Azure Monitor's reusable definition of contacts and automated responses for when an alert or budget fires. Contacts can be reached by email, SMS, push or voice; responses include webhooks, Functions, Logic Apps and Automation runbooks. Budgets alone can only send notifications.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Action group in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- Budget
A spending threshold you set in Cost Management for a management group, subscription or resource group. Alerts go out as real or forecast costs approach it, yet hitting the figure never halts any resource; wiring it to an action group lets automation react.
- SMS
Text-message verification, where a one-time code is sent to a phone for MFA, password reset or sign-in; Microsoft advises organisations to move to stronger options. Microsoft itself stops sending these texts and voice calls from 1 February 2027, or 1 July 2027 for Global Administrators and external users, so anyone still needing them must then bring a telephony provider.
- Real-time streaming semantic model
Covers live-fed push, streaming and PubNub models, plus streaming dashboard tiles. Microsoft now steers people towards Real-Time Intelligence in Fabric, as these are being retired and new ones can only be made until 31 October 2027.
- Logic Apps
Low-code Azure service for building automated workflows from triggers, actions and connectors, used for things like integrating systems or sending approval emails.
- Budgets
In Cost Management, spending limits you can scope and filter by tag, which raise alerts when actual or forecast spend nears or passes them.
Related terms
- Activity log alert
Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
- Email Azure Resource Manager role
Action group notification type: when an alert fires, it emails every user or group assigned the chosen subscription-level role, whether Monitoring Reader, Reader, Owner, Monitoring Contributor or Contributor.
- FAILED_LOGIN_GROUP
SQL Server audit action group, scoped to the server, that records failed logins to the instance. The recommended Azure SQL Database groups don't include it.
- Log search alert rule
When failed Databricks job runs pile up, for example, this kind of Azure Monitor rule can notice: it periodically evaluates a KQL query against Log Analytics and, if the condition holds, calls an action group.
- Secure Webhook
Calls an endpoint secured with Microsoft Entra ID from an Azure Monitor action group; basic authentication can't be used. It supersedes the IT Service Management Connector for BMC Helix and ServiceNow.
- Service Health alerts
When planned maintenance, a health advisory or a service issue hits one of your subscriptions, these activity log alerts fire an action group to contact you by SMS, email, push notification, webhook or Logic Apps.
- Smart detection
Machine learning in Application Insights that warns about unusual performance problems or failures with no setup required. Failure Anomalies alerts go to a default action group of the same name as the feature.
- Webhook
In an action group, an action that posts the alert payload to an HTTP endpoint; each subscription may make up to 1,500 such calls per minute.