logo

Challenges in Azure Log Monitoring: Insights for Your SOC by Dmitriy Beryoza

ID: a960c9ca-02fe-565f-b4d7-5b052558f1e9

STIX ID: report--a960c9ca-02fe-565f-b4d7-5b052558f1e9

Feed Name: Vectra AI Blog

Date Published: 2023-10-31

Date Updated: 2026-05-01

...
...

This report analyzes systemic weaknesses in Microsoft cloud logging across Entra ID (Azure AD), Microsoft 365, and Azure resources that impede detection and response, including outages and ingestion delays, paywalled telemetry ("logging tax"), unlogged reconnaissance, inconsistent IDs/IPs/geolocation/device data, schema drift, missing and broken events, and unannounced changes. It describes how these issues create investigation blind spots and enable attacker evasion, and recommends that defenders continuously verify log flow and completeness, craft resilient queries favoring stable identifiers, and press vendors for timely, consistent, and well-documented telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.