Skip to main content

Azure Health: Incidents, RCA and Resources

Overview

Azure Health in Spotto shows Azure platform incidents and resource availability issues for the subscriptions you select. It brings Service Health events, PIR/RCA context, impacted services, impacted regions, and Resource Health availability into one review page so you can answer the practical question: "Was this us, Azure, or both?"

Feature overview

Health combines two related Azure signals:

  • Service Health events from Azure Resource Health / Service Health, including service issues, planned maintenance, health advisories, security advisories, RCA events, and emerging issues.
  • Resource Health availability statuses for individual resources, including Available, Unavailable, Degraded, and Unknown states.

The page is designed for incident review, operational handover, and quick blast-radius checks. It complements Change Monitoring: Change Monitoring explains what changed inside the subscription; Health explains what Azure platform or resource health event affected the subscription.

Where to find it: In the Spotto Portal sidebar, go to Review -> Health.

Why use this? (Jobs, pains, gains)

Jobs to be done

  • When an outage is reported, I want to see whether Azure published a related incident, so I can separate platform impact from tenant-side changes.
  • When Microsoft publishes a post-incident review, I want the RCA/PIR sections in the same place as the affected subscription context, so I can brief teams without rebuilding the timeline by hand.
  • When a resource is degraded or unavailable, I want a resource-level view with links back to Spotto resource details, so ownership and remediation are easier to follow.

Common pains

  • Azure Service Health and Resource Health answer different questions, and switching between them during an incident is not anyone's idea of a good time.
  • Activity logs show management operations, but not the full customer-facing incident summary, impact window, PIR tags, or recommended actions from Microsoft.
  • Resource-level health can be missed when the subscription-level incident has already moved to Resolved.

What you gain

  • A subscription-scoped view of Azure health events across selected subscriptions.
  • Summary cards for active incidents, final PIRs, impacted resource statuses, and resolved events.
  • PIR/RCA details such as "What happened", "What went wrong and why", and "How customers can reduce impact" when Microsoft provides them.
  • Resource Health availability rows with direct links back to Spotto resource details when a resource ID is available.

Turn the evidence into a decision

Select the labelled briefcase Business Value button beside Notes. The brief combines live incident, impacted/unavailable resource, and post-incident review facts with a resilience decision.

Technical severity does not establish business criticality; validate that context with service owners. Generate tailors only the narrative for permitted users and saves it to the exact scope. Clear removes that saved narrative and immediately restores the standard Business Value content without deleting Customer Context or changing live facts. Regenerate when evidence changes. Above 100 subscriptions, the curated live brief remains available without tailoring.

Current position and priority work

Stabilize active incidents according to business-service priority, then turn recurring events and post-incident findings into owned resilience improvements.

Business outcomes

Health review connects Azure incidents and resource availability to services, users, and recovery commitments. That connection helps teams restore the most important services first and fund resilience improvements from real incident evidence.

Cost of delay

Technical severity alone may not reveal business criticality, which can prolong customer impact or misdirect response effort. Repeated failure patterns may continue when PIR actions are not assigned, funded, and tracked.

Decision required

Confirm service priority, approve the immediate recovery and follow-up work, and assign owners and dates to post-incident actions.

Validate with stakeholders

When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.

  • Which business services and users are affected?
  • What availability commitments, workarounds, and escalation thresholds apply?
  • Which PIR actions require an owner and investment decision?

Key capabilities

Where to find it

In the Spotto Portal sidebar, open Investigate -> Review -> Health.

Select subscriptions to scope the view

Use the subscription selector at the top of the page to choose one or more subscriptions. Health only loads data for subscriptions that are ready for review.

Review active and resolved incidents

The Service Health events table shows:

  • Event title and summary
  • Event type, such as ServiceIssue, PlannedMaintenance, HealthAdvisory, SecurityAdvisory, RCA, or EmergingIssues
  • Status, such as Active or Resolved
  • Severity level when provided
  • Impacted services and regions
  • Impacted resource counts and resource links when available
  • Last update time and impact duration

Read PIR and RCA details

When Microsoft includes post-incident review content, expand Details on the event row to review:

  • What happened
  • What went wrong and why
  • How Microsoft responded
  • How Microsoft is reducing recurrence
  • How customers can reduce impact
  • Recommended actions
  • Impacted resources

These fields are optional because Microsoft does not publish every section for every event.

Review current resource availability

The Resource availability table shows current per-resource health states. Use it to find resources that are:

  • Unavailable
  • Degraded
  • Unknown
  • Available (visible when you switch the resource health filter to All resources)

Each row can include the resource name, resource type, subscription, health state, reason, summary, recommended actions, and linked service-impacting events.

