Logs
The diary of what happened. Who signed in, from where, and who changed a setting. ITDR reads this diary to know what is going on.
Plain-English guide
Your Microsoft license decides how much ITDR is allowed to watch. This page explains, in everyday words, what you get with each license — Entra Free, Business Premium, E3, E5, Entra P1, and Entra P2 — for logs, detections, alerts, and risk.
Last reviewed
June 10, 2026
Want the precise, technical version with API names and warning signals? See the license coverage matrix.
Read this first
Microsoft licenses are like the wristband you get at the gate. The wristband decides which rides you are allowed on. ITDR is the security team watching the cameras — but Microsoft only lets us watch the camera feeds your wristband includes. A bigger wristband (a higher license) means more cameras, sharper footage, and Microsoft's own guards handing us tip-offs. ITDR is the same product for everyone; the wristband just decides how much we are allowed to see.
The four building blocks
The diary of what happened. Who signed in, from where, and who changed a setting. ITDR reads this diary to know what is going on.
The rules that read the diary and shout "that looks wrong." Example: the same person "signs in" from two countries ten minutes apart.
The sticky note a detection leaves for your team: "Check this — it might be an attacker." Some alerts come from Microsoft itself (Defender).
Microsoft's own opinion about how dangerous a sign-in or user looks. It is a bonus signal we mix in — but Microsoft only shares it on higher licenses.
The chain runs left to right: logs feed detections, detections raise alerts, and Microsoft's risk score makes those alerts smarter. Your license decides how much of each Microsoft will share.
At a glance
| What ITDR can do | Entra Free | Entra P1 (Business Premium / E3) | Entra P2 (E5) |
|---|---|---|---|
Identity inventory A list of your users, devices, and apps. | Yes | Yes | Yes |
Directory change logs Who changed a role, a group, or a password setting. | Limited | Yes | Yes |
Sign-in logs Who logged in, from where, on what device. The backbone of ITDR. | No | Yes | Yes |
Mailbox & file activity Sneaky inbox rules, forwarding, odd file access (needs Microsoft 365 apps). | Depends | Depends | Yes |
Microsoft's risk score Microsoft flags a sign-in as "risky" and tells us why. | No | Limited | Yes |
Risky users list Microsoft's ranked list of accounts it thinks are compromised. | No | No | Yes |
Defender alerts & incidents Ready-made alerts from Microsoft Defender, pulled into one place. | No | Depends | Yes |
Containment actions Disable an account, kick out active sessions, remove from a group. | Yes | Yes | Yes |
Depends means it is not about the Entra tier — it needs your Microsoft 365 apps (Exchange, SharePoint) with audit turned on. Limited means it works, but Microsoft hides some detail until a higher license.
Real customer scenarios
"I only have Entra ID Free."
Entra ID Free — the default that comes with any Microsoft 365 subscription.
What ITDR can watch
We can see your users, devices, and apps, and read directory change logs (kept ~7 days). But Microsoft does not let Free tenants stream sign-in logs to us, and there is no risk data.
What you get
What you don't get
Bottom line: Works, but thin. Sign-in telemetry is the heart of identity threat detection, so Free leaves most detections dark. The single best upgrade is anything that includes Entra P1.
"I have Microsoft 365 Business Premium."
Business Premium quietly includes Entra ID P1 and the Microsoft 365 apps (Exchange, SharePoint).
What ITDR can watch
This is the sweet spot for small/mid customers. We get sign-in logs and directory logs (kept ~30 days), plus mailbox and file activity once Microsoft 365 audit is on.
What you get
What you don't get
Bottom line: Strong, practical coverage. Most of what people picture when they say "identity threat detection" works here.
"I have Microsoft 365 E3."
E3 also includes Entra ID P1 plus the Microsoft 365 apps — for ITDR it behaves like Business Premium.
What ITDR can watch
Same as Business Premium: sign-in logs, directory logs (30 days), and mailbox/file activity with audit on.
What you get
What you don't get
Bottom line: Solid. The only thing standing between E3 and "everything" is the P2 / Defender depth that comes with E5.
"I have Microsoft 365 E5."
E5 includes Entra ID P2 and Microsoft Defender — the top tier.
What ITDR can watch
Everything. Sign-in and directory logs, mailbox/file activity, full Microsoft risk detail, and ready-made Defender alerts and incidents.
What you get
What you don't get
Bottom line: Best case. ITDR runs at full strength.
"I have Entra ID P1 (on its own)."
Standalone Entra P1 — the identity license without the Microsoft 365 apps necessarily attached.
What ITDR can watch
Sign-in logs and directory logs (30 days) plus a basic risk signal. Mailbox/file detections only if you also have Exchange/SharePoint with audit on.
What you get
What you don't get
Bottom line: A genuinely useful minimum. P1 is the line where ITDR goes from "barely watching" to "actually detecting."
"I have Entra ID P2 (on its own)."
Standalone Entra P2 — top identity license, but not automatically the Microsoft 365 apps.
What ITDR can watch
All the identity signals: sign-in logs, directory logs, full risk detail, and the risky-users list. Mailbox/file detections still depend on having Microsoft 365 apps with audit on.
What you get
What you don't get
Bottom line: Top-tier identity coverage. Pair it with Microsoft 365 apps to also unlock the mailbox lane.
So what is the minimum?
Official Microsoft references