2 Best Methods to Access Windows 365 Cloud PC Audit Logs
In this article, I will show you how to access Windows 365 Cloud PC audit logs. You can use PowerShell and the Graph API to get Windows 365 audit logs. The audit logs for Windows 365 keep track of what changed on a cloud PC because of an action.
For an Intune admin managing the cloud PCs, the Windows 365 audit logs are useful when you want to audit certain events on the cloud PCs. The audit logs are also useful when you would like to troubleshoot Cloud PC issues.
Create, update (edit), delete, assign, and remote actions all create audit events that administrators can review for most Cloud PC actions that go through Graph. By default, auditing is enabled for all customers using cloud PCs. It can’t be disabled.
http://www.chevrolet-club.com.ua/forum/viewtopic.php?f=7&t=43342
http://www.chevrolet-club.com.ua/forum/viewtopic.php?f=30&t=29477
http://www.chevrolet-club.com.ua/forum/viewtopic.php?f=30&t=29483
http://www.chevrolet-club.com.ua/forum/viewtopic.php?f=5&t=29524
http://roadragenz.com/forum/viewtopic.php?f=24&t=1395183
http://roadragenz.com/forum/viewtopic.php?f=24&t=1487404
http://roadragenz.com/forum/viewtopic.php?f=10&t=805322
https://39504.org/showthread.php?tid=1704
https://www.eclipse-gaming.de/forum/showthread.php?tid=4712
https://forum.shortcutgamez.com/showthread.php?tid=28500
http://libens.freehostia.com/viewtopic.php?p=645033
It doesn’t matter whether the device is a cloud PC or a Windows device managed with Intune, the audit logs will contain the log for every action initiated for the devices. The audit reports are available when you provision a Cloud PC or reprovision Cloud PCs.
Methods to access the Audit Logs for Cloud PCs
If you are looking to access the audit logs for Cloud PCs, there are two methods that you can use:
Method 1: Access the audit logs for Cloud PC from Intune Portal.
Method 2: Use Graph API and PowerShell to retrieve Windows 365 audit events.
The easiest method to access the Windows 365 audit logs is via the Intune portal. To get the Cloud PC audit data with the PowerShell and Graph API method, you will need to install the Microsoft Graph SDK. I will cover both methods to retrieve the Windows 365 audit events.
Who can access the Cloud PC Audit data?
In order to access the Cloud PC audit logs, the users require the following permissions:
- Global Administrator.
- Intune Service Administrator.
- Administrators assigned to an Intune role with Audit data – Read permissions.
Where can I find the Cloud PC Audit Logs?
The Cloud PC audit logs are located in Intune Portal and you can access the logs with following steps:
- Sign in to Microsoft Intune Portal.
- Navigate to Tenant Administration > Audit Logs.
- Here you’ll find all the audit logs related to Cloud PCs.
What details are available in Cloud PC Audit Logs
In the Intune portal, when you access the Cloud PC audit logs, there are multiple columns that you see. The following details are included for a Cloud PC audit log:
http://libens.freehostia.com/viewtopic.php?p=645252
https://www.aging2.com/blog/lets-talk-robot-caregivers/
http://nicolasmorenopsicologo.com/foro_psicologia/index.php/topic,56530.0.html
http://warhammer.world.free.fr/viewtopic.php?t=286
http://warhammer.world.free.fr/viewtopic.php?t=681
http://warhammer.world.free.fr/viewtopic.php?t=703
https://princeboiz.com/showthread.php?tid=4
http://fourmribh.v90.us/showthread.php?tid=5881
http://oakridgedaily.com/forum/showthread.php?tid=2592
http://9majigi.kr/bbs/board.php?bo_table=reservation&wr_id=1&me_code=4020
Date: The date and time of the activity.
Initiated by: The user account who initiated the action. It can be an admin or application who initiated the action. The initiated by (actor) reveals who initiated the action on Cloud PC.
Application name: The name of the application, for example, Microsoft Intune Portal extension.
Activity: The activity details show what action was performed on the Cloud PC. For example, if you have initiated a Cloud PC sync action, the activity “sync Device Managed Device” will be logged.
Target: The target is typically the component for which the activity was triggered. For example, the windowsDefenderScan Managed Device activity relates to target WindowsDefenderScan.
Category Details: This includes the category to which the audit logs belong to. The examples of categories include Device, Device Configuration, Software Updates, etc.
Status: The status column shows the status of the activity which is either “Success” or “Failed“.
Comments
Post a Comment