Emil Dosen
blog / projects / github
Back to blog
Microsoft365
  • Searching the Unified Audit Log by SharePoint or OneDrive URL
    How to use the ObjectId field in Microsoft Purview to filter audit log events by SharePoint or OneDrive URL.
  • Configuring Microsoft Sentinel with Entra ID and UEBA
    Step-by-step guide to setting up Microsoft Sentinel, connecting Entra ID logs, and enabling UEBA for behavioral anomaly detection.
  • Break-glass account login alerts
    Set up email alerts in Azure when a break-glass account signs in, using Log Analytics and KQL.
© 2026 Emil Dosen