Instiq
Chapter 5 · Identity governance and monitoring·v1.0.0·Updated 6/28/2026·~12 min

What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).

5.4Monitoring identity activity

Key points

Understand analyzing sign-in/audit/provisioning logs, diagnostic settings (sending to Log Analytics/storage/Event Hubs), KQL queries, workbooks and reports, and improving posture with Identity Secure Score.

Governance is completed by "monitoring and visibility." The access administrator designs analysis of identity logs, long-term retention/correlation, and continuous posture improvement.

5.4.1Log types and diagnostic settings

Entra’s main logs are three: sign-in logs (who signed in, when, from where; CA results), audit logs (directory changes: role grants, policy edits), and provisioning logs (results of auto-provisioning to SaaS). Default retention is short, so diagnostic settings route them to a Log Analytics workspace (analyze with KQL), a storage account (long-term/compliance), or Azure Event Hubs (stream to SIEM/third parties). For "retain logs long-term and correlate," use diagnostic settings + Log Analytics.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.