Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.4. Monitoring Identity Activity

💡 First Principle: Governance without observability is faith. The identity plane writes three journals — who signed in, who changed what, what got provisioned — and monitoring is the pipeline that keeps those journals long enough, queryable enough, and loud enough to answer yesterday's incident and tomorrow's audit.

This section is also where several earlier threads terminate: CA troubleshooting reads sign-in logs (2.2.4), compromise response reads audit logs for persistence (2.3.3), PIM's trail lands in audit logs (5.3.3), and break-glass alerting rides diagnostic settings. Expect stems that name a question ("who consented to this app in March?") and grade your choice of log, destination, and tool.

⚠️ Common Misconception: Entra keeps logs long-term by default. Portal retention is short — 30 days for sign-in/audit logs with P1/P2 (7 days on Free) — so any requirement measured in months ("retain for one year for compliance") mandates exporting via diagnostic settings to a destination you control. No export configured = data already gone when the auditor asks.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications