Azure Security & Activity Reports

17 Reports
About Security & Activity Reports

The Security & Activity tab in Azure Reports brings seventeen premium Microsoft Entra ID reports together in one place — sign-in and audit activity, sign-in risk and legacy authentication, MFA registration and enforcement coverage, conditional access policies and hygiene, identity-protection risk, and full Privileged Identity Management (PIM) eligibility, activity, and history. These reports surface the security and activity data that on-premises Active Directory simply doesn't have.

Put simply, this is where you answer the questions auditors and security teams actually ask about your cloud identity: who is signing in and how, is MFA really protecting everyone, are our Conditional Access policies closing the gaps, where is the identity risk, and who holds privileged access? Every report is read-only — you can investigate, evidence a finding, and export it for an audit without changing anything in your tenant. It's a fit for security reviews, Zero Trust and MFA rollouts, incident investigation, and periodic access certifications in hybrid or cloud-first environments.

Premium tier: Each report is labeled P1 or P2 for the Microsoft Entra ID license it needs. If you're missing a license or admin consent, AD Reports shows a clear License Required or Permission Required message instead of a cryptic error. Consent for premium data is requested only when you run a report — your normal sign-in and free-tier Azure reports are never affected.
What These Reports Help You Answer

Each report targets a specific security question. Here's how the seventeen reports map to the things you actually need to know:

  • Who's signing in — and how? Sign-In Logs, User Sign-In Activity, and Legacy Authentication Sign-Ins show who authenticated, when, and over which protocols — so you can find dormant accounts and risky legacy sign-ins (POP / IMAP / SMTP) that quietly bypass MFA.
  • Is MFA actually protecting everyone? MFA Registration, Users with Weak or No MFA, and MFA Enforcement Coverage reveal who is unprotected — no MFA, only phishable methods, or not actually covered by an enforced policy — with admins highlighted.
  • Are Conditional Access policies closing the gaps? Conditional Access Policies, Conditional Access Policy Hygiene, and Sign-Ins Without Conditional Access surface policies that aren't enforcing, accounts excluded from protection, and logins that no policy applied to.
  • Where is the identity risk? Risky Users, Risky Sign-Ins, and Risk Detections bring Microsoft Entra ID Protection's risk signals into reports you can filter, export, and act on.
  • Who has privileged access — and what did they do? PIM Eligible Roles, PIM Active Role Assignments, and PIM Activation History show who can elevate, who holds standing admin rights, and a full audit trail of activations.
  • What changed in the directory? Directory Audit Logs and Provisioning Logs record user, group, role, and policy changes with the actor, target, and timestamp for each one.

Example: Azure Security & Activity tab in AD Reports

AD Reports Azure Security and Activity Reports

Available Reports

Grouped by the security question each one answers. Every report is read-only and exports to your usual formats.

Sign-In Activity & Legacy Authentication
Sign-In Logs P1

Interactive and non-interactive sign-in events from your tenant — who signed in, when, from where, on which app, and whether it succeeded or failed.

Use it to: trace a suspicious login, confirm where a user authenticated from, or spot failed-sign-in spikes.

User Sign-In Activity P1

Per-user last-sign-in summary (signInActivity) — the fastest way to find dormant cloud accounts that haven't authenticated in months.

Use it to: find inactive cloud accounts to review or deprovision.

Legacy Authentication Sign-Ins P1 New

Sign-ins that used legacy protocols (POP, IMAP, SMTP, older Office clients) — the most common way attackers bypass MFA. A prime hardening target.

Use it to: build the case for blocking legacy auth and see who still depends on it.

MFA Posture
MFA Registration P1

Per-user multi-factor authentication registration status — who is registered for MFA / passwordless methods and who is still a gap.

Use it to: track MFA rollout progress across the tenant.

Users with Weak or No MFA P1 New

Users who have no MFA registered or only phishable methods (SMS, voice, email), with admins highlighted so the riskiest gaps stand out.

Use it to: prioritize the accounts that need stronger methods first — starting with admins.

MFA Enforcement Coverage P1 New

For every user, whether they're actually covered by an enforced “require MFA” Conditional Access policy (expanding group memberships), with admins highlighted. Tenants using Security Defaults are correctly reported as MFA-enforced.

Use it to: prove MFA is truly enforced — not just registered — for every admin.

Conditional Access Coverage
Conditional Access Policies P1

Inventory of every Conditional Access policy with its state, assignments, conditions, and grant controls — a one-glance review of your access posture.

Use it to: document your CA posture for an audit.

Conditional Access Policy Hygiene P1 New

Analyzes your CA policies and flags coverage-gap risks: policies that aren't enforcing (report-only or off), accounts excluded from a policy, and missing MFA/block controls.

Use it to: find the weak spots in your policy set before an attacker does.

Sign-Ins Without Conditional Access P1 New

Sign-ins that no Conditional Access policy applied to — coverage gaps where a login had zero CA enforcement.

Use it to: catch the logins slipping through every policy.

Identity Protection Risk
Risky Users P2

Microsoft Entra ID Protection risky users with their risk level and risk state — the accounts most likely to be compromised.

Use it to: triage the users Microsoft has flagged and confirm or dismiss the risk.

Risky Sign-Ins P2 New

Sign-ins that Microsoft Entra ID Protection flagged as risky — risk level, state, detail, and event types — shown alongside Risky Users and Risk Detections.

Use it to: investigate the specific sign-ins behind a risky user.

Risk Detections P2

Individual Identity Protection risk detections (anonymous IP, impossible travel, leaked credentials, and more) with detection type, level, and timestamp.

Use it to: see the raw signals feeding your risk scores.

Privileged Access (PIM)
PIM Eligible Roles P2

Privileged Identity Management eligible role assignments — who can activate privileged directory roles, even when not currently active.

Use it to: review who is eligible for admin roles.

PIM Active Role Assignments P2 New

Who currently holds each privileged role, with a Permanent column flagging standing admins vs. just-in-time PIM activations.

Use it to: hunt down standing/permanent admins that should be just-in-time.

PIM Activation History P2 New

A read-only audit trail of privileged-role activations and assignments — who did what to which role, when, and the result — completing the PIM trio.

Use it to: evidence privileged-access activity for a compliance review.

Directory & Provisioning Activity
Directory Audit Logs P1

Directory changes — user, group, role, and policy modifications — with the actor, target, and timestamp for each change.

Use it to: answer “who changed this, and when?” during an investigation.

Provisioning Logs P1

Records of accounts provisioned to and from connected apps — useful for tracking SCIM / app provisioning successes and failures.

Use it to: diagnose app provisioning errors.

What [P1] and [P2] Mean

P1 reports require a Microsoft Entra ID P1 license — sign-in / audit / provisioning logs, legacy authentication sign-ins, MFA registration, weak/no MFA, MFA enforcement coverage, sign-ins without Conditional Access, and Conditional Access policies & hygiene.

P2 reports require a Microsoft Entra ID P2 license, which adds Identity Protection (Risky Users, Risky Sign-Ins, Risk Detections) and Privileged Identity Management (PIM Eligible Roles, Active Role Assignments, and Activation History). The exact requirement is shown next to each report inside AD Reports, and unavailable reports explain precisely what's missing.