Change Monitoring: Azure Activity Review
Overview
Change Monitoring in Spotto is an Azure activity review page for answering "what changed, who changed it, and did it line up with the incident?" It combines material changes, sensitive actions, failed events, and resource health signals across selected subscriptions so you can troubleshoot environment issues without starting from raw activity logs.
Use it when something broke, slowed down, became exposed, stopped updating, or started behaving strangely. The fastest first question is usually not "what is the root cause?" It is "what changed recently?"
Feature overview
Change Monitoring summarizes Azure activity logs into a focused investigation view:
- Material Changes: important configuration, resource, or operation changes.
- Sensitive Actions: credential, RBAC, networking, firewall, policy, and similar security-sensitive events.
- Health Events: Azure resource health changes that help correlate outages or degraded service.
- Failed Events: failed operations that may explain incomplete work or instability.
- Actor context: users, service principals, managed identities, Azure platform events, and unknown actors.
- Resource context: affected resource, resource group, resource type, subscription, operation, status, and event count.
Questions Change Monitoring answers
Use Change Monitoring when you need quick answers to operational and security investigation questions:
- What changed in this Azure environment recently?
- Who made the change: a user, service principal, managed identity, Azure platform event, or unknown actor?
- Which sensitive actions occurred, such as credential, RBAC, networking, firewall, or policy activity?
- Which operations failed and may explain incomplete updates or unstable services?
- Which resources, resource groups, and subscriptions were affected?
- Did a resource health event happen near the same time as the issue?
- Were noisy activity log events suppressed so the review stays focused?
This makes the page useful for Azure change monitoring, cloud troubleshooting, incident correlation, audit review, and "please tell me this was not a mystery change" conversations.
Why use this? (Jobs, pains, gains)
Jobs to be done
- When an incident starts, I want to see recent material changes, so I can quickly confirm whether a deployment, configuration change, or platform event lines up with the issue.
- When access or exposure looks wrong, I want to find sensitive actions, so I can review credential, RBAC, firewall, networking, and policy changes first.
- When a patch or update did not run cleanly, I want to find failed operations, so I can separate "planned work completed" from "planned work tried and failed".
- When I need accountability, I want to see the actor and actor type, so follow-up goes to the right user, automation owner, or platform team.
Common pains
- Azure activity logs are comprehensive, which is another way of saying "there is a lot of noise."
- The useful question is rarely "show me every event." It is "show me the events that matter for this problem."
- Security-sensitive changes are often mixed in with routine operations.
- Failed updates, health events, and user changes are easy to review separately and harder to correlate quickly.
What you gain
- A focused activity feed across selected subscriptions.
- Clear separation between Change, Security, and Health event types.
- Importance labels (High, Medium, Low) with text labels, not just color.
- Actor filters for Users, Automation, Azure Platform, and Unknown.
- Breakdowns by actor, operation, and resource group for fast pattern recognition.
- CSV export for incident notes, change review, and audit follow-up.
Turn the evidence into a decision
Select the labelled briefcase Business Value button beside Notes. The brief combines live material, security-sensitive, failed-change, and actor facts with an owned response decision.
Live activity evidence is not replaced by AI and caller identity is not inferred when Azure did not provide it. Generate tailors only the narrative and saves it for the exact scope. Clear removes that saved narrative and immediately restores the standard Business Value content without deleting Customer Context or changing live facts. Regenerate when evidence changes. Above 100 subscriptions, the curated live brief remains available without tailoring.
Current position and priority work
Investigate failed, security-sensitive, or disruptive changes affecting important services first. Group recurring patterns into rollback, automation, approval-control, or accepted-risk actions with clear owners.
Business outcomes
Change monitoring creates operational accountability by connecting material activity to actors, resources, and timing. It can reduce investigation time while showing where controls or automation need improvement without slowing normal delivery.
Cost of delay
Unauthorized or unintended changes may persist longer and become harder to reconstruct during an incident. Recurring failed or disruptive changes can continue when intent, root cause, and ownership remain unclear.
Decision required
Agree which changes require immediate response, which control improvement will prevent recurrence, and who owns the follow-up.
Validate with stakeholders
When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.
- Was the change authorized, expected, and linked to a change record?
- Did it affect a critical service, security boundary, or compliance control?
- Should the response be rollback, investigation, control improvement, or acceptance?
