跨租户导出Azure AD B2C审计日志至Azure存储账户问题
Alright, let's tackle this cross-tenant Azure AD B2C audit log export problem. I've run into this exact scenario before—here's how to get the user password resets, account creations, and other B2C-specific audit data into your main tenant's storage account:
1. First, Clear Up the Log Type Confusion
- Azure Activity Logs (what you set up on Tenant 1): These track resource-level operations (like creating a storage account) across your tenant, but they do NOT include Azure AD B2C user management actions (password resets, user creation). That's why your first setup didn't capture the data you need.
- Azure AD Audit Logs (in Tenant 2): This is the source that has the exact actions you're looking for. The catch is you can't directly export these to a storage account in another tenant via the native portal tool—so we need a workaround.
2. Option 1: Centralize with Azure Monitor Log Analytics (Scalable Approach)
This is the best long-term solution if you want to aggregate logs across multiple tenants:
- Step 1: Send Tenant 2's audit logs to a Log Analytics Workspace (LAW) in Tenant 2
- Navigate to your Azure AD B2C tenant in the portal → Audit logs → Diagnostic settings → Add diagnostic setting.
- Check the box for
AuditLogsunder the "Logs" section. - Select "Send to Log Analytics workspace" and choose an existing LAW in Tenant 2 (create one if you don't have it). Save the setting.
- Step 2: Grant Tenant 1 access to Tenant 2's LAW
- In Tenant 2's LAW, go to Access control (IAM) → Add role assignment.
- Assign the Log Analytics Reader role to a user or service principal from Tenant 1 that needs access to the logs.
- For broader access, set up cross-tenant Azure Monitor access: In Tenant 2's Azure Monitor, go to Cross-tenant access settings, add Tenant 1 as a trusted tenant, and enable access to the LAW.
- Step 3: (Optional) Export logs from LAW to Tenant 1's storage account
- If you need the logs stored directly in Tenant 1's storage, set up a Data Export rule in Tenant 2's LAW:
- Go to the LAW → Data exports → Add.
- Select the
AuditLogstable, set your export frequency, and specify Tenant 1's storage account as the target. - Critical: Grant the LAW's managed identity access to write to Tenant 1's storage account:
- In Tenant 1's storage account, go to IAM → Add role assignment for Storage Blob Data Contributor to the managed identity of Tenant 2's LAW.
- If you need the logs stored directly in Tenant 1's storage, set up a Data Export rule in Tenant 2's LAW:
3. Option 2: Custom Workflow with Azure Logic Apps
If you want more control over the log processing, use Logic Apps to pull logs from Tenant 2 and push them to Tenant 1's storage:
- Step 1: Build a Logic App in Tenant 2
- Start with a Recurrence trigger (e.g., run every hour to fetch recent logs).
- Add an Azure AD Audit Logs action to retrieve the latest logs. Use the
filterparameter to target only the actions you care about, like:OperationName eq 'Add user' or OperationName eq 'Change password'
- Step 2: Connect to Tenant 1's storage account
- Create a service principal in Tenant 1 and assign it the Storage Blob Data Contributor role on your target storage account.
- In the Logic App, add an Azure Blob Storage action, connect it using the Tenant 1 service principal, and configure it to upload the fetched log data as JSON or CSV files.
4. Key Pitfalls to Avoid
- Permissions Check: Always verify that cross-tenant identities (LAW managed identity, Logic App service principal) have the correct roles assigned. Test with a small batch of logs first to confirm access.
- Log Retention: Azure AD B2C audit logs are retained for 30 days by default. If you need longer retention, make sure your LAW or storage account is configured to keep logs beyond that window.
- Filter Early: Use filters in diagnostic settings or Logic Apps to only export the logs you need—this reduces storage costs and keeps your log data clean.
内容的提问来源于stack exchange,提问作者Stan B
相关产品推荐
相关产品推荐

