What is the difference between an alert and an audit record?¶
An alert is a system's assessment that an event or pattern may require attention. An audit record describes an event the service recorded. The alert can establish what the detection system concluded and when; the underlying records establish the events on which that conclusion was based.
Alerts add interpretation¶
At 09:24, Microsoft Entra ID Protection labels a sign-in to Dave's account high risk because its properties appear unfamiliar. The sign-in record identifies application SharePoint Online, IP address, client and result at 09:20. The risk detection is a second record, created by a rule or model interpreting one or more observations.
An alert has its own identifier, creation or detection time, severity, indicators and later status. It may group several underlying events and can be raised or revised after they occurred.
False positives and missed activity are possible because the provider sees limited context and applies its own detection logic.
Audit records supply the event detail¶
The underlying entries may identify the account or application, session, resource, action, IP address, time and outcome. They can establish what the system accepted or changed even where the alert's risk judgement is disputed.
Preserve the alert and linked raw events. The user's or administrator's response to it may create further evidence. Obtain the provider's detection type, linked sign-in or audit IDs, risk-history changes and the relevant device and session records.
Report both accurately¶
“The provider flagged this sequence as high risk” is not “the provider proved compromise”. Combine the detection reason, events, device evidence and legitimate explanations.
Microsoft Entra risk detections - checked 3 September 2026
Microsoft describes sign-in risk as the probability that an authentication request was not made by the authorised account owner. Detections can occur in real time or offline, and risk status can later change through investigation or remediation. Preserve the detection time, last-updated time, risk state and linked sign-in rather than treating a current portal label as timeless fact.
The point to remember
An alert is a risk judgement; an audit record is an event record. Use the alert to explain concern and the underlying evidence to establish what happened.