Azure Monitor | Activity log vs Directory Logs

R Alghamdi 21 Reputation points
2021-11-08T18:31:35.203+00:00

Dears,

I'm seeking your help to explain the difference between Activity log vs Directory Logs in Azure monitor. I was trying to spot the event of assigning global administrator role to somebody and was able to spot it with the help of this doc https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#view-elevate-access-logs

But now I need your help to understand the different types of events that might trigger under each category.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,826 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,662 questions
0 comments No comments
{count} votes

Accepted answer
  1. Stanislav Zhelyazkov 21,411 Reputation points MVP
    2021-11-09T07:49:49.767+00:00

    Hi,
    In general, there is no difference between them. Initially activity logs were only available at subscription scope so the activity logs were for resources at that scope and below. Later management groups were introduced and the activity logs for management groups. The activity logs for management groups apply only for resources at the management group scope selected. At Azure we also have one higher scope which is the Tenant scope. The resources which you can manage at that scope are limited but still you have activities that are logged for that scope. As in Azure Monitor blade you there is no way to select tenant scope they have introduced a drop down where you can select directory activity. When you select it you will notice that you no longer have option to filter on subscriptions or management groups. Basically, directory activities (tenant), the activity logs for management groups and the activity logs for subscriptions combined represent all activities happing at your Azure tenant on all levels. Scopes are probably most visible as concept in Azure template documentation.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful