Fabian 5/10/2026

Now You See Me: AADGraphActivityLogs

Read Original

This article discusses the introduction of AADGraphActivityLogs, a new log source in Microsoft Entra ID that provides crucial insights into Azure AD Graph API activity. It explains how to enable these logs via Diagnostic Settings, describes the log schema including key fields like TimeRequested, RequestMethod, UserAgent, and CallerIpAddress, and highlights detection opportunities for identifying reconnaissance tooling such as ROADtools and AADInternals. The author emphasizes the importance of this log for closing detection gaps in monitoring abuse of the legacy Azure AD Graph API, which attackers have exploited for tenant reconnaissance and conditional access bypass attacks.

Now You See Me: AADGraphActivityLogs

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet