As cited
Copy frozen at (site build).
cloud saas
Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
Azure AD Graph Activity Logs are now available for ingestion into Elastic and other security platforms, closing a decade-long visibility gap where adversary reconnaissance tools operated undetected. The legacy Azure AD Graph API (graph.windows.net) remained inaccessible to defenders as a log stream until early 2026, while threat actors continued using it via tools like ROADtools and AADInternals. The article provides guidance on ingesting these logs, hunting for malicious activity, and detecting five common attack patterns including suspicious user-agents and API version abuse.
Why it matters: Azure AD and Entra ID administrators need to enable and monitor Azure AD Graph Activity Logs immediately to detect reconnaissance activity from compromised accounts or external attackers that was previously invisible to SOCs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
Azure AD Graph Activity Logs became accessible through Elastic in early 2026, closing a decade-long visibility gap where legacy directory application programming interface (API) calls from adversary tools went undetected. The logs now ingest into Elastic's security information and event management (SIEM) platform with proper extraction and enable threat hunters to detect reconnaissance activity through five key detection patterns. The legacy Azure AD Graph service remains queryable in most tenants despite Microsoft's deprecation push, with internal API versions exposing more sensitive data than the modern Microsoft Graph alternative.
Why it matters: Azure administrators and security operations center (SOC) analysts need to ingest these logs immediately to detect reconnaissance by tools like ROADrecon, AADInternals, and MSOLSpray that have operated invisibly for years; Elastic users can implement the five provided hunting patterns today to surface Entra ID enumeration attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
Azure AD Graph Activity Logs became accessible through Elastic in early 2026, closing a decade-long visibility gap where legacy directory application programming interface (API) calls from adversary tools went undetected. The logs now ingest into Elastic's security information and event management (SIEM) platform with proper extraction and enable threat hunters to detect reconnaissance activity through five key detection patterns. The legacy Azure AD Graph service remains queryable in most tenants despite Microsoft's deprecation push, with internal API versions exposing more sensitive data than the modern Microsoft Graph alternative.
Why it matters: Azure administrators and security operations center (SOC) analysts need to ingest these logs immediately to detect reconnaissance by tools like ROADrecon, AADInternals, and MSOLSpray that have operated invisibly for years; Elastic users can implement the five provided hunting patterns today to surface Entra ID enumeration attacks.
- Source published
- First seen by Cybersecurity Tracker