Monitors changes in Entra ID and alerts about new, modified, and deleted users.
The Entra ID User and Devices Event Monitor monitors your Entra ID users and sends alerts if users are modified, deleted, or new since the last time the event monitor checked.
This event monitor provides the following options:
This option will send you an alert if the device cannot be contacted.
Use this option to receive an alert if the event monitor detects user accounts that have been newly created.
This option will send an alert of your choice if user accounts have been deleted.
Use this option to receive an alert if user accounts have not logged in for a specified number of days.
Use this option to get alerted if user accounts are disabled.
Use this option to receive an alert if user accounts do not have multi-factor authentication enabled.
Enable this option to check only users in the group you specify.
Enter the names of the accounts to ignore, separated by commas. Note that this feature does not apply to deleted accounts.
Check this box to ignore disabled user accounts.
Use this filter option to ignore Entra ID guest accounts.
Use this option to ignore member accounts in Entra ID.
This option lets you ignore user accounts that have never logged in.
Enter a group ID that will be checked. This option allows you to be notified whenever changes are made to specific group in Microsoft Entra.
Use this option to receive an alert of your choice if members have been added since the event monitor last ran.
This option will send an alert of your choice if members are removed from Entra ID.
Enable this option to include a list of detected group members in the event text this event monitor generates. Enter the number of group members you want displayed.
This option will send you an alert of your choice if computers have been added since the last time the event monitor checked.
Enable this option to receive an alert of your choice if computers have been deleted since the last time the event monitor ran.
The account used to authenticate must have User.Read.All, Directory.Read.All, Group.Read.All, Device.Read.All, GroupMember.Read.All, and AuditLog.Read.All at the application level.
This event monitor generates the following data points:
| Data Point | Description |
|---|---|
| Deleted Devices | Number of deleted devices. |
| Deleted Users | Number of deleted users. |
| Disabled Users | Number of disabled user accounts. |
| New Devices | Number of new devices since last check. |
| New Users | Number of new users since last check. |
| Stale Accounts | Number of stale accounts |
| Users Without MFA | Number of user accounts without multi-factor auth enabled. |
Add a comment