I recently noticed that the Office 365 integration is no longer syncing Azure AD Login Events for a few different USM Anywhere deployments. Looking at the job scheduler, I'm seeing the below entry whenever the scan is run:
ScanOffice365AuditAzureActiveDirectory This job (ScanOffice365AuditAzureActiveDirectory) was already running.
As opposed to the successful entries for other Office 365 scans:
ScanOffice365AuditExchange This job (ScanOffice365AuditExchange) has finished: Audit Exchange Events collected successfully: 0 events processed
The Azure Active Directory audit seems to have started failing on 9/24/2018. I'm inclined to think a change to the Azure API is the culprit, so I have a ticket open with Microsoft. Has anyone else experienced this?