Skip to main content
So far we’ve covered how Microsoft Entra helps organizations manage identities, control access, and protect against security threats. Even in well-architected environments, users can encounter sign-in problems, denied access, or security incidents. Effective troubleshooting and monitoring are therefore essential parts of identity security operations. This lesson covers common identity-related issues, the investigative tools available, and how administrators monitor identity activity across Microsoft 365.

Common support scenario: signed in but cannot access a resource

A frequent support case is a user who successfully signs in but cannot access a resource. This can appear confusing because authentication succeeded — the user’s identity was verified — yet authorization fails.
A presentation slide titled "Troubleshooting and Monitoring Identity Security" showing a Microsoft sign-in error dialog that reads "You cannot access this right now" with a short explanation that the sign-in was successful but doesn't meet access criteria. The dialog also offers options like signing in with a different account and viewing more details.
Common causes for this scenario include Conditional Access policies, device compliance state, network or location restrictions, risk-based controls, or application-level permissions. For example, a user signing in from a personal device may complete authentication but be denied authorization because the organization requires a managed corporate device. Authentication vs. authorization — start here
  • Authentication = verifies who the user is.
  • Authorization = determines what the authenticated identity is allowed to access.
Authentication confirms who the user is. Authorization checks what the user is allowed to do. When sign-in succeeds but access fails, investigate authorization controls first (Conditional Access, device compliance, application permissions).

Two pillars of effective troubleshooting

  1. Technical knowledge — Know how identities, authentication flows, Conditional Access, device management, and application permissions interact.
  2. Active investigation — Use evidence from logs, policy configurations, and telemetry to find the root cause.
Think of troubleshooting like a clinician diagnosing a patient: deep domain knowledge is important, but diagnosis relies on observing symptoms and collecting evidence.

Tools for troubleshooting and monitoring identity security

Microsoft provides several complementary tools for investigation and continuous monitoring. Use them together to determine whether an access problem stems from identity configuration, device posture, application permissions, or a security incident. Where possible, correlate signals across these tools (for example, a blocked sign-in in Entra ID with a device risk alert from Defender for Endpoint) to rapidly identify root causes.

Third-party applications and governance

External apps connected to Microsoft 365 increase productivity but also introduce risk if they’re unmanaged or over-permissioned. Uncontrolled apps may request excessive scopes, store credentials insecurely, or access sensitive data without oversight.
A presentation slide titled "Troubleshooting and Monitoring Identity Security" showing an "Unmanaged Third-Party App" icon with a red alert badge. The app is flanked by two issues labeled "No oversight" and "Exposed credentials."
To reduce risk, register and govern applications in Microsoft Entra ID. Registration enables administrators to:
  • Control authentication methods and redirect URIs
  • Define and restrict permissions (apply least privilege)
  • Manage consent settings and require admin consent where appropriate
  • Apply Conditional Access or access reviews to application access
Unmanaged or poorly configured third-party apps are a common attack vector. Enforce app registration, review permissions regularly, and use app consent policies to limit exposure.

Application registration and secure integration flow

Registering applications in Entra ID ensures they follow organizational policies and apply governance from the start. Registered apps can be restricted to the minimum required permissions, authenticated securely, and included in Conditional Access rules or access reviews.
A slide titled "Troubleshooting and Monitoring Identity Security" showing a three-step flow: applications -> registered and governed in Microsoft Entra ID -> safely authenticate and integrate with M365. It illustrates that proper app registration lets apps authenticate and access data safely.
Best practices:
  • Register every production app in Entra ID.
  • Apply least privilege to scopes and API permissions.
  • Use managed identities or certificate-based authentication where possible.
  • Periodically review app permissions and consent history.

Summary — what to focus on for the exam and in practice

Identity security is more than signing users in. Administrators should:
  • Monitor and collect logs: sign-ins, audit events, provisioning logs, and device reports.
  • Investigate incidents using logs and telemetry from Entra ID, Intune, and Defender for Endpoint.
  • Secure device posture and verify compliance state.
  • Govern and periodically review third-party application access.
  • Continuously evaluate risk signals and Conditional Access outcomes.
For certification, emphasize understanding the role of each monitoring capability and how they work together to protect a Microsoft 365 environment.

Where to find relevant logs in the Entra portal

In the Microsoft Entra admin center you can access the primary logs and insights needed for troubleshooting:
  • Monitoring section: sign-in logs, audit logs, provisioning logs, and Conditional Access insights.
  • Sign-in logs: show who signed in, which application was used, IP address, resource, device information, and which Conditional Access policies were applied. Open a sign-in record to view location, device, authentication details, and policy evaluation results.
  • Audit logs: record administrative operations such as user or group changes and configuration updates.
A screenshot of the Microsoft Entra (Azure AD) admin center showing a list of recent sign-in events on the left. A right-hand Activity Details pane is open to the Conditional Access tab, showing a policy named "Non-FL-blocker" with a Block grant control.
Use these logs to determine why a sign-in or access attempt was blocked and which policy or condition caused the denial. When needed, correlate Entra logs with Intune device reports and Defender for Endpoint telemetry to complete the investigation. These resources provide detailed guidance and step-by-step instructions for locating logs, configuring Conditional Access, and integrating device and endpoint telemetry into your investigations.

Watch Video