| title | Audit Microsoft Defender for IoT user activity |
|---|---|
| description | Learn how to track and audit user activity across Microsoft Defender for IoT. |
| ms.date | 12/19/2023 |
| ms.topic | how-to |
After you've set up your user access for the Azure portal, on your OT network sensors, you'll want to be able to track and audit user activity across all of Microsoft Defender for IoT.
Use Microsoft Entra user auditing resources to audit Azure user activity across Defender for IoT. For more information, see:
Audit and track user activity on a sensor's Event timeline. The Event timeline displays events that occurred on the sensor, affected devices for each event, and the time and date that the event occurred.
Note
This procedure is supported for the default, privileged admin users and any user with an Admin role.
To use the sensor's Event Timeline:
-
Sign into the sensor console as the default, privileged admin users or any user with an Admin role.
-
On the sensor, select Event Timeline from the left-hand menu. Make sure that the filter is set to show User Operations.
For example:
:::image type="content" source="media/manage-users-sensor/track-user-activity.png" alt-text="Screenshot of the Event Timeline on the sensor showing user activity.":::
-
Use additional filters or search using CTRL+F to find the information of interest to you.
For more information on the event timeline, see Track network and sensor activity with the event timeline
For more information, see: