There are limitations in days for Azure Active directory log retention as mentioned below,
How long does Azure AD store the data?
Activity reports
Report | Azure AD Free | Azure AD Premium P1 | Azure AD Premium P2 |
---|---|---|---|
Audit logs | 7 days | 30 days | 30 days |
Sign-ins | 7 days | 30 days | 30 days |
Azure AD MFA usage | 30 days | 30 days | 30 days |
Admins can retain the audit and sign-in activity data for longer than the default retention period outlined above by routing it to an Azure storage account using Azure Monitor.
Prerequisites
To use this feature, you need:
- An Azure subscription. If you don't have an Azure subscription, you can sign up for a free trial.
- An Azure AD tenant.
- A user who's a global administrator or security administrator for the Azure AD tenant.
- A Log Analytics workspace in your Azure subscription. Learn how to create a Log Analytics workspace.
Licensing requirements
Using this feature requires an Azure AD Premium P1 or P2 tenant. You can find the license type of your tenant on the Overview page in Azure Active Directory.
If you want to know for how long the activity data is stored in a Premium tenant, see: How long does Azure AD store the data?
Send logs to Azure Monitor
-
Sign in to the Azure portal.
-
Select Azure Active Directory > Diagnostic settings -> Add diagnostic setting. You can also select Export Settings from the Audit Logs or Sign-ins page to get to the diagnostic settings configuration page.
-
In the Diagnostic settings menu, select the Send to Log Analytics workspace check box, and then select Configure.
-
Select the Log Analytics workspace you want to send the logs to or create a new workspace in the provided dialog box.
-
Do either or both of the following:
- To send audit logs to the Log Analytics workspace, select the AuditLogs check box.
- To send sign-in logs to the Log Analytics workspace, select the SignInLogs check box.
-
Select Save to save the setting.
-
After about 15 minutes, verify that events are streamed to your Log Analytics workspace.
Comments
0 comments
Please sign in to leave a comment.