Skip to content
Summa Lai
Never Stop Learning, Building a Little Wiki…
Life is like riding a bicycle. To keep your balance, you must keep moving. But DON'T move too fast.
  • Home
  • Apple
  • Cloud
  • Linux
  • Microsoft
  • Networks
  • Solutions
  • TOOLS
  • Log In
  • About Me

How to Monitor Sign-in of Emergency Access Accounts in Microsoft Entra ID

Posted on March 8, 2024March 8, 2024 by Summa Lai

Quick Reference:

Monitor sign-in and audit logs

Organizations should monitor sign-in and audit log activity from the emergency accounts and trigger notifications to other administrators. When you monitor the activity on break glass accounts, you can verify these accounts are only used for testing or actual emergencies. You can use Azure Log Analytics to monitor the sign-in logs and trigger email and SMS alerts to your admins whenever break glass accounts sign in.

Obtain Object IDs of the break glass accounts

  1. Sign in to the Microsoft Entra admin center as at least a User Administrator.
  2. Browse to Identity > Users > All users.
  3. Search for the break-glass account and select the user’s name.
  4. Copy and save the Object ID attribute so that you can use it later.
  5. Repeat previous steps for second break-glass account.

Create an alert rule

  1. Sign in to the Azure portal as at least a Monitoring Contributor.
  2. Browse to Monitor > Log Analytics workspaces.
  3. Select a workspace.
  4. In your workspace, select Alerts > New alert rule.
  5. Under Resource, verify that the subscription is the one with which you want to associate the alert rule.
  6. Under Condition, select Add.
  7. Select Custom log search under Signal name.
  8. Under Search query, enter the following query, inserting the object IDs of the two break glass accounts. NoteFor each additional break glass account you want to include, add another “or UserId == “ObjectGuid”” to the
  9. query.Sample queries:

// Search for a single Object ID (UserID)
SigninLogs
| project UserId
| where UserId == “f66e7317-2ad4-41e9-8238-3acf413f7448”

// Search for multiple Object IDs (UserIds)
SigninLogs
| project UserId
| where UserId == “f66e7317-2ad4-41e9-8238-3acf413f7448” or UserId == “0383eb26-1cbc-4be7-97fd-e8a0d8f4e62b”

// Search for a single UserPrincipalName
SigninLogs
| project UserPrincipalName
| where UserPrincipalName == “[email protected]”

  1. Under Alert logic, enter the following:
    • Based on: Number of results
    • Operator: Greater than
    • Threshold value: 0
  2. Under Evaluated based on, select the Period (in minutes) for how long you want the query to run, and the Frequency (in minutes) for how often you want the query to run. The frequency should be less than or equal to the period.alert logic
  3. Select Done. You may now view the estimated monthly cost of this alert.
  4. Select an action group of users to be notified by the alert. If you want to create one, see Create an action group.
  5. To customize the email notification sent to the members of the action group, select actions under Customize Actions.
  6. Under Alert Details, specify the alert rule name and add an optional description.
  7. Set the Severity level of the event. We recommend that you set it to Critical(Sev 0).
  8. Under Enable rule upon creation, leave it set as yes.
  9. To turn off alerts for a while, select the Suppress Alerts check box and enter the wait duration before alerting again, and then select Save.
  10. Click Create alert rule.

Create an action group

  1. Select Create an action group.create an action group for notification actions
  2. Enter the action group name and a short name.
  3. Verify the subscription and resource group.
  4. Under action type, select Email/SMS/Push/Voice.
  5. Enter an action name such as Notify Global Administrator.
  6. Select the Action Type as Email/SMS/Push/Voice.
  7. Select Edit details to select the notification methods you want to configure and enter the required contact information, and then select Ok to save the details.
  8. Add any additional actions you want to trigger.
  9. Select OK.

Ref: Manage emergency access admin accounts – Microsoft Entra ID | Microsoft Learn

Posted in Azure, Cloud, Microsoft 365, Microsoft Family Tagged Monitor Sign-in of Emergency Access Accounts in Microsoft Entra ID

Post navigation

← How to Change Default Permissions of /var/log on Linux
How to Log Messages from a Remote Host to a Specific File in Rsyslog →

