Azure Activity Log: Auditing All Changes to Azure Resources
Which Azure governance tool provides a way to audit all changes made to resources in your Azure subscription?
Quick Answer
The answer is the Azure Activity Log, which is the correct governance tool for auditing all changes to Azure resources because it captures every control-plane operation—such as creating, updating, or deleting resources—across your subscription. This log records the who, what, when, where, and how of each change, providing a complete audit trail for security and compliance. On the AZ-900 exam, this concept tests your understanding of Azure’s monitoring and governance services, often appearing in questions that contrast the Activity Log with Azure Monitor metrics or diagnostic logs. A common trap is confusing it with Azure Resource Manager templates or Azure Policy, but remember: the Activity Log is purely for auditing management-plane actions, not for enforcing rules or deploying resources. To recall this easily, think “Activity Log = Action Log”—it logs every administrative action taken on your resources.
⚠ Common exam trap
It's easy for candidates to confuse Azure Monitor Metrics (which tracks performance data) with the Activity Log (which tracks configuration changes), because both are part of Azure Monitor but serve fundamentally different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Activity Log
The Azure Activity Log is the correct tool because it provides a complete audit trail of all control-plane operations (management-plane actions) performed on resources in an Azure subscription. Every create, update, delete, and other write operation (PUT, POST, DELETE) is logged, enabling you to answer 'who, what, when, where, and how' for any change. This makes it the primary governance tool for auditing resource modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Monitor Metrics
Why it's wrong here
Metrics capture numeric performance time series such as CPU and requests, not who changed a resource or when. It is tempting because it records activity over time, and would be correct for charting utilisation thresholds and triggering alerts.
- ✓
Azure Activity Log
Why this is correct
The Azure Activity Log records subscription-level control-plane operations, capturing who performed which create, update or delete action on resources, with timestamps and caller identity. This satisfies the audit requirement by providing a queryable history of all resource changes across the subscription.
- ✗
Azure Application Insights
Why it's wrong here
Application Insights is an APM service collecting telemetry, request traces and performance metrics from running applications; it does not record control-plane operations on Azure resources. It is tempting because it audits application behaviour, but the tool that logs resource changes is Azure Activity Log, which captures subscription-level write operations.
- ✗
Azure Resource Health
Why it's wrong here
Resource Health reports current and historical service availability and degradation per resource, not configuration change history. It is tempting as a monitoring surface, and would be correct when checking whether a resource is experiencing a platform outage.
Go deeper
Related to this question
Learn chapter
Azure Resource Locks and Tags
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
Key term
Azure subscription
An Azure subscription is a logical container in Microsoft Azure that provides billing isolation and access boundaries for your cloud resources and services.
About these practice questions
One of 983 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which Azure feature creates an audit trail showing who performed what actions on Azure resources and when?
medium- A.Azure Monitor Metrics
- ✓ B.Azure Activity Log
- C.Azure AD Sign-in logs
- D.Azure Network Watcher packet captures
Why B: The Azure Activity Log is a platform log in Azure that provides insight into subscription-level events, recording all control-plane operations (e.g., creating a VM, deleting a resource group) with details on who performed the action (via Azure AD principal), what the action was, and when it occurred. This makes it the correct feature for creating an audit trail of resource management actions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.