Activity/Audit log for Azure Graph API used inside the Active Directory Application

Viewed 1830

Background: We have developed an Active Directory Enterprise Application. This application is developed to read free/busy information from the outlook calendar of a user in active directory. This application uses the Get Schedule Graph API to get the free/busy information of the user. The authentication mechanism is via admin consent.

Problem: We have a client who is going to use this application and install it in their active directory. They want to see on their side the activity/operations which are being performed by this application using the Graph API. I am not sure if it is possible to get activity performed by each installed application. I know there is a way to know who installed/authorized the actual application but beyond that I do not see a way on Azure portal to see the logs for each API call.

In short, the client wants to know each API call that the enterprise application is making and validate that it is not fetching data that is sensitive.

Appreciate any guidance here.

Update - 11/17/2020

After reaching out to Microsoft Support through various channels we finally got an answer mentioning that it is not possible to obtain the information that we are looking for. There is no way to audit the usage of graph APIs mentioned above.

Regards, Bhavik

2 Answers

At least from the perspective of Azure AD, Microsoft has not provided such tools or methods to accomplish this.

It appears that your client is very worried that a person from other tenants (for example, your tenant) will access their company's data through this enterprise application. I think your client does not understand how the enterprise app works.

When your enterprise application is installed into his tenant via admin consent, it means that they could use this enterprise application to access their own data within the scope of this application. But as the developer, you have no access to their data. Any other tenants who are using your enterprise application will also not able to access other tenants' data.

Multi-tenant app is used to offer a Software as a Service (SaaS) application to many organizations. Clients' data is accessed in their own tenant. Learn more information here.

Besides, the enterprise application should follow the "least privilege principle", so if your app is only assigned Calendars.Read based on Permissions, it won't be able to get data other than Calendars data.

You can secure the process by limiting the answers received from the graph api to the customer tenant only, with the token reply url. that way ,answers will only be accepted to requests made from the customer domain. regarding the auditing, it's not perfect but you can monitor http requests to the api address with curl or 3rd party tool , and log the relevant api requests. it will give them a sense of what going on behind the curtain.

Related