Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planEasy

A company is migrating its on-premises applications to Azure. They have a strict compliance requirement to audit all administrative actions performed on Azure resources, including who performed the action, when, and what changes were made. Which Azure service should be used to meet this auditing requirement?

  1. AAzure Monitor Activity Log
  2. BAzure Policy
  3. CAzure Advisor
  4. DAzure Security Center (now Defender for Cloud)
Show answer & explanation

Correct answer: A. Azure Monitor Activity Log

The Azure Monitor Activity Log (formerly Azure Audit Logs or Operational Logs) records all control-plane events on Azure subscriptions, including resource creation, updates, and deletions, along with who initiated the action and when. This directly fulfills the requirement for auditing administrative actions.

Why the other options are wrong

  • B. Azure Policy enforces organizational standards and assesses compliance, but it does not intrinsically log every administrative action taken on resources.
  • C. Azure Advisor provides personalized recommendations for best practices, not auditing of administrative actions.
  • D. Azure Security Center (Defender for Cloud) provides cloud security posture management and threat protection, but the Activity Log is the primary source for administrative action auditing.

Azure Monitor Activity Log

A log that records events that occur at the subscription level in Azure, detailing administrative operations on resources, service health events, and other control-plane actions.

  • Records who, what, and when for control-plane operations.
  • Essential for auditing and compliance.
  • Part of Azure Monitor.

Memory trick: To 'See Every Admin Step', check the Activity Log.

More Develop a security and compliance plan questions