SC‑300 Study Portal Path 5

Unit 8: Analyze Privileged Identity Management audit history and reports

Privileged Identity Management (PIM) provides built-in auditing and reporting to help organizations track how privileged access is used. These audit capabilities are essential for security monitoring, investigations, and compliance.

Using PIM audit history, administrators can:

Audit data is available for privileged access group members and owners within Microsoft Entra ID.

Important limitation to understand

If your organization uses Azure delegated resource management (for example, a managed service provider), then:

This is important for audit scope and compliance discussions.

Types of audit views in PIM

PIM provides two primary audit views for privileged access groups:

Audit typePurpose
Resource auditShows all activity related to a specific privileged access group
My auditShows activity related only to the signed-in user

Each view serves a different governance purpose.

View resource audit history

What is Resource audit?

Resource audit provides a centralized view of all actions performed on a privileged access group.

This includes:

This view is typically used by:

Steps: View resource audit history

The audit list updates based on the selected filter.

When to use Resource audit

Use Resource audit when you need to:

View personal audit history (My audit)

What is My audit?

My audit allows an individual user to view their own privileged activity within a privileged access group.

This view includes:

This view does not show other users’ actions.

Steps: View My audit

When to use My audit

Use My audit when you want to:

Governance and compliance value

PIM audit history supports:

Audit logs help answer key governance questions:

Exam-focused summary