "Failed")
    by Workload, Operation
| order by Records desc
EnrichedMicrosoft365AuditLogs
| where UserId =~ "[email protected]"
| project
    TimeGenerated,
    UserId,
    ActorUserType,
    Workload,
    Operation,
    ResultStatus,
    ObjectId,
    SourceIp,
    ClientIp,
    AdditionalProperties
| order by TimeGenerated desc

Find legacy Azure AD Graph callers

AADGraphActivityLogs
| summarize
    Requests=count(),
    Failures=countif(ResponseStatusCode >= 400)
    by AppId, ApiVersion, RequestUri
| order by Requests desc

If a legacy-table query fails, inspect the table schema before changing field names; the table is a different and older source, not a current Graph table with a guaranteed matching schema.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan cost, retention, and destination by use case

Graph activity volume can be substantial. Microsoft gives illustrative estimates of 14 GiB of storage and 15 GiB of Azure Monitor Logs per month for a 1,000-user tenant, and 1,000 GiB of storage and 1,200 GiB of Azure Monitor Logs per month for a 100,000-user tenant. These are estimates, not billing guarantees; actual volume varies with tenant activity, apps, workloads, API patterns, and time of day.

There is no universal dollar price. Azure Monitor costs depend on region, currency, purchasing agreement, log plan, ingestion, retention, query and export usage, and Sentinel configuration. Microsoft’s Azure Monitor pricing page presents estimates and directs customers to the Azure pricing calculator for an account-specific estimate.

Destination or plan Best fit Trade-off to assess
Log Analytics, Analytics Logs Frequent interactive KQL investigations, native alerting, and insights. Broader query capabilities; ingestion and extended retention affect cost.
Basic Logs Lower-cost storage for records that need less frequent investigation. Interactive-query capabilities are more limited; query charges may apply.
Auxiliary Logs / Lake Lower-cost ingestion or specialized data-lake use cases. Query capabilities and applicable charges differ from Analytics.
Azure Storage Long-term archive and data-lake processing. Not as convenient as Log Analytics for routine interactive KQL; costs vary by capacity, tier, redundancy, transactions, retrieval, and transfer.
Event Hubs Streaming to an external SIEM or custom pipeline. Requires a downstream consumer and introduces capacity, throughput, and processing considerations.
Microsoft Sentinel SOC analytics, threat hunting, detections, incidents, and response. Usage and configuration affect cost; it is not simply a low-cost archival destination.

The table reference says MicrosoftGraphActivityLogs supports Basic, Auxiliary/Lake, and ingestion-time DCR capabilities; verify current availability and plan constraints for your workspace. Workspace transformations may reduce ingested data where supported, but diagnostic settings themselves cannot filter Graph requests. Consider keeping frequently investigated security data in Analytics, archiving older or rarely queried records to Storage, and avoiding duplicate routing without a defined need.

Retention is determined by the destination, table plan, workspace configuration, and applicable compliance requirements—not by one universal period for all Entra or Microsoft 365 logs. Azure Monitor can charge for extended retention based on volume and duration; records marked _IsBillable == false are excluded from ingestion and retention charges according to Microsoft’s data retention guidance. Review the live pricing details for Basic and Auxiliary query charges and the Analytics pricing model before selecting a plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a collection pattern that matches the operating need

  • Occasional investigation: Route only the categories needed to Log Analytics, choose a retention period aligned with the investigation requirement, and measure actual ingestion before expanding collection.
  • Security operations: Use Log Analytics with Microsoft Sentinel when detections, cross-source hunting, and incident response are needed; keep the frequently queried telemetry in a suitable interactive plan.
  • Compliance archive or external SIEM: Route to Storage for long-term retention, or Event Hubs for streaming to an external consumer. Keep recent investigative data in Log Analytics if analysts require interactive KQL.

Troubleshoot empty results and misleading fields

  • No records: Confirm diagnostic settings were saved, the correct tenant and workspace were selected, and the selected category actually populates the expected table.
  • Wrong table name: Query EnrichedMicrosoft365AuditLogs rather than assuming EnrichedOffice365AuditLogs exists. Inspect tables and sample records in the workspace if a connector uses a different name.
  • Wrong time range: Check the query time picker and remember that TimeGenerated is the event time represented in the table.
  • Permissions or licensing: Verify the admin role, workspace access, Azure subscription access, and whether the feature is licensed and in use. Some audit properties can appear as hidden without the relevant license.
  • Data not yet available: Allow for ingestion delay and check again with a sufficiently broad time range.
  • Unexpectedly sparse data: Check for workspace transformations that removed records or columns, and inspect the source category and actual table schema.
  • Null IP: Do not infer that activity lacked a network origin; for Entra-related entries, ClientIp can be null by design.
  • Different schema than expected: Azure Monitor and Microsoft Graph schemas need not have identical names, structures, or event coverage. Validate representative rows before building joins or detections.

Microsoft notes that users can see no results in the Entra admin center or Microsoft Graph and points to diagnostic settings for integration with Azure Monitor. Confirm which interface and destination you are querying rather than assuming that a portal view automatically means records are present in a workspace.

Protect and interpret the data

These logs can expose user identifiers, application identities, request paths, scopes, roles, object identifiers, device details, and operational patterns. Limit workspace and export permissions to appropriate roles, and review what is sent to downstream systems. A successful response code is not proof that an application’s behavior was approved: assess its identity, permissions, endpoint, timing, and related events. Likewise, one request can fail, be retried, or be batched, while an audit record may show the resulting tenant operation without the full raw request context.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.