Oct 20 2023 12:33 PM
Are there logs within sentinel I can query to see when a new azure subscription is enabled? We recently had a user accidentally setup a new subscription and I was only able to see in the subscription activity log not in Sentinel.
Is there a data table where I can see this?
Thanks.
Oct 23 2023 02:45 AM
Hi @Porter76,
as far as I know, Microsoft Azure does provide the capability to monitor and track the creation of new Azure subscriptions but not with Sentinel rather using Log analytics and Azure Logic App.
Here is an interesting article how to achive that:
Monitoring for Azure Subscription Creation - Microsoft Community Hub
Azure Activity connector for Microsoft Sentinel | Microsoft Learn
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
(LinkedIn)
Oct 23 2023 02:45 AM