Entra ID
Entra ID
Hal reads identity activity from Microsoft Entra ID through Microsoft Graph, over read-only permissions. This is the feed behind most identity alerts — impossible travel, risky sign-ins, and MFA changes.
What’s collected:
- Interactive and non-interactive sign-in logs
- Risk detections from Entra ID Protection
- Directory audit events — role changes, app consents, MFA registrations
- The Conditional Access outcome on each sign-in
Polled every few minutes, retained 365 days.
Prerequisite: sign-in logs, directory audits, and Conditional Access
outcomes need Entra ID P1 (or higher); risk detections require Entra ID
P2. See Audit Logging Prerequisites.
Connect it: issued alongside Microsoft 365 in Getting Started — the same read-only app registration covers both.