Skip to content
Skip to main content
Cloud Services Technical Explainer

What is an administrator audit log?

An administrator audit log records privileged changes made through a management identity, application or interface. It can establish that the tenant accepted a particular configuration change - even when ordinary user activity logs cannot show it.

Preserve the before-and-after change

At 11:06, Microsoft Entra records administrator account ADM-204 adding Dave to the Global Reader role. Event AUD-7719 identifies the target user, initiated-by identity, operation, result and changed properties. The service is recording a management request and its accepted change, not merely that the administrator had the power to make one.

Useful events include user creation, password or MFA reset, role assignment, application consent, policy updates, log changes and deletion. Record the target, previous and new values, actor, exact role, session or application, time, outcome and event ID.

Role history matters. A person may no longer be an administrator but may have held the necessary authority at the event time. Delegated administrators and managed-service providers may also act within the tenant.

Privileged actor is still a technical identity

The administrator account could be shared, automated or compromised. Compare the event with authentication and session records, change tickets, approvals, work schedules and the management tool used.

In a compromise sequence, new administrators, hidden delegation and disabled logging can create persistence or reduce visibility. Preserve these records before operational removal where urgency permits. Compare AUD-7719 with the administrator's sign-in and session, historical role assignment, and change ticket or approval.

Capability and action remain separate

Holding a role shows ability. The audit event addresses a particular use of that ability. Personal attribution requires the bridge from the recorded route to the administrator or attacker.

Microsoft Entra audit events - checked 3 September 2026

Microsoft Entra separates audit logs for changes to users, groups, applications and licences from sign-in logs. Audit entries expose an activity, initiator, target and result; changed properties may provide the before-and-after detail required to explain the operation.

The point to remember

Administrator logs record powerful tenant changes. Reconstruct the historical role, exact action and access route before attributing the event to a named administrator.

Reference: CLD-102Cloud Services