Sep 03 2020
- last edited on
Feb 19 2021
We have received an Azure activity logs in which the Operation Name is Delete role assignment and the Event initiated by is MS-PIM.
In which case the role is deleted by "MS-PIM" and what's the reason for deletion.
When we tried to fetch the logs through Log Analytics the Caller was some hexadecimal string, so is there a way to resolve that to the user name with log analytics query.