Audit Logs - You do not have access

Erick Sanchez 20 Reputation points
2026-06-02T16:58:35.59+00:00

Got the following warning when trying to access the Audit log from Monitoring & Health menu.

{"sessionId":"37fe23bc011d4662b582ad7cfae70f4a","subscriptionId":"","resourceGroup":"","errorCode":"401","resourceName":"","details":"Error loading your content"}

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Rukmini 43,995 Reputation points Microsoft External Staff Moderator
2026-06-02T17:10:21.96+00:00

Hey Erick, that 401 (“Unauthorized”) message means you don’t currently have permission to load the audit data. A few things to check:

  1. Your Azure AD role • To view Entra Audit logs in the portal you need one of these directory roles: – Global Administrator – Security Administrator – Security Reader – Reports Reader • If you’re a guest user, you can’t view the tenant’s audit logs by default.
  2. Your license level • Audit logs in the Entra portal are available in all editions, but if you’re trying to surface Entra logs through Azure Monitor (or the Activity log in the Azure subscription blade), you must have at least an Entra ID P1 or P2 license.
  3. Where you’re looking • If you navigated to Azure Monitor > Activity log, you’ll only see logs for ARM resources. Entra audit logs live under Microsoft Entra (older “Azure Active Directory”) > Monitoring & Health > Audit logs.
  4. Diagnostic settings (only if your goal is to route logs into a Storage Account, Event Hub, or Log Analytics) • You must explicitly configure Diagnostic Settings on “Microsoft Entra ID” in the Azure portal. There is no backfill, so you’ll only see events after the setting was in place.

Next steps

• Verify your directory role and upgrade or request the needed role if you don’t have it.

• Confirm you’re in the Entra portal’s Audit logs blade versus the Azure Monitor Activity log.

• If you’re routing logs to Azure Monitor, make sure diagnostic settings are enabled on the “Microsoft Entra ID” resource.

Let me know:

• Which blade you clicked to get this error?

• What directory role and license you have?

• Whether you’re a “Member” or “Guest” in this tenant?

— Reference docs

• Audit log activities: https://learn.microsoft.com/entra/identity/monitoring-health/reference-audit-activities

• Entra logs in Azure Monitor troubleshooting: https://docs.microsoft.com/azure/active-directory/reports-monitoring/concept-activity-logs-azure-monitor

• Entra licensing and roles requirements: https://learn.microsoft.com/entra/fundamentals/get-started-premium

Note: This content was drafted with the help of an AI system. Please verify the information before relying on it for decision-making. Hello @Erick Sanchez ]

If the resolution was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.