A company needs to monitor sign-in logs from multiple Microsoft Entra ID tenants and analyze user sign-in patterns across those tenants. Which Azure solution should they use?
Trap 1: Azure Log Analytics workspace with Microsoft Entra ID diagnostic…
While you can configure Microsoft Entra ID diagnostic settings for 'SignInLogs' and 'AuditLogs' in each tenant to stream into a single shared Log Analytics workspace, that workspace only provides a data store and a KQL query interface. It lacks Sentinel's integrated security analytics features: no built-in analytics rules, no UEBA, no automated incident management, and no native multi-tenant correlation. You would have to manually build and maintain every alert and investigation query, and there is no central overview of health or state across tenants beyond raw log aggregation—so it is not an adequate monitoring solution on its own.
Trap 2: Microsoft Entra ID Reports and Monitoring
Microsoft Entra ID Reports & Monitoring (the built-in sign-in logs, audit logs, and provisioning logs in the Entra admin center) show logging for exactly one tenant at a time; there is no native cross-tenant aggregation or comparison. These reports also rely on the diagnostics/activity blade that offers limited filtering, exports, and retention periods, with no custom detection rules, scheduled queries, or cross-data-source correlation. To monitor sign-ins across several tenants, you would have to navigate into each tenant separately and manually piece together trends, which is not a scalable or analysis-ready approach.
Trap 3: Azure Monitor Workbooks
Azure Monitor Workbooks are interactive reporting canvases that visualize data already stored in sources like a Log Analytics workspace, Azure Data Explorer, or Application Insights, but they do not ingest or collect data themselves. A workbook cannot directly connect to multiple Microsoft Entra ID tenants or pull sign-in logs on its own; it depends on an underlying repository where logs must first be aggregated. Even if you pointed a workbook at a shared workspace, you would still need Sentinel's ingestion, analytics, and alerting to make that data usable for multi-tenant sign-in monitoring—so workbooks are merely a visualization component, not a monitoring solution.
- A
Azure Sentinel with Microsoft Entra ID connectors
Azure Sentinel is a cloud-native SIEM/SOAR that includes purpose-built connectors for Microsoft Entra ID (and Microsoft Entra ID) tenants. Its Microsoft Entra ID connector can ingest sign-in and audit logs from multiple tenants into a unified workspace, enabling cross-tenant correlation, scheduled detection rules, threat hunting with KQL, and automated incident response. This makes it the only option that delivers the full security analytics, alerting, and orchestration capabilities needed for monitoring sign-in activity across multiple Entra ID tenants.
- B
Azure Log Analytics workspace with Microsoft Entra ID diagnostic settings
Why it fails: While you can configure Microsoft Entra ID diagnostic settings for 'SignInLogs' and 'AuditLogs' in each tenant to stream into a single shared Log Analytics workspace, that workspace only provides a data store and a KQL query interface. It lacks Sentinel's integrated security analytics features: no built-in analytics rules, no UEBA, no automated incident management, and no native multi-tenant correlation. You would have to manually build and maintain every alert and investigation query, and there is no central overview of health or state across tenants beyond raw log aggregation—so it is not an adequate monitoring solution on its own.
- C
Microsoft Entra ID Reports and Monitoring
Why it fails: Microsoft Entra ID Reports & Monitoring (the built-in sign-in logs, audit logs, and provisioning logs in the Entra admin center) show logging for exactly one tenant at a time; there is no native cross-tenant aggregation or comparison. These reports also rely on the diagnostics/activity blade that offers limited filtering, exports, and retention periods, with no custom detection rules, scheduled queries, or cross-data-source correlation. To monitor sign-ins across several tenants, you would have to navigate into each tenant separately and manually piece together trends, which is not a scalable or analysis-ready approach.
- D
Azure Monitor Workbooks
Why it fails: Azure Monitor Workbooks are interactive reporting canvases that visualize data already stored in sources like a Log Analytics workspace, Azure Data Explorer, or Application Insights, but they do not ingest or collect data themselves. A workbook cannot directly connect to multiple Microsoft Entra ID tenants or pull sign-in logs on its own; it depends on an underlying repository where logs must first be aggregated. Even if you pointed a workbook at a shared workspace, you would still need Sentinel's ingestion, analytics, and alerting to make that data usable for multi-tenant sign-in monitoring—so workbooks are merely a visualization component, not a monitoring solution.