Skip to content

Entra ID

Entra ID

Hal reads identity activity from Microsoft Entra ID through Microsoft Graph, over read-only permissions. This is the feed behind most identity alerts — impossible travel, risky sign-ins, and MFA changes.

What’s collected:

  • Interactive and non-interactive sign-in logs
  • Risk detections from Entra ID Protection
  • Directory audit events — role changes, app consents, MFA registrations
  • The Conditional Access outcome on each sign-in

Polled every few minutes, retained 365 days.

Prerequisite: sign-in logs, directory audits, and Conditional Access outcomes need Entra ID P1 (or higher); risk detections require Entra ID P2. See Audit Logging Prerequisites.

Connect it: issued alongside Microsoft 365 in Getting Started — the same read-only app registration covers both.