question

Noun-5028 avatar image
0 Votes"
Noun-5028 asked Noun-5028 commented

Azure active directory user accounts accidental deletion

Hi,

Is there a way to protect Azure Active Directory user and group accounts from being accidentally deleted like you can with an AD on-premise user or group object?

azure-active-directory
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

sbairu avatar image
0 Votes"
sbairu answered Noun-5028 commented

Hi @Noun-5028,

Enable accidental deletions prevention in the Azure AD provisioning service in (Preview) now, please find the below information for more details.


https://docs.microsoft.com/en-us/azure/active-directory/app-provisioning/accidental-deletions

Thanks & Regards,
Sarat chandra ,

Note: If you agree with my answer please accept my answer

· 4
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,

I have seen that article, but is just for protecting a user being removed from an enterprise app is it not?

I need to protect the deletion of an actual Azure security group or Azure user account.

0 Votes 0 ·

Hi @Noun-5028

You can set an alert to find out who deleted a user from the Azure AD, to find out which accounts were deleted

Please find below:
Navigate to Azure Active Directory → Go to Monitoring → Click Audit Logs → Filter the audit log by the Delete user activity → Click on the last event with the Delete user activity.

Please accept my answer if it helps you

Thanks & Regards,
Sarat Chandra

0 Votes 0 ·

@sbairu how do you setup the alert? I can find the event in the activity log, but how do you create the email alert?

0 Votes 0 ·
Show more comments
JaiVerma-7010 avatar image
0 Votes"
JaiVerma-7010 answered sbairu commented

For users and groups, there is no such similar functionality 'prevent from deletion' like in AD. Today, only two possibilities

  • If users and groups are synced, you can set Deletion Threshhold on Azure AD Connect

  • Setup a alert to trigger an alert email, whenever any user/group gets deleted from Azure AD. Based on transactions in your tenant, there may be too many alerts.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks can you set alerts when specific groups are deleted or is an all of nothing alert setting?

1 Vote 1 ·