Categories

  • About Me (1)
  • Apple (24)
    • Apple Devices (18)
    • iCloud (3)
    • Mac OS (7)
  • Certifications (21)
    • CCNP (21)
    • CompTIA A+ (2)
    • CompTIA Network+ (9)
  • Cloud (80)
    • AWS (2)
    • CloudFlare (2)
    • Google Cloud (19)
    • JumpCloud (1)
    • Microsoft 365 (49)
    • Oracle (1)
    • RADIUS (2)
  • Linux Family (57)
    • Apache (20)
    • CentOS (23)
    • PHP (3)
    • Putty / WinSCP (1)
    • Shopify (2)
    • WordPress (18)
  • Microsoft Family (537)
    • Autopilot / Intune (52)
    • Azure (94)
    • Compliance Portal (3)
    • Dymanic (2)
    • Exchange (13)
    • Hyper-V (1)
    • Microsoft Defender (6)
    • Microsoft Office (172)
    • Power BI (94)
    • PowerShell (15)
    • SQL (20)
    • Surface (3)
    • Teams / SharePoint (20)
    • Windows 7/8/10/11 (133)
    • Windows Servers (70)
  • Networks (122)
    • Adobe (1)
    • Darktrace (2)
    • Firewalls (21)
    • Google (12)
    • Hardware (21)
    • Meraki (1)
    • Mobile phones (5)
    • NordLayer (1)
    • Others (24)
    • Palo Alto (11)
    • Phones (1)
    • Router/Switch (26)
    • Ubiquiti (1)
    • Wi-Fi (9)
  • Oversea Living (26)
  • Solutions (50)
    • 1Password (2)
    • Adobe (2)
    • BI and Reporting (5)
    • eCommerce (8)
    • Forensics / Investigation (1)
    • Google Workspace (4)
    • IT Management (2)
    • KnowBe4 (1)
    • Password Management (5)
    • Project Management (2)
    • QuickBooks (1)
    • Sage (3)
  • Tools (15)
    • Atera (2)
    • Chocolatey (1)
    • Google (4)
    • PatchMyPC (3)
  • Travels (2)
  • Uncategorized (13)
  • VMware (2)

Recent Posts

  • How to Insert a Table of Contents with Office 365 June 19, 2025
  • Password Expiration Notification for Microsoft 365 Users May 1, 2025
  • How to Fix “Your organization does not allow external forwarding.” Microsoft 365 April 9, 2025
  • How to Check the Windows 11 Version and Build March 25, 2025
  • How to Remove Previously Granted Access to a User’s OneDrive February 13, 2025
  • How to Create a Milestone with Project for The Web February 4, 2025
  • How To Convert a .CRT Certificate into a .PEM or .PFX Format January 6, 2025
  • How to Deploy 1Password SCIM Bridge on Azure Container Apps January 2, 2025
  • How to Send Email Notifications When PING Fails December 14, 2024
  • How to Fix “We Couldn’t Update the System Reserved Partition” Error on Windows 10/11 December 9, 2024

Recent Comments

  • buy CBD on SUMMA LAI – NEVER STOP LEARNING

Archives

  • June 2025 (1)
  • May 2025 (1)
  • April 2025 (1)
  • March 2025 (1)
  • February 2025 (2)
  • January 2025 (2)
  • December 2024 (2)
  • November 2024 (3)
  • October 2024 (4)
  • September 2024 (3)
  • August 2024 (7)
  • July 2024 (7)
  • June 2024 (4)
  • May 2024 (4)
  • April 2024 (1)
  • March 2024 (5)
  • February 2024 (7)
  • January 2024 (12)
  • December 2023 (7)
  • November 2023 (11)
  • October 2023 (8)
  • September 2023 (8)
  • August 2023 (6)
  • July 2023 (12)
  • June 2023 (15)
  • May 2023 (17)
  • April 2023 (18)
  • March 2023 (14)
  • February 2023 (17)
  • January 2023 (21)
  • December 2022 (17)
  • November 2022 (20)
  • October 2022 (18)
  • September 2022 (17)
  • August 2022 (17)
  • July 2022 (17)
  • June 2022 (18)
  • May 2022 (12)
  • March 2022 (11)
  • February 2022 (18)
  • January 2022 (22)
  • December 2021 (26)
  • November 2021 (22)
  • October 2021 (23)
  • September 2021 (24)
  • August 2021 (12)
  • July 2021 (14)
  • June 2021 (20)
  • May 2021 (23)
  • April 2021 (28)
  • March 2021 (24)
  • February 2021 (27)
  • January 2021 (28)
  • December 2020 (31)
  • November 2020 (13)
  • October 2020 (4)
  • September 2020 (3)
  • August 2020 (7)
  • July 2020 (23)
  • June 2020 (24)
  • May 2020 (21)
Copyright 2024, Privacy Policy
  • SUMMA LAI – NEVER STOP LEARNING