azureloggingazure-active-directorytelemetrypii

Are Azure Subscription ID, AAD Tenant ID, and AAD App Client ID considered secret/PII?


I would like to log the following in my telemetry for diagnostic and usage purposes:

Should I treat them as secrets/PII and hash/encrypt them?

(it goes without saying I will not be retaining the client secret in any way shape or form)


Solution

  • Ultimately, you should determine what to log and how, from a compliance/privacy/security perspective, based on official and compliance/privacy/security reviews and certifications within your company or by 3rd parties.

    That disclaimer aside:

    Do note that some companies and privacy reviews often consider these 3 data points as Organization Identifiable Information (OII) and sometimes have policies for handling those (less stringent that PII though).