eG Monitoring
 

Measures reported by AzrADActvtyTest

Azure Active Directory provides Audit Logs, where changes/updates to the configuration of users, groups, and applications are logged. With the audit logs in Azure AD, administrators get access to records of system activities for compliance.

Whenever critical changes are made to an Azure organization - e.g., a password is changed, an application is updated, if the license of a user has changed etc. - administrators may want to know whether such changes were initiated by authorized services/users. This is because, unauthorized changes, if permitted, can have serious, long-standing repurcussions on the overall health and operations of the cloud organization. SometimesTo quickly spot such changes, and to know what was changed and by whom, administrators need to review the audit logs periodically. The AzrADActvtyTest helps administrators in this exercise!

This test monitors the Azure AD audit logs at configured intervals, and notifies administrators every time a user-, group-, or application-related change/activity is logged in the audit log file.

Detailed diagnostics provide additional details about the change/activity, thereby enabling administrators to figure out who made the change and when. With the help of this information, administrators can quickly detect unauthorized changes, and take appropriate action.

Outputs of the test : One set of results for the Azure AD tenant being monitored

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
Add_user Indicates the number of ‘add user’ activities performed on Azure AD. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Delete_user Indicates the number of ‘delete user’ actions that were performed on Azure AD. Number Use the detailed diagnosis of this measure to know when the deletionion occurred, who initiated the deletion, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_user Indicates the number of ‘update user’ actions that were performed on Azure AD. Number Use the detailed diagnosis of this measure to know when the updation occurred, who initiated it, the status of the updation attempt (success/failure), and the reason for the failure (if any).
Restore_user Indicates the number of ‘restore user’ actions that were performed on Azure AD. Number Use the detailed diagnosis of this measure to know when the action occurred, who initiated it, the status of the action (success/failure), and the reason for the failure (if any).
Disable_user_acc Indicates the number of ‘disable user account’ actions that were performed on Azure AD. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Change_user_license Indicates the number of ‘change user license’ actions that were performed on Azure AD. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Change_user_pwd Indicates the number of attempts made to change user passwords. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Reset_user_pwd Indicates the number of attempts made to reset user passwords. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Set_force_change_pwd Indicates the number of attempts made to force-change user passwords. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Register_user_pwd Indicates the number of attempts made to register user passwords. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Strong_authenticate Indicates the number of attempts made to enable strong authentication. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Create_application_pwd Indicates the number of attempts made to create an application password for users. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Delete_application_pwd Indicates the number of attempts made to delete an application password for users. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Admin_generate_temp_pwd Indicates the number of attempts made by an admin to generate a temporary password. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Add_application Indicates the number of ‘add application’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any)
Delete_application Indicates the number of ‘delete application’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_application Indicates the number of ‘update application’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Restore_application Indicates the number of ‘restore application’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_service_principle Indicates the number of attempts made to add service principals. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_srvcprncpl_crdntial Indicates the number of attempts made to add service principal credentials. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_srvcprncpl Indicates the number of attempts made to update service principal. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Remove service principal Indicates the number of attempts made to remove service principal Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_srvcprncpl_crdntial Indicates the number of attempts made to remove service principal credentials. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_group Indicates the number of attempts made to add groups. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_group_sttng Indicates the number of attempts made to create group settings. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Delete_group Indicates the number of ‘delete application’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Delete_group_sttng Indicates the number of attempts made to delete group settings. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_group Indicates the number of ‘update group’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_group_sttng Indicates the number of attempts made to update group settings. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Restore_group Indicates the number of ‘restore group’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Start_apply_grp_license Indicates the number of times the application of group-based licenses to users were started. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Finish_apply_grp_license Indicates the number of times the application of group-based licenses to users were completed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Set_group_license Indicates the number of attempts made to set group licenses. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Trigger_group_license Indicates the number of attempts made to trigger group license recalculation. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_policy Indicates the number of ‘add policy’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_plcy_to_applctn Indicates the number of attempts made to add policy to application. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_plcy_to_srvcprncpl Indicates the number of attempts made to add policy to service principal. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Delete_policy Indicates the number of ‘delete policy’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_policy Indicates the number of ‘update policy’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_role_defntion Indicates the number of attempts made to add role definitions. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_rl_assignmnt Indicates the number of attempts made to add role assignment to role definitions. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_elgbl_membr_to_rl Indicates the number of attempts made to add eligible member to role. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_rl_frm_tmplt Indicates the number of attempts made to add role from template. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Delete_rl_defntn Indicates the number of attempts made to delete role definitions. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_elgbl_membr_frm_rl Indicates the number of attempts made to remove eligible member from role. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_rl_assgnmnt Indicates the number of attempts made to remove role assignment from role definition. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_scpd_membr_frm_rl Indicates the number of attempts made to remove scoped member from role. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_role Indicates the number of ‘update role’ actions that were performed. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Update_rl_dfntn Indicates the number of attempts made to update role definitions. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_ownr_to_plcy Indicates the number of attempts made to add owner to policy. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_ownr_to_applctn Indicates the number of attempts made to add owner to application. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_ownr_to_grp Indicates the number of attempts made to add owner to group. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_ownr_to_srvcprncpl Indicates the number of attempts made to add owner to service principal. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_ownr_frm_grp Indicates the number of attempts made to remove owner from group. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_ownr_frm_policy Indicates the number of attempts made to remove owner from policy. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_ownr_frm_applctn Indicates the number of attempts made to remove owner from application. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_ownr_frm_srvcprncpl Indicates the number of attempts made to remove owner from service principal. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_membr_frm_grp Indicates the number of attempts made to remove member from group. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_membr_frm_role Indicates the number of attempts made to remove member from role. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_membr_frm_admnstrtv Indicates the number of attempts made to remove member from administrative unit. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_membr_to_role Indicates the number of attempts made to remove member from administrative unit. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_membr_to_grp Indicates the number of attempts made to add member to group. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_membr_to_admnstrtv Indicates the number of attempts made to add member to administrative unit. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_app_rl_to_srvcprncpl Indicates the number of attempts made to add app role assignment to service principal. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_app_rl_to_user Indicates the number of attempts made to add app role assignment to user. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Add_app_rl_to_grp Indicates the number of attempts made to add app role assignment to group. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_app_rl_frm_srvcprnc Indicates the number of attempts made to remove app role assignment from service principal. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_app_rl_frm_user Indicates the number of attempts made to remove app role assignment from user. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).
Rmve_app_rl_frm_grp Indicates the number of attempts made to remove app role assignment from group. Number Use the detailed diagnosis of this measure to know when the addition occurred, who initiated the addition, the status of the attempt (success/failure), and the reason for the failure (if any).