Key capabilities
Where to find it
In the Spotto Portal sidebar, open Investigate -> Review -> Change Monitoring.
Use the company and subscription selector at the top of the page to choose the Azure subscriptions you want to investigate. Change Monitoring combines the selected subscriptions into one activity feed.
Review the summary cards
The summary cards show:
- Material Changes: activity rows Spotto classified as material changes.
- Sensitive Actions: security-sensitive events and how many failed events are present.
- Health Events: Azure resource health events, including the latest event age.
- Human Actors: distinct user actors, plus noisy events suppressed from the focused feed.
These cards help you decide whether the review is mostly about a change, a security-sensitive action, a health event, or actor follow-up.
Use insight cards for investigation leads
Change Monitoring generates insight cards from the selected activity:
- Failed change activity found: failed events may explain recent instability or incomplete work.
- Sensitive actions need review: credential, RBAC, networking, firewall, policy, or similar sensitive events were surfaced.
- User-driven activity is visible: human actors appear in the selected feed.
- Resource health changed: health events are available for incident correlation.
- No notable change activity: no material change, security, or health events were found in the selected feed.
Understand event types and importance
| Field | Values | What it means |
|---|---|---|
| Type | Change, Security, Health, Operation | The activity feed the event belongs to. The main filters expose Change, Security, and Health. |
| Importance | High, Medium, Low | A triage label for which rows deserve attention first. The UI shows text labels in addition to color. |
| Actor type | User, Service Principal, Managed Identity, Azure Platform, Unknown | Who or what initiated the activity, based on the best actor information available. |
| Status | Examples include Succeeded, Failed, Resolved | Whether the operation completed, failed, or represents a resolved health event. |
Change Monitoring is evidence for investigation, not a final incident verdict. A sensitive action can be expected, and a quiet feed does not prove nothing happened outside the available data.
Inspect the activity feed
The Activity Feed table includes:
- When: relative event time. Grouped rows show the grouped event count.
- Type: event type plus importance.
- Change: operation name and operation subtype.
- Actor: actor display name and actor type.
- Resource: affected resource, resource group, and resource type.
- Status: operation status and subscription.
Use this table to answer practical troubleshooting questions:
- Did a user or automation change the resource before the issue started?
- Did a failed patch, update, deployment, or action line up with the incident?
- Did a resource health event occur during the same window?
- Did a sensitive action affect credentials, access control, network paths, firewall rules, or policy?
- Is the activity concentrated in one actor, operation, or resource group?
Filter by feed, importance, actor, and search
Use filters to narrow the feed:
- Search by actor, operation, resource, resource group, resource type, subscription, status, category, kind, or importance.
- Filter by feed: All Feeds, Change, Security, or Health.
- Filter by importance: All Importance, High, Medium, or Low.
- Filter by actor type: All Actors, Users, Automation, Azure Platform, or Unknown.
The filtered row count updates above the table, so you can see whether the investigation scope is narrowing as expected.
Review breakdowns
Breakdown cards show the top activity groups:
- By Actor: which users, identities, or platform actors appear most often.
- By Operation: which operations are driving the feed.
- By Resource Group: where activity is concentrated.
These are useful when you need a quick lead before reading every row.
Export the current activity feed
Use Export CSV to download the currently filtered rows. The export includes timestamp, kind, importance, operation, actor, status, subscription, resource, resource group, resource type, and event count.
The export filename uses change_monitoring_YYYY-MM-DD.csv.
Recommended investigation workflow
1. Scope the affected subscriptions
Select the subscriptions tied to the incident or service you are investigating. Keep the scope tight at first; broad searches are useful later, but incident triage starts with the smallest plausible blast radius.
2. Check High importance activity
Filter importance to High. Review failed operations and sensitive actions first, especially if the issue involves access, networking, firewall behavior, credentials, policy, or system updates.
3. Compare activity timing with the incident
Use the When column to compare event timing with alert timestamps, deployment windows, customer reports, or monitoring signals. Close timing is not proof, but it is a good reason to keep looking.
4. Review actor patterns
Use By Actor and the actor type filter to distinguish user activity from automation and Azure platform events. A failed service principal action points to a different follow-up path than a user-driven portal change.
5. Check Health events
Filter feed to Health when the issue looks like platform instability, VM availability, service degradation, or a resource health transition.
