Azure PIM Logs

Matt 21 Reputation points
2021-01-28T15:10:56.353+00:00

HI All,

Looking to automate the export of PIM logs (Activiation, Approvals, Role ammendments etc) into a storage account or loganalytics workspace where they can be retained for an undefined amount of time potentially 5 years. I undertstand you can click the export button but doing this manually once a month or however often ist scalable long term.

All the best,
Matt

Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,561 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,376 Reputation points Microsoft Employee
    2021-01-28T23:38:57.54+00:00

    @Matt
    Thank you for your post!

    My team and I weren't able to find any documentation regarding the automation of exporting PIM logs into a storage account or workspace. However, I did find a PIM REST API that might help you gather audit events.

    If you want to see the full audit history of activity in your Azure Active Directory (Azure AD) organization, including administrator, end user, and synchronization activity, you can use the Azure Active Directory security and activity reports. You can also integrate Azure AD logs with Azure Monitor logs, which allows you to query data to find particular events, analyze trends, and perform correlation across various data sources.

    Since this feature isn't available as of now, I'd recommend leveraging our user voice forum so our engineering team can look into implementing your feature request.

    Current User Voice item - Support Diagnostic Settings for PIM Audit Logs

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Joby K 1 Reputation point
    2022-06-24T05:46:34.767+00:00

    How to send logs from PIM to Defender or Splunk , Please share us the steps

    0 comments No comments