User activity audit logs? #302
FreeFree13
started this conversation in
General
Replies: 1 comment
-
|
Hello Brian, EntraCP (or any claims provider for trusted auth) does not decide/control/change what the user identifier is. Regarding the audit of the requests, did you consider to parse the IIS logs and use the field |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello Yvan,
We are using EntraCP to authenticate against our Sharepoint on premise infrastrucure and would like to retrieve some logs to address few use cases, per example:
_Detect big amount of data transfer / deletion
_Sharepoint access outside business hours
…
In all these use case, we need to identify users who initiate such actions.
However, since we configured federation with Entra CP for user authentication, we cannot clearly identify users in native SharePoint audit logs or ULS logs.
All we can see is a number or ID rather than username or UPN, this even cannot be translated because it doesn’t correspond to AAD user GUID.
Do you have any idea on how we can identify users in SharePoint logs when using EntraCP solution ?
Thank you so much in advance.
Best regards
Brian
Beta Was this translation helpful? Give feedback.
All reactions