| name | cis-azure-foundations-6.1.1.10 |
| description | Ensure Intune logs are captured and sent to Log Analytics |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","logging","monitoring","intune","endpoint-management"] |
| cis_id | 6.1.1.10 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | ["cis-azure-foundations-6.1.1.9"] |
| prerequisites | [] |
| severity_boost | {} |
Ensure that Intune logs are captured and sent to Log Analytics
Description
Ensure that Intune logs are captured and fed into a central log analytics workspace.
Rationale
Intune includes built-in logs that provide information about your environments. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.
Impact
A Microsoft Intune plan is required to access Intune. The amount of data logged and, thus, the cost incurred can vary significantly depending on the tenant size.
Audit Procedure
Using Azure Portal
- Go to
Intune.
- Click
Reports.
- Under
Azure monitor, click Diagnostic settings.
- Next to each diagnostic setting, click
Edit setting, and review the selected log categories and destination details.
- Ensure that at least one diagnostic setting is configured to send the following logs to a Log Analytics workspace:
AuditLogs
OperationalLogs
DeviceComplianceOrg
Devices
Windows365AuditLogs
Expected Result
At least one Intune diagnostic setting should exist that sends AuditLogs, OperationalLogs, DeviceComplianceOrg, Devices, and Windows365AuditLogs to a Log Analytics workspace.
Remediation
Remediate from Azure Portal
- Go to
Intune.
- Click
Reports.
- Under
Azure monitor, click Diagnostic settings.
- Click
+ Add diagnostic setting.
- Provide a
Diagnostic setting name.
- Under
Logs > Categories, check the box next to each of the following logs:
AuditLogs
OperationalLogs
DeviceComplianceOrg
Devices
Windows365AuditLogs
- Under
Destination details, check the box next to Send to Log Analytics workspace.
- Select a .