The blind spot was the reconnaissance itself. Sign-in alerts and consent reviews miss the stage where tools quietly map a tenant, and that is the part Elastic can now see for Azure AD Graph traffic.
Elastic Security Labs says Azure AD Graph Activity Logs now ingest into Elastic with full ECS parsing through the Azure integration, and it published validated rules for spotting directory enumeration from tools like ROADrecon and AADInternals. The legacy graph.windows.net surface still returns tenant data in many environments, so this turns old directory sweeps into parsed events instead of invisible API calls.
For identity SOCs, the value is not a new threat. It is the first practical way to catch recon against a deprecated API before it turns into role abuse, consent abuse, or follow-on access.