Search code examples

How to hook Log Analytics / Azure Monitor into role assignments?

Is there a way to hook Log Analytics or Azure Monitor into Role Assignments in order to capture when a new user/service principal/group is added to a Role for any resource within a tenant?

I'm looking for a log to tie alerts to. Something with a human readable DisplayName for both the user/sp/group and the resource its applied to.


  • Bob Smith was assigned Contributor role to Storage Account stg123 in Resource Group rgabc


  • What @Satya provided, azure portal has activity logs and it is the most easy way to query role assignments in azure, and as @ericOnline said above, azure monitor also provides similar feature.

    See details in :

    enter image description here

    enter image description here