Enterprise Identity & Access Management Platform  ·  View 22 of 27  ·  Operations

Identity Observability & Detection

Seven signal families, and what each one causes to happen.

Editable source SVG draw.io All views
Emit
Emit
Collect
Collect
Store
Store
Detect
Detect
Act
Act
Authentication
Authentication
Sign-in logs
2.6M/day
Sign-in logs...
Diagnostic setting
Diagnostic setting
Log Analytics 90 d
Log Analytics 90 d
Impossible travel, MFA fatigue
Impossible travel, MFA fatigue
Sentinel incident to SOC
Sentinel incident to SOC
Directory change
Directory change
Audit logs
every write
Audit logs...
Diagnostic setting
Diagnostic setting
LAW + 7-year archive
LAW + 7-year archive
Role assigned outside IaC
Role assigned outside IaC
Auto-revert, page IAM
Auto-revert, page IAM
Privileged access
Privileged access
PIM activation events
PIM activation events
Diagnostic setting
Diagnostic setting
Evidence archive
Evidence archive
Activation without ticket
Activation without ticket
Weekly approver review
Weekly approver review
Workload identity
Workload identity
SP sign-ins, MI usage
SP sign-ins, MI usage
Diagnostic setting
Diagnostic setting
Log Analytics
Log Analytics
New IP or ASN for an SP
New IP or ASN for an SP
CA block, rotate credential
CA block, rotate credential
Secrets
Secrets
Key Vault data-plane log
Key Vault data-plane log
Diagnostic setting
Diagnostic setting
LAW + archive
LAW + archive
Bulk read, unusual principal
Bulk read, unusual principal
Disable version, rotate
Disable version, rotate
Entitlement
Entitlement
Provisioning + review logs
Provisioning + review logs
Graph scheduled export
Graph scheduled export
Governance store
Governance store
Dormant 60 days, orphaned
Dormant 60 days, orphaned
Auto-remove, notify owner
Auto-remove, notify owner
Posture
Posture
Defender for Cloud, CIEM
Defender for Cloud, CIEM
Continuous assessment
Continuous assessment
Defender workspace
Defender workspace
Permission creep score
Permission creep score
Right-size in next sprint
Right-size in next sprint
Identity Observability & Detection
Identity Observability & Detection
The matrix exists to make gaps visible. Every row must reach the Act column: a signal that is collected and stored but never acted on is cost without control, and three of these rows were exactly that before this design.
The matrix exists to make gaps visible. Every row must reach the Act column: a signal that is collected and stored but never acted on is cost without control, and three of these rows were exactly that before this design.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

Why a matrix

  • Rows are signal families, columns are the stages every signal passes through. The matrix makes gaps visible where a flow diagram hides them.
  • Every row must reach the Act column. A signal collected and stored but never acted on is cost without control, and three of these rows were exactly that before this design.
  • Detection is defined alongside the signal, not after an incident. Each of the 27 Sentinel rules names its response and its owner.

What gets someone woken up

  • Break-glass sign-in and role assignment made outside the IaC pipeline are P1, paging the IAM on-call immediately.
  • PIM activation without a ticket reference and a service principal signing in from a new ASN are P2, reviewed within the working day.
  • Dormant entitlement and permission-creep findings are backlog items with an owner, not alerts. Paging on posture drift trains people to ignore pages.

Cost and gaps

  • 240 GB per day, of which sign-in logs are roughly 70%. Non-interactive sign-ins go to the basic tier and archive; only summaries reach the analytics tier.
  • Per-application SCIM provisioning health has no dedicated alert today. It is an open item, and the visible gap is why it is on this page.
  • Sentinel commitment tier is sized on analytics-tier ingest only, so it must be re-checked whenever the log split changes.