question

iraed91 avatar image
0 Votes"
iraed91 asked stan answered

Azure Monitor | Activity log vs Directory Logs

Dears,

I'm seeking your help to explain the difference between Activity log vs Directory Logs in Azure monitor. I was trying to spot the event of assigning global administrator role to somebody and was able to spot it with the help of this doc https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#view-elevate-access-logs

But now I need your help to understand the different types of events that might trigger under each category.

azure-monitorazure-ad-audit-logs
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

stan avatar image
0 Votes"
stan answered

Hi,
In general, there is no difference between them. Initially activity logs were only available at subscription scope so the activity logs were for resources at that scope and below. Later management groups were introduced and the activity logs for management groups. The activity logs for management groups apply only for resources at the management group scope selected. At Azure we also have one higher scope which is the Tenant scope. The resources which you can manage at that scope are limited but still you have activities that are logged for that scope. As in Azure Monitor blade you there is no way to select tenant scope they have introduced a drop down where you can select directory activity. When you select it you will notice that you no longer have option to filter on subscriptions or management groups. Basically, directory activities (tenant), the activity logs for management groups and the activity logs for subscriptions combined represent all activities happing at your Azure tenant on all levels. Scopes are probably most visible as concept in Azure template documentation.


Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.