Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Audit in context, with comparison tables and the common traps.
Terms in this definition
- Append
Policy effect in Azure that inserts fields only while a resource is being created or updated; resources that already exist are not corrected by it.
- Activity log
Record, held for 90 days, of control-plane operations in a subscription such as deployments and Policy events. Data-plane actions, Key Vault reads for example, are not captured.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
Related terms
- 10-Year Audit Log Retention
An add-on licence assigned per user that lets audit records be kept for a decade. The user also needs Audit (Premium) and a retention policy covering those records, and older records are not extended retroactively.
- A5
The highest Microsoft 365 plan for education, equivalent to E5 for schools and universities. It includes premium Purview and Defender capabilities, for example Endpoint DLP, Audit (Premium), Insider Risk Management and the premium eDiscovery features.
- Advanced Audit Policy Configuration
Holds fine-grained audit subcategories (Audit Credential Validation, for instance) in Group Policy, superseding the nine basic categories.
- Apply and Monitor
An assignment mode in Azure Machine Configuration that applies settings a single time and afterwards just reports drift. Audit only reports, while Apply and Autocorrect fixes drift too.
- Audit action group
Named bundle of database-engine events, BATCH_COMPLETED_GROUP being one, selected when defining an audit policy. By default Azure SQL audits BATCH_COMPLETED_GROUP together with successful and failed database authentication.
- Audit log retention policy
Lets an organisation decide how long particular audit records survive, filtered by user, activity or service: between 7 days and 1 year as standard, or 3, 5, 7 or 10 years with the 10-Year add-on. It is an Audit (Premium) feature; up to 50 can exist, and they win over the default policy.
- Audit log system table
Databricks recommends this over exporting diagnostic logs:
system.access.audit, a Public Preview system table holding audit events from the account's workspaces in a region, retained free for 365 days. - AUDIT_CHANGE_GROUP
Fires when someone creates, alters or drops an audit or audit specification, so it captures changes to the auditing setup itself; logins and queries are covered by other action groups.