Instiq
Chapter 5 · Identity governance and monitoring·v1.0.0·Updated 6/29/2026·~12 min

What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).

5.4Monitoring identity activity

Key points

Understand analyzing sign-in/audit/provisioning logs, diagnostic settings (sending to Log Analytics/storage/Event Hubs), KQL queries, workbooks and reports, and improving posture with Identity Secure Score.

Governance is completed by "monitoring and visibility." The access administrator designs analysis of identity logs, long-term retention/correlation, and continuous posture improvement.

5.4.1Log types and diagnostic settings

Entra’s main logs are three: sign-in logs (who signed in, when, from where; CA results), audit logs (directory changes: role grants, policy edits), and provisioning logs (results of auto-provisioning to SaaS). Default retention is short, so diagnostic settings route them to a Log Analytics workspace (analyze with KQL), a storage account (long-term/compliance), or Azure Event Hubs (stream to SIEM/third parties). For "retain logs long-term and correlate," use diagnostic settings + Log Analytics.

5.4.2KQL, workbooks, and Identity Secure Score

Logs sent to Log Analytics are flexibly searched/aggregated with KQL (Kusto Query Language). Workbooks are dashboards visualizing sign-in trends, CA impact, and more. Identity Secure Score scores adherence to identity best practices and prioritizes improvement actions (expand MFA, block legacy authentication, etc.). For "measure and continuously improve identity posture," use Identity Secure Score (distinct from infrastructure Secure Score).

Exam point

Cues: "record of directory changes (role grants, etc.)" = audit logs. "sign-in status / CA results" = sign-in logs. "retain logs long-term / to SIEM" = diagnostic settings (Log Analytics/storage/Event Hubs). "analyze with KQL" = Log Analytics. "score and prioritize identity posture" = Identity Secure Score.

Warning

Watch the mix-ups: (1) Identity Secure Score (identity posture) vs Defender for Cloud Secure Score (infra posture). (2) Entra logs have short default retention—use diagnostic settings for long-term export. (3) Sign-in logs (auth events) and audit logs (admin changes) serve different purposes.

Diagram of three logs (sign-in/audit/provisioning), diagnostic settings to Log Analytics (KQL)/storage (long-term)/Event Hubs (SIEM), workbooks, and Identity Secure Score (identity posture).
Measure and improve

5.4.3Section summary

  • Three logs = sign-in/audit/provisioning; diagnostic settings route to Log Analytics (KQL)/storage (long-term)/Event Hubs (SIEM)
  • Analyze/visualize with KQL and workbooks; Identity Secure Score scores identity posture and prioritizes improvement
  • Identity Secure Score (identity) differs from Defender for Cloud Secure Score (infra)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to retain Entra sign-in/audit logs long-term and correlate them with KQL. Which is best?

Q2. You want to track directory changes such as role grants and policy edits. Which log do you check?

Q3. You want to stream Entra logs in real time to a SIEM (third party). Which diagnostic-settings destination fits?

Q4. You want to score adherence to identity best practices and prioritize improvement actions. Which is best?

Q5. Which correctly distinguishes Identity Secure Score from Defender for Cloud Secure Score?

Check your understandingPractice questions for Chapter 5: Identity governance and monitoring

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.