Azure Monitor alerts

David Wrafter 41 Reputation points
2022-04-26T16:22:29.387+00:00

Hi

In a recent security BLOG Microsoft have advised alerts should be configured [in Azure tenancy] to prompt review on high-risk modification of tenant configuration, including but not limited to:

Modification of Azure AD roles and privileged users associated with those roles.
Modification of tenant-wide security configurations.

Can someone please provide me with some examples of the rules mentioned?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,783 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,381 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,491 Reputation points Microsoft Employee
    2022-04-26T16:37:02.773+00:00

    Azure monitor has built-in templates for Azure Activity alerts. You also have tools like Azure AD Identity Protection, Defender for Cloud, and Sentinel that can help to address this requirement. https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/activity-log-alerts

    0 comments No comments