SV-270227r1085728_rule
V-270227
SRG-APP-000125
ENTR-ID-000370
CAT II
10
Configure the Microsoft Entra to transfer Microsoft Entra server logs to another server for storage, analysis, and reporting at least every seven days.
1. Sign in to the Microsoft Entra admin center as a Global Administrator.
2. Browse to Identity >> Monitoring & health >> Diagnostic settings.
3. Select "+ Add diagnostic settings".
4. Select at least these required categories:
- SigninLogs.
- AuditLogs.
- ServicePrincipalSignInLogs.
- ManagedIdentitySignInLogs.
- UserRiskEvents.
- RiskyUsers.
- RiskyServicePrincipals.
- ServicePrincipalRiskEvents.
5. Select "Send to Log Analytics workspace". For details on establishing a log analytics workspace, reference the DOD365 TCG.
Verify Microsoft Entra ID sign-in logs are updated in Microsoft Sentinel or equivalent SIEM. Verify the Connected Status is "green" with Last Log Received within the past hour.
1. Sign in to the Microsoft Entra admin center as a Global Administrator.
2. Browse to Identity >> Monitoring & health >> Diagnostic settings.
3. Select "Edit settings" for the entry that has an established log analytics workspace.
4. Review the selected log categories. The minimum required categories are:
- SigninLogs.
- AuditLogs.
- ServicePrincipalSignInLogs.
- ManagedIdentitySignInLogs.
- UserRiskEvents.
- RiskyUsers.
- RiskyServicePrincipals.
- ServicePrincipalRiskEvents.
If there is not an entry established to offload logs to a log analytic workspace and the minimum log categories are not selected, this is a finding.
V-270227
False
ENTR-ID-000370
Verify Microsoft Entra ID sign-in logs are updated in Microsoft Sentinel or equivalent SIEM. Verify the Connected Status is "green" with Last Log Received within the past hour.
1. Sign in to the Microsoft Entra admin center as a Global Administrator.
2. Browse to Identity >> Monitoring & health >> Diagnostic settings.
3. Select "Edit settings" for the entry that has an established log analytics workspace.
4. Review the selected log categories. The minimum required categories are:
- SigninLogs.
- AuditLogs.
- ServicePrincipalSignInLogs.
- ManagedIdentitySignInLogs.
- UserRiskEvents.
- RiskyUsers.
- RiskyServicePrincipals.
- ServicePrincipalRiskEvents.
If there is not an entry established to offload logs to a log analytic workspace and the minimum log categories are not selected, this is a finding.
M
5671