Hi @JB306yxe
Thank you for asking this question on the **Microsoft Q&A Platform. **
You can send the events of the azure AD to a Log Analytic https://video2.skills-academy.com/en-us/azure/active-directory/reports-monitoring/howto-install-use-log-analytics-views
After that, you can set an alert with the occurrence of specifics events https://video2.skills-academy.com/en-us/azure/azure-monitor/alerts/alerts-log
Also, you can:
- Integrate Azure Active Directory logs with ArcSight using Azure Monitor https://video2.skills-academy.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-arcsight
- Integrate Azure Active Directory logs with Splunk using Azure Monitor https://video2.skills-academy.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-splunk
- Integrate Azure Active Directory logs with SumoLogic using Azure Monitor https://video2.skills-academy.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-sumologic
Hope this helps,
Carlos Solís Salazar
----------
Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.
NOTE: To answer you as quickly as possible, please mention me in your reply.