entra1-7 Exercise 1: Which Log, Which Tab, Which Filter? ========================================================= Source: Microsoft Learn pages on sign-in logs, audit logs, provisioning logs, filtering and the sign-in log activity details. Re-check before relying on any detail; Microsoft renames tabs and fields. (a) User error page showing a correlation ID Log / tab: Sign-in logs. Start with Interactive user sign-ins, and also check Non-interactive if nothing appears. Filter: Correlation ID (paste the value from the error page). If it finds nothing, filter by User, Application and a narrow time. Microsoft cautions that the correlation ID is based on client parameters and isn't guaranteed accurate. Field to copy: Sign-in error code and Failure reason (plus the correlation ID itself). (b) Nightly import job (client secret, no user) stopped on Tuesday Log / tab: Sign-in logs > Service principal sign-ins. Filter: Application (or Application ID); Status = Failure; date range covering Tuesday. Field to copy: Sign-in error code (for example 7000222 = expired secret, 7000215 = invalid secret), Failure reason, date/time with the time zone, and the Resource. Why: No user is involved, so the interactive tab will show nothing. (c) Users asked to sign in again every hour, via your server's refresh Log / tab: Sign-in logs > Non-interactive user sign-ins (refresh-token and code redemption on a user's behalf are recorded there). Filter: User and Application; Status = Failure. Field to copy: Sign-in error code (for example 700082/70008 expired for inactivity, 50173 revoked grant, 70043 sign-in frequency), Failure reason, Conditional Access result. Also: Check the Conditional Access tab for a session policy. (d) Directory-to-product sync created some users but not others Log / tab: Provisioning logs (enterprise application > Provisioning logs); needs Entra ID P1/P2. Filter: Status = Failure or Skipped; Identity for a specific user; Action = Create. Field to copy: For a failed user: Troubleshooting & Recommendations tab (error code and reason), plus the Cycle ID and Change ID, which Microsoft says can be shared with product support. Also: "Skipped" can simply mean out of scope; it isn't always an error. (e) "Who changed the secret on your app, and when?" Log / tab: Audit logs (category ApplicationManagement). Filter: Activity = Update application - Certificates and secrets management; Target = the application; date range; read Initiated by. Field to copy: Date/time, Initiated by, Target, Status and the Correlation ID. Note: Only the tenant that owns the registration has this entry. If the registration is in the vendor's tenant (arrangement A), the client's audit log won't show it. WHY THIS WORKS AS AN ANSWER --- The pattern is: decide whether a person, an app-only job, a refresh or a change is involved, then pick the matching log and tab, narrow with one or two filters, and copy the error and identifiers.