| Azure Activity Log | Subscription control-plane create, update, delete, action, policy, security, and service-health events | Azure retains the log for a default period; export with diagnostic settings for longer retention and analytics | Make a benign resource change and query the actor, operation, scope, status, time, and correlation ID |
| Microsoft Entra sign-ins | Interactive, non-interactive, service-principal, managed-identity, risk, device, authentication, and Conditional Access context | Route required categories through Entra diagnostic settings; account for licensing and retention | Perform representative sign-ins and verify applied policy and authentication details |
| Microsoft Entra audit | User, group, application, role, authentication-method, policy, consent, and directory changes | Collect the categories required for investigation and protected audit history | Create a controlled directory change and correlate actor, target, and result |
| Resource logs | Service-specific data-plane, administrative, request, firewall, audit, and security events | Enable per resource or at scale with supported policy or data collection features | Generate a service event and confirm the correct resource-specific table or destination |
| Platform metrics | Performance, capacity, availability, errors, throttling, and service behavior | Select metrics that support security and operational use cases; configure alerts | Test threshold or dynamic alert routing |
| Defender for Cloud | Recommendations, attack paths, alerts, workload signals, vulnerability findings | Confirm plan coverage, connector, integration, notification, and export behavior | Trace a test or historical alert into the incident workflow |
| Network telemetry | Firewall, WAF, gateway, Front Door, Application Gateway, DNS, flow, and connection events | Choose supported current sources and retention; monitor product transitions | Perform an allowed and denied connection and locate both records |
| Guest operating systems | Security events, processes, authentication, EDR, syslog, application logs | Use Azure Monitor Agent and data collection rules or approved endpoint tooling | Confirm agent health, source computer, event time, and required fields |
| Applications and APIs | User activity, authorization, transactions, errors, fraud, sensitive actions, trace context | Instrument securely; avoid secrets and unnecessary personal data | Run a known transaction and correlate application, identity, and Azure events |
| Backup and recovery | Policy changes, protection stop, deletion, restore, vault security, jobs, alerts | Route critical changes and job status to accountable owners and security monitoring | Perform a controlled test or review a restore record end to end |