certslothcertsloth
SC-300/Topic 07

Microsoft / Associate

Identity Logs, KQL and Operational Investigation

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Find the actual actor, resource and policy result.

Must remember

Sign-in logs explain authentication/resource access attempts and Conditional Access evaluation. Audit logs describe directory/configuration changes. Provisioning logs track identity synchronization into applications/services. Choose the log matching the failed operation before changing policy.

Diagnostic settings route supported logs to Log Analytics, storage or Event Hubs for analysis, retention or external processing. Availability, retention and licensing vary by log/capability. Protect access because logs can contain personal and security-sensitive information. A destination configured today does not reconstruct every historical event.

Use KQL to filter a time range, correlate identity/application/correlation IDs and summarize failure trends. Workbooks visualize reusable analysis; Identity Secure Score highlights improvement recommendations rather than certifying that the tenant is safe. Investigate a sudden score change in context.

For a failed app login, trace user/device state, authentication method, risk, policy result, application assignment and consent. For provisioning failure, inspect mapping/scope and target API responses. For privileged activity, correlate PIM activation with subsequent audit events. Preserve evidence and distinguish an expected administrative action from misuse.

Choose under exam pressure

Requirement Choice and reason
User cannot authenticate Sign-in logs and policy details.
User authenticates but app account missing Provisioning logs and assignment/mapping.
Role unexpectedly changed Directory audit logs and PIM history.

Traps

  • A Secure Score recommendation is not proof of an incident.
  • Changing Conditional Access will not necessarily repair a provisioning error.

Active recall

1. Which log describes a directory role change?

Audit logs, with PIM history where relevant.

2. Which log helps explain MFA/policy outcome?

Sign-in logs.

3. Why use correlation IDs?

To connect related events across a request flow.

4. What is a workbook for?

Reusable interactive visualization of query/monitoring results.

5. Why configure retention deliberately?

Default history may be insufficient for investigation or obligations.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.