Memory hook: Find the actual actor, resource and policy result.
Must remember
Sign-in logs explain authentication/resource access attempts and Conditional Access evaluation. Audit logs describe directory/configuration changes. Provisioning logs track identity synchronization into applications/services. Choose the log matching the failed operation before changing policy.
Diagnostic settings route supported logs to Log Analytics, storage or Event Hubs for analysis, retention or external processing. Availability, retention and licensing vary by log/capability. Protect access because logs can contain personal and security-sensitive information. A destination configured today does not reconstruct every historical event.
Use KQL to filter a time range, correlate identity/application/correlation IDs and summarize failure trends. Workbooks visualize reusable analysis; Identity Secure Score highlights improvement recommendations rather than certifying that the tenant is safe. Investigate a sudden score change in context.
For a failed app login, trace user/device state, authentication method, risk, policy result, application assignment and consent. For provisioning failure, inspect mapping/scope and target API responses. For privileged activity, correlate PIM activation with subsequent audit events. Preserve evidence and distinguish an expected administrative action from misuse.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| User cannot authenticate | Sign-in logs and policy details. |
| User authenticates but app account missing | Provisioning logs and assignment/mapping. |
| Role unexpectedly changed | Directory audit logs and PIM history. |
Traps
- A Secure Score recommendation is not proof of an incident.
- Changing Conditional Access will not necessarily repair a provisioning error.
Active recall
1. Which log describes a directory role change?
Audit logs, with PIM history where relevant.
2. Which log helps explain MFA/policy outcome?
Sign-in logs.
3. Why use correlation IDs?
To connect related events across a request flow.
4. What is a workbook for?
Reusable interactive visualization of query/monitoring results.
5. Why configure retention deliberately?
Default history may be insufficient for investigation or obligations.