HI everyone,
I need to check my logs to see if a user has MFA enabled or not. I've already configured Microsoft Azure App for Splunk, as all the other data is coming through. Additionally, I can see 'azure:monitor:aad' logs. Can someone help me understand what changes need to be made on the Azure side to be able to view these logs?
Thank you in advance.
Hi @toporagno , did you find a solution? I am looking for answers for the same case.