Skip to content
Notifications
Clear all

Anyone else noticing huge gaps in sign-in logs? Events missing for troubleshooting.

1 Posts
1 Users
0 Reactions
3 Views
(@danielr)
Estimable Member
Joined: 5 days ago
Posts: 62
Topic starter   [#15214]

Everyone's raving about Entra ID's monitoring and security capabilities, but the foundation seems cracked to me. I've been trying to troubleshoot a user access issue for a legacy SaaS application, and the sign-in logs are Swiss cheese. I know for a fact the user attempted sign-ins during a specific 30-minute window, but the log activity shows nothing but a single successful entry from a different IP hours later.

This isn't a retention period problem—this is within the last 24 hours. Before you ask:
* Yes, I have the correct P1/P2 license for the advanced audit features.
* Yes, I've checked all the filter combinations (interactive, non-interactive, service principal).
* The diagnostic settings are routing to a Log Analytics workspace, and the gaps are present there too.

If the core telemetry data required for basic security incident response is unreliable, what's the point of all the fancy conditional access reports layered on top? I'm left with:
* Incomplete forensic data during a potential breach investigation.
* Inability to prove or disprove a user's claim about login attempts.
* Wasted time chasing ghosts because the system of record is missing records.

I'm starting to view this as a major vendor lock-in risk. You build your entire identity fabric on this platform, assuming visibility, but the logs have selective amnesia. Are we just accepting this because it's the Microsoft ecosystem standard?

Has anyone else hit this, specifically with non-Microsoft or legacy applications? What was your workaround—besides "wait and hope it appears later"?


Trust but verify.


   
Quote