6. Export evidence for follow-up
Export the filtered feed once you have a useful view. Attach it to incident notes, change records, security review, or remediation tickets.
Technical reference
| Component | Details |
|---|---|
| Inputs | Azure activity log reports for each selected subscription, including material changes, security-sensitive events, resource health events, suppressed noisy event summaries, actor details, resource context, operation names, status, and event counts. |
| Outputs | Summary cards, insight cards, actor/operation/resource-group breakdowns, a searchable and filterable activity feed, and CSV export. |
| Defaults | Data is fetched per selected subscription. The table page size is 25 rows. Filters default to All Feeds, All Importance, and All Actors. |
How it differs from Azure-native activity logs
Azure activity logs are the source of truth, but they are designed as a broad event stream. Change Monitoring is designed for the operational question: "what should I look at first while troubleshooting?"
Spotto focuses the activity review by:
- Grouping activity into Change, Security, and Health feeds.
- Surfacing material and security-sensitive events ahead of routine noise.
- Showing actor, operation, resource, and status context in one table.
- Suppressing noisy events while still showing how much noise was suppressed.
- Letting you filter and export the incident-relevant slice.
How it works (high level)
- You select one or more Azure subscriptions.
- Spotto loads activity log reports for each selected subscription.
- The Portal combines changes, security events, and health events into one sorted feed.
- Rows may represent single events or grouped events, with grouped event(s) shown in the When column.
- The model calculates summary counts, top breakdowns, insights, and filterable rows from the selected data.
Coverage and limitations
- Not a full SIEM: Change Monitoring helps with troubleshooting and review, but it is not a replacement for a dedicated SIEM, EDR, or forensic logging platform.
- Not real-time: The page updates after Spotto receives activity log data. It should be treated as investigation support, not live alerting.
- Sensitive action does not always mean breach: Sensitive actions need review because they can affect security posture, not because they automatically indicate compromise.
- Unknown actors can happen: Some events may not resolve cleanly to a user, service principal, or managed identity.
- Suppressed events are intentionally hidden from the main feed: Suppression reduces noise, but the summary still shows how many noisy events were suppressed.
- Azure only today: Change Monitoring currently covers Azure activity log data.
Related Spotto workflows
- Use Perimeter Insights to check whether recent network or public IP changes affected internet exposure.
- Use Security to review secure score and security recommendations after sensitive actions.
- Use Cloud Resources to inspect affected resources and related recommendations.
- Use Relationship Graph to understand resource relationships and blast radius after a change.
- Use Tickets to track follow-up work created from investigation findings.
Troubleshooting
No change monitoring data found
What you're seeing: The page shows No change monitoring data found.
Likely causes:
- No subscriptions are selected.
- The selected subscriptions do not currently have activity log data available.
- The subscriptions have not completed their first sync.
How to fix:
- Select at least one subscription.
- Confirm the subscriptions are connected and syncing in Spotto.
- Refresh after the next ingestion cycle.
No activity matches these filters
What you're seeing: The table shows No activity matches these filters.
Likely causes:
- The search term is too specific.
- The feed, importance, or actor filter excludes the rows you expected.
How to fix:
- Clear the search box.
- Reset feed to All Feeds.
- Reset importance to All Importance.
- Reset actor to All Actors.
Activity log data could not be loaded
What you're seeing: The page shows Activity log data could not be loaded.
Likely causes:
- Temporary API or network issue.
- The selected company or subscriptions are not available in your current session.
How to fix:
- Refresh the page.
- Re-select the subscriptions.
- If it continues, capture the time, company, and subscription IDs and contact support.
Some subscriptions unavailable
What you're seeing: A notification says Some subscriptions unavailable and lists subscription names.
Likely causes:
- Spotto loaded activity data for some selected subscriptions but failed to load others.
- One or more subscriptions are temporarily unavailable or still syncing.
How to fix:
- Review the rows that did load.
- Retry after the unavailable subscriptions finish syncing.
- If the same subscriptions fail repeatedly, contact support with the listed subscription names.
I expected to see every Azure activity log event
What you're seeing: The summary mentions suppressed noisy events, but those rows do not appear in the main feed. Likely cause: Change Monitoring suppresses routine or noisy events so the main feed stays useful for troubleshooting. How to fix: Use the suppressed event count as a noise indicator, then use Azure-native activity logs if you need every raw event for audit or forensic review.
Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?
Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.
Book a Free Consultation