Loading...

Microsoft Graph activity logs is now generally available

Microsoft Graph activity logs is now generally available

We’re excited to announce the general availability of Microsoft Graph activity logs! Microsoft Graph activity logs give you visibility into HTTP requests made to the Microsoft Graph service in your tenant. With rapidly growing security threats and an increasing number of attacks, this log data source allows you to perform security analysis, threat hunting, and monitor application activity in your tenant.  

 

Some common use cases include: 

  

  • Identifying the activities that a compromised user account conducted in your tenant. 
  • Building detections and behavioral analysis to identify suspicious or anomalous use of Microsoft Graph APIs, such as an application enumerating all users, or making probing requests with many 403 errors. 
  • Investigating unexpected or unnecessarily privileged assignments of application permissions. 
  • Identifying problematic or unexpected behaviors for client applications, such as extreme call volumes that cause throttling for the tenant. 

 

You’re currently able to collect sign-in logs to analyze authentication activity and audit logs to see changes to important resources. With Microsoft Graph activity logs, you can now investigate the complete picture of activity in your tenant – from token request in sign-in logs, to API request activity (reads, writes, and deletes) in Microsoft Graph activity logs, to ultimate resource changes in audit logs.

 

Figure 1: Microsoft Graph activity logs in Log Analytics.Figure 1: Microsoft Graph activity logs in Log Analytics.

 

 

We’re delighted to see many of you applying the Microsoft Graph activity logs (Preview) to awesome use cases. As we listened to your feedback on cost concerns, particularly for ingestion to Log Analytics, we’ve also enabled Log Transformation and Basic Log capabilities to help you scope your log ingestion to a smaller set if desired.

 

To illustrate working with these logs, we can look at some basic queries: 
 
Summarize applications and principals that have made requests to change or delete groups in the past day:

 

MicrosoftGraphActivityLogs 

| where TimeGenerated > ago(1d) 

| where RequestUri contains '/group' 

| where RequestMethod != "GET" 

| summarize UriCount=dcount(RequestUri) by AppId, UserId, ServicePrincipalId, ResponseStatusCode 

 

See recent requests that failed due to authorization:

 

MicrosoftGraphActivityLogs 

| where TimeGenerated > ago(1h) 

| where ResponseStatusCode == 401 or ResponseStatusCode == 403 

| project AppId, UserId, ServicePrincipalId, ResponseStatusCode, RequestUri, RequestMethod 

| limit 1000 

 

Identify resources queried or modified by potentially risky users:

Note: This query leverages Risky User data from Entra ID Protection.

 

MicrosoftGraphActivityLogs 

| where TimeGenerated > ago(30d) 

| join AADRiskyUsers on $left.UserId == $right.Id 

| extend resourcePath = replace_string(replace_string(replace_regex(tostring(parse_url(RequestUri).Path), @'(\/)+','/'),'v1.0/',''),'beta/','') 

| summarize RequestCount=dcount(RequestId) by UserId, RiskState, resourcePath,

RequestMethod, ResponseStatusCode 

 

Microsoft Graph activity logs are available through the Azure Monitor Logs integration of Microsoft Entra. Administrators of Microsoft Entra ID P1 or P2 tenants can configure the collection and storage destinations of Microsoft Graph activity logs through the diagnostic setting in the Entra portal. These settings allow you to configure the collection of the logs to a storage destination of your choice. The logs can be stored and queried in an Azure Log Analytics Workspace, archived in Azure Storage Accounts, or exported to other security information and event management (SIEM) tools through Azure Event Hubs. For logs collected in a Log Analytics Workspace, you can use the full set of Azure Monitor Logs features, such as a portal query experience, alerting, saved queries, and workbooks.   

 

Find out how to enable Microsoft Graph activity logs, sample queries, and more in our documentation. 

 

Kristopher Bash 

Product Manager, Microsoft Graph 
LinkedIn

 

 

Learn more about Microsoft Entra: 

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Microsoft Teams: Meeting Participant Detail audit records will be available in all participating (non-organizer) tenants

Starting late August 2026, Microsoft Teams will share Meeting Participant Detail audit records with all participating tenants for their own us...

3 hours ago

Microsoft Purview | Data Loss Prevention: Unified data access messages in Microsoft 365 Copilot

Microsoft 365 Copilot now shows a consistent message when Microsoft Purview DLP policies restrict content access or processing. This update im...

3 hours ago

Microsoft Teams: Update the Teams mobile app to maintain Calendar functionality

Users must update the Microsoft Teams mobile app by late October 2026 to retain Calendar functionality on iOS and Android. Older app versions ...

3 hours ago

Microsoft 365 Copilot: Retirement of role-to-skill mapping files in People Skills

Starting August 22, 2026, Microsoft 365 Copilot will retire role-to-skill mapping files in People Skills. Skills inferencing will no longer us...

3 hours ago

Simplifying creation on M365 Copilot mobile

The Microsoft 365 Copilot mobile app will remove the standalone Create experience, starting August 2026, to simplify content creation via Copi...

3 hours ago

Sales in Microsoft 365 Copilot-Add Microsoft 365 Graph grounding for emails, meetings, chats as knowledge to Sales agent

We are announcing the ability to add Microsoft 365 Graph grounding for emails, meetings, and chats as knowledge to Sales agent in Sales in Mic...

3 hours ago

Microsoft Copilot (Microsoft 365): New Rich Answer Cards

Surface new model-driven, dynamically placed Answer Cards across top 7 segments: weather, sports, finance, images, video, places and news for ...

4 hours ago

DLP Prevents Microsoft 365 Copilot from Processing External Email

A new (preview) DLP capability allows Microsoft 365 tenants to block Microsoft 365 Copilot from processing the content of external email. When...

6 hours ago

Microsoft Copilot (Microsoft 365): Workforce Insights Agent

Workforce Insights (WFI) Agent in Microsoft 365 Copilot is an agent designed to help leaders, managers, and their delegates quickly understand...

13 hours ago

What Is Microsoft 365 Copilot Cowork?

Microsoft 365 Copilot Cowork handles multi-step business tasks instead of using Copilot only for creating drafts, summaries, or recommendation...

19 hours ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy