Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst is investigating an incident in Microsoft Sentinel and needs to quickly identify all administrative activities performed by a specific user across all Azure subscriptions within the tenant. The analyst also needs to see if this user has made any changes to critical resources like network security groups or virtual machines. Which Kusto Query Language (KQL) table is the primary source for this type of information?

  1. AAzureActivity
  2. BSigninLogs
  3. CSecurityEvent
  4. DHeartbeat
Show answer & explanation

Correct answer: A. AzureActivity

The AzureActivity table contains all subscription-level events, including administrative operations performed on Azure resources. This is the primary source for tracking changes to resources and administrative actions across subscriptions.

Why the other options are wrong

  • B. SigninLogs contains Azure AD user sign-in activities, not administrative changes to Azure resources.
  • C. SecurityEvent contains Windows security event logs (e.g., successful/failed logins, process creation), not Azure resource activity.
  • D. Heartbeat records agent availability and connectivity, not user activity or resource changes.

KQL AzureActivity table

The AzureActivity table in Log Analytics (and thus Sentinel) contains events from the Azure Activity Log, which records control plane operations performed on Azure resources across subscriptions.

  • Tracks resource creation, update, deletion, and other management operations.
  • Provides 'who, what, when, and where' for Azure management events.
  • Crucial for auditing and security investigations of Azure resource changes.

Memory trick: Activity Always Audits Azure Actions

More Mitigate threats using Microsoft Sentinel questions