Skip to main content

Failed to Collect Logons — Forbidden Error in Entra ID Monitoring Plan

Symptom

The following error is prompted in Health Log for your Microsoft Entra ID monitoring plan (formerly Azure AD monitoring plan):

Source:Azure AD Audit Service
Event ID:2002
Computer: %Auditor_server_name%
User:N/A
Description:Monitoring Plan: %Azure_AD_monitoring_plan_name%

The following error has occurred while processing %tenant%:

Failed to collect Azure Logons audit data due to the following error: The remote server returned an error: (403) Forbidden.

Causes

  • App was incorrectly configured.
  • Admin consent was not granted to the Azure app.
  • API permissions were not granted neither manually, nor via the app manifest.
  • Logon activity collection is enabled without a purchased Premium Plan (P1 or P2) license for the Microsoft Entra ID tenant.

Resolutions

NOTE: Learn more about Microsoft Entra ID licenses in Sign up for Microsoft Entra ID P1 or P2 Editions ⸱ Microsoft: https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/get-started-premium