Search and filter

Use the search box to find events or resources by title, summary, service, region, subscription name, resource name, resource ID, or recommended action.

Use the filters to switch between:

  • All, active, and resolved health events
  • Impacted, unavailable, degraded, unknown, and all resource availability statuses

Technical reference

ComponentDetails
InputsAzure Microsoft.ResourceHealth/events and Microsoft.ResourceHealth/availabilityStatuses data collected per subscription. Impacted resources are included when available.
OutputsSummary cards, searchable Service Health event rows, PIR/RCA detail sections, resource availability rows, and links to Spotto resource detail pages.
DefaultsEvent rows sort by latest update or impact start time. Resource availability rows prioritize Unavailable, Degraded, and Unknown resources before Available resources.
RetentionHealth events depend on the collected Azure Resource Health event window. Older events are available only if they were collected and retained by Spotto.

How it differs from Change Monitoring

Change Monitoring and Health are intentionally separate.

QuestionUse
"Who changed this resource or subscription setting?"Change Monitoring
"Did Azure report a platform incident, outage, maintenance event, or RCA?"Health
"Which resources are currently degraded, unavailable, or recently impacted?"Health
"Was there a failed deployment, policy assignment, or administrative operation?"Change Monitoring

Activity logs can contain health-looking categories, but they are compact management events. Health preserves Azure Service Health and Resource Health fields such as impact windows, impacted services and regions, PIR tags, article content, recommended actions, and resource availability status.

How it works (high level)

  1. You select one or more subscriptions.
  2. Spotto loads the normalized Health artifacts collected for those subscriptions.
  3. Service Health events and Resource Health availability statuses are combined into a single review page.
  4. Events remain linked to impacted resources when Azure provides the resource IDs.
  5. Resource IDs link back to Spotto resource details for deeper investigation.

Coverage and limitations

  • Microsoft does not provide full PIR/RCA sections for every health event.
  • Some events are subscription-level only and may not include a resource-level impacted resources list.
  • Resource availability is a point-in-time signal from the latest collection. If Azure health changes after the last sync, wait for the next collection or refresh after sync completes.
  • Sensitive advisory details may require additional Azure permissions and may not be visible in every environment.

Permissions and access

Health uses the same Spotto portal access as Change Monitoring. If a user cannot access Change Monitoring for a company, they will not see Health.

For Azure collection, Spotto needs read access to Resource Health data, including:

  • Microsoft.ResourceHealth/events/read
  • Microsoft.ResourceHealth/events/impactedResources/read
  • Microsoft.ResourceHealth/AvailabilityStatuses/read
  • Microsoft.ResourceHealth/AvailabilityStatuses/current/read

Troubleshooting

The Health page is empty

What you're seeing: The page shows no Service Health events or Resource Health availability statuses.

Likely causes:

  • No subscriptions are selected.
  • The selected subscriptions are not ready yet.
  • Azure has no collected health events or availability statuses for the selected subscriptions.
  • Resource Health permissions are missing from the cloud account.

How to fix:

  1. Select at least one ready subscription.
  2. Wait for the cloud account sync to complete.
  3. Confirm the Azure role assigned to Spotto includes the Resource Health read permissions listed above.

PIR or RCA sections are missing

What you're seeing: An event appears, but fields such as "What happened" or "What went wrong and why" are blank.

Likely causes:

  • Microsoft has not published a preliminary or final PIR for that event.
  • The event type does not include post-incident review sections.
  • The event has only summary, update, or article content.

How to fix:

  1. Check whether the event has a Preliminary PIR or Final PIR badge.
  2. Review the event summary and recommended actions.
  3. Recheck after Microsoft publishes the final update.

What you're seeing: An impacted resource appears as text, but there is no usable Spotto resource link.

Likely causes:

  • Azure did not provide a targetResourceId for the impacted resource.
  • The resource is outside the selected subscriptions or has not been collected into Spotto inventory.
  • The resource was deleted before the latest inventory sync.

How to fix:

  1. Search for the resource by name or ID in Cloud Resources.
  2. Select the subscription that owns the resource.
  3. Refresh after the next inventory sync if the resource was recently created or restored.

Resource Health says Available but users still reported impact

What you're seeing: Resource availability rows show Available, but users reported downtime or degradation.

Likely causes:

  • The impact was transient and resolved before the latest Resource Health collection.
  • The incident affected an upstream dependency rather than the resource directly.
  • The issue was tenant-side, such as a deployment, policy, network, or identity change.

How to fix:

  1. Check Service Health events for the same time window.
  2. Review Change Monitoring for deployments or administrative changes around the incident.
  3. Check resource metrics and logs for tenant-side symptoms.
Optimize Your Azure Environment

Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?

Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.

Book a Free Consultation