Skip to main content

Standard Reference Tables & Views for the AzureADInventory Data Collector

The AzureADInventory Data Collector collects essential user and group inventory information into standard reference tables. Unlike other Access Analyzer data collectors, the AzureADInventory Data Collector writes data to these tables regardless of the job executing the query.

These tables and their associated views are outlined below:

TableDetails
SA_AzureADInventory_ContactsContains a list of principal identifiers and their corresponding Department and Job Title
SA_AzureADInventory_DomainsContains information about the domain such as last updated date and time
SA_AzureADInventory_EffectiveGroupMembersContains expanded group membership which includes a flattened representation of members and nesting levels
SA_AzureADInventory_ExceptionsContains information about security issues and concerns See the AzureADInventory Exception Types Translated section for an explanation of Exception Types
SA_AzureADInventory_ExceptionTypesContains more detailed information about each security issues and concerns See the AzureADInventory Exception Types Translated section for an explanation of Exception Types
SA_AzureADInventory_ExtendedAttributesContains information gathered by the custom attributes component of the query configuration
SA_AzureADInventory_GroupMembersContains a map of groups to member Identifiers
SA_AzureADInventory_GroupOwnersContains a map of groups to owner Identifiers
SA_AzureADInventory_GroupsContains extended information about groups, mail enabled, security enabled, and so on
SA_AzureADInventory_PrincipalsContains common attributes for users, groups, and computers as well as references to their primary display name and mail addresses
SA_AzureADInventory_UsersContains extended information about users, department, title, and so on

Views are the recommended way for you to obtain the information gathered by the AzureADInventory Data Collector. They contain additional information for building queries easily. The following is an explanation of the corresponding views created for some of the tables generated by the AzureADInventory Data Collector:

ViewsDetails
SA_AzureADInventory_EffectiveGroupMembersViewContains effective group membership information
SA_AzureADInventory_ExceptionsViewContains principals that are identified to have security concerns as well as detailed security concern information
SA_AzureADInventory_GroupMembersViewContains group membership information
SA_AzureADInventory_GroupOwnersViewContains group owner information
SA_AzureADInventory_GroupsViewContains group level information
SA_AzureADInventory_PrincipalsViewContains common attributes from the principals table including additional domain details
SA_AzureADInventory_UsersViewContains user information

AzureADInventory Exception Types Translated

The following table translates the Type of Exceptions that can found.

TypeExceptionDescription
1Large GroupsGroups with a large amount of effective members
2Deeply NestedGroups with deep levels of membership nesting
3Circular NestingGroups with circular references in their effective membership
4Empty GroupsGroups with no membership
5Single Member GroupsGroups with a single direct member
6Stale UsersUsers that have not logged onto the domain for an extended period of time
7Stale MembershipGroups with a high percentage of effective members that are stale users
8Large TokenUsers with a large amount of authorization groups in their token