Key mappings worth memorising

The lookups people get wrong. Both tables are in the catalogue below with full detail and sample KQL.

A user’s job title, department or manager

IdentityInfo.JobTitle

Job title lives in IdentityInfo — the User and Entity Behavior Analytics (UEBA) identity enrichment table — in the JobTitle column, alongside Department, Manager, City, EmployeeId, AssignedRoles and GroupMembership. It is not in SigninLogs, and it is not in SecurityAlert; enrich by joining on AccountObjectId (or AccountUPN).

IdentityInfo is append-only snapshot data: take the newest row per identity with summarize arg_max(TimeGenerated, *) by AccountObjectId.

Who changed an attribute, and from what to what

AuditLogs → TargetResources[].modifiedProperties

Directory changes are in AuditLogs, not in the sign-in tables. Each record’s TargetResources array carries a modifiedProperties array whose elements have displayName, oldValue and newValue — the before/after pair for a role assignment, a JobTitle edit, a group membership change, an app credential being added, and so on.

oldValue and newValue arrive JSON-encoded (usually quoted strings), so strip the quotes or re-parse them: trim('"', tostring(mp.newValue)).

Search and filter the catalogue

Matches table names, aliases, plain-language concepts and column names. Press / to jump to this box, Esc to clear it, Enter or Space on a card to open details.

Filter by category

Table catalogue