Courseiva
easyMultiple Choice

Which Table to Query for Microsoft Entra ID Role Changes

A SOC analyst wants to create a scheduled analytics rule in Microsoft Sentinel that detects when a user is added to a privileged Microsoft Entra ID role (e.g., Global Administrator). Which data table is essential for the query?

Quick Answer

The answer is the AuditLogs table. This is correct because the AuditLogs table in Microsoft Sentinel captures all directory-level audit activities, including modifications to Microsoft Entra ID role assignments, such as when a user is added to a privileged role like Global Administrator. The specific event is logged as an 'Add member to role' activity, making AuditLogs the essential data source for detecting these changes. On the SC-200 exam, this tests your understanding of which Sentinel table maps to specific identity events, often appearing in scenarios where you must distinguish between SigninLogs (authentication events) and AuditLogs (configuration changes). A common trap is confusing AuditLogs with the AADUserRiskEvents table, which only tracks user risk, not role assignments. For a quick memory tip, remember that any time a role or permission is changed in Entra ID, it is always an audit event—so think "AuditLogs for admin adds."

⚠ Common exam trap

Microsoft often tests the distinction between sign-in logs (SigninLogs) and audit logs (AuditLogs), trapping candidates who confuse authentication events with directory configuration changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AuditLogs

The AuditLogs table in Microsoft Sentinel captures all directory-level audit activities, including modifications to Microsoft Entra ID (formerly Azure AD) role assignments. When a user is added to a privileged role like Global Administrator, the event is logged as an 'Add member to role' activity in the AuditLogs table. This makes AuditLogs the essential data source for detecting such privileged role changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AuditLogs

    Why this is correct

    Role assignments in Microsoft Entra ID, including additions to privileged roles such as Global Administrator, are recorded in the AuditLogs table. Querying AuditLogs with the Add member to role operation captures the directory change, which SigninLogs and SecurityEvent do not record.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs records authentication events, including sign-in success, failure and conditional access outcomes, but not directory role membership changes. It is the right table for detecting anomalous sign-ins or impossible travel. Role assignment auditing resides in AuditLogs, which captures the Add member to role operation.

  • ✗

    SecurityEvent

    Why it's wrong here

    SecurityEvent holds Windows and server security events forwarded by the Log Analytics agent, so it contains no Microsoft Entra ID directory role assignment records. It is the correct table for host-based detections such as suspicious process creation or account manipulation on servers, not for cloud identity role changes.

  • ✗

    CommonSecurityLog

    Why it's wrong here

    CommonSecurityLog ingests CEF-formatted events from third-party security appliances such as firewalls and intrusion detection systems, so it carries no Microsoft Entra ID role data. It is correct for correlating external device telemetry, not for detecting privileged role assignments, which AuditLogs records.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SOC analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect when a user account is added to a privileged role in Microsoft Entra ID. The analyst wants to correlate with the user's previous role assignments to identify potential privilege escalation. Which table should the analyst query?

medium
  • ✓ A.AuditLogs
  • B.SigninLogs
  • C.AzureActivity
  • D.SecurityEvent

Why A: The AuditLogs table in Microsoft Sentinel captures directory activity, including changes to privileged role assignments in Microsoft Entra ID (formerly Azure AD). By querying AuditLogs, the analyst can correlate the current role addition with historical role assignment events to detect potential privilege escalation. SigninLogs, AzureActivity, and SecurityEvent do not contain the specific role assignment audit data needed for this correlation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.