In order to use the Log monitoring feature, you need to configure a Log Monitoring app registration within your Entra ID. This app is used to gain access to the Microsoft Graph API of the protected tenants. All access tokens are stored within your Entra ID tenant / DSCM Enterprise solution.
Create the App
- Go to the Azure Portal and navigate to the Entra ID tenant.
- Navigate to the “App registrations” section.
- Click on “New registration”.
- Fill in the required fields:
- Name:
didsomeoneclone.me Log Monitoring App
- Supported account types:
Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant)
- Name:
- Click on “Register”.
- Click on “Add a Redirect URI”
- Click on “Add a platform”
- Click on “Web”
- Fill in the required fields:
- Redirect URI:
https://dscm-api-<YOUR_AZURE_APP_NAME>.azurewebsites.net/m365_logmon_auth
- Redirect URI:
- Click on “Configure”
- Click on “Add URI”
- Fill in the required fields:
- Redirect URI:
https://dscm-api-<YOUR_AZURE_APP_NAME>.azurewebsites.net/m365_logmon_mitigate
- Redirect URI:
- Click on “Save”
- Click on “API permissions”
- Click on “Add a permission”
- Click on “Microsoft Graph”
- Click on “Delegated permissions”
- Click on “AuditLog.Read.All”
- Click on “Add permissions”
- Repeat step 15-19 for the following permissions:
- User.EnableDisableAccount.All
- User.RevokeSessions.All
- Click on “Certificates & secrets”
- Click on “New client secret”
- Fill in the required fields:
- Description:
didsomeoneclone.me Log Monitoring App
- Expires:
730 days (24 months)
- Description:
- Click on “Add”
- Copy the “Client secret” and “Client ID”.
Email the Client ID and Client Secret to [email protected]. We will enable Log Monitoring in your DSCM Enterprise solution.