Search code examples
azurerolesazure-log-analyticsazure-monitoring

How to hook Log Analytics / Azure Monitor into role assignments?


Is there a way to hook Log Analytics or Azure Monitor into Role Assignments in order to capture when a new user/service principal/group is added to a Role for any resource within a tenant?

I'm looking for a log to tie alerts to. Something with a human readable DisplayName for both the user/sp/group and the resource its applied to.

Example:

  • Bob Smith was assigned Contributor role to Storage Account stg123 in Resource Group rgabc

Solution

  • What @Satya provided, azure portal has activity logs and it is the most easy way to query role assignments in azure, and as @ericOnline said above, azure monitor also provides similar feature.

    See details in : https://learn.microsoft.com/en-us/azure/role-based-access-control/change-history-report

    enter image description here

    enter image description here