AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company wants to monitor sign-in failures for their Microsoft Entra ID-integrated applications. They need a dashboard in Azure Monitor showing sign-in failures by application and user location. Which data source should they stream to a Log Analytics workspace?
⚠ Common exam trap
A common mix-up: candidates confuse Audit logs with Sign-in logs, assuming Audit logs capture all security events, but Audit logs specifically exclude authentication attempts and location data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Sign-in logs
Microsoft Entra ID Sign-in logs contain detailed information about every sign-in attempt, including success or failure status, application name, user location (IP address), and failure reasons. Streaming these logs to a Log Analytics workspace enables you to build custom dashboards in Azure Monitor that visualize sign-in failures by application and user location. Audit logs track configuration changes, not authentication events; Provisioning logs cover user/group synchronization; and Office 365 Activity logs focus on workload-specific actions, not general sign-in failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Audit logs
Why it's wrong here
Microsoft Entra ID Audit logs record every configuration change and administrative action inside the tenant, such as adding a user, modifying a group, updating a conditional access policy, or resetting a password. They are often described as "who did what" and do not capture the outcome of an authentication attempt, so a sign-in failure would never appear here. Sign-in events belong exclusively to the Sign-in logs; audit logs only show the resulting tenant changes made after a successful admin operation.
- ✓
Microsoft Entra ID Sign-in logs
Why this is correct
Microsoft Entra ID Sign-in logs are the authoritative telemetry for authentication against the directory, containing both successful and failed sign-in attempts for interactive and non-interactive sessions. Each entry includes the user principal name, application, client IP, device, location, and a specific sign-in error code (e.g., 50126 for invalid password), along with conditional access and MFA status. Because they persist and expose the exact failure reason, they are the correct data source for monitoring sign-in failures across Entra ID-integrated applications.
- ✗
Microsoft Entra ID Provisioning logs
Why it's wrong here
Microsoft Entra ID Provisioning logs monitor the background synchronization lifecycle of identities into third-party SaaS applications such as ServiceNow, Salesforce, or AWS. These records capture operations like creating, updating, deactivating, and deleting user accounts in those external systems, and they are completely independent of any interactive authentication attempt. A sign-in failure would not generate a provisioning log entry because provisioning doesn't happen at the moment of sign-in; instead, it runs on a schedule or when identity changes are detected.
- ✗
Office 365 Activity logs
Why it's wrong here
Office 365 Activity logs, also known as the unified audit log, aggregate actions performed in Microsoft 365 workloads, such as an Exchange Online mailbox operation, a SharePoint file access, or a Teams message event, and are scoped to the M365 service plane. They do not capture the authentication transaction that occurs at the Microsoft Entra ID directory boundary before access is granted to an integrated application. Sign-in failures for an integrated app happen in the identity plane, so they are issued in the Sign-in logs, while Office 365 Activity logs would only reflect downstream activity if the user actually gained access.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.