@Techtester Microsoft.Authorization/policies/deny/action
is a type of Azure activity log event that is generated when an Azure Policy denies an action on a resource.
When a policy is assigned to a resource, it can have a "deny" effect that prevents certain actions from being performed on the resource. When an action is denied by a policy, an Azure activity log event is generated with the Microsoft.Authorization/policies/deny/action
event type.
This event type contains information about the policy that denied the action, the resource that the action was performed on, and the user or application that attempted to perform the action. This information can be used to monitor and audit policy compliance in your Azure environment.
You can try create an activity log alert for being notified whenever deny policy action takes place. On how to create activity log alert, you can refer this document.