Choosing the Azure Activity workbook to analyze subscription-level administrative actions in Microsoft Sentinel

Configure the Microsoft Sentinel SIEM and platform
Answer Correct answer: A — The Azure Activity workbook analyzes subscription-level Azure Resource Manager operations, which is what administrative privileges to the subscription generate.

You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1. From Content Hub, you deploy the Microsoft Entra solution for Microsoft Sentinel and configure a connector. You need to analyze actions performed by users that have administrative privileges to the subscription. Which workbook should you use?

  1. Azure Activity Correct Answer
  2. Microsoft Entra Audit logs
  3. Microsoft Entra Sign-ins logs
  4. Identity & Access

Community Votes

B
56%
A
44%

56% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Subscription-level administrative operations are recorded in the Azure Activity log; the Azure Activity workbook in Sentinel is the correct view for analyzing who performed what at subscription scope, as opposed to directory-level Entra activity.

After deploying the Microsoft Entra solution to a Sentinel workspace, you need to analyze actions performed by users with administrative privileges to the subscription; the Azure Activity workbook surfaces subscription-level Azure Resource Manager activity.

Picking Microsoft Entra Audit logs because the question mentions the Entra solution — those logs cover tenant/directory administrative actions, not the subscription-scoped Azure Resource Manager operations the question asks about.

Community Discussion (5 comments)

limpan 👍 1 Selected: B
Explanation: Microsoft Entra Audit logs: These logs provide detailed information about administrative actions performed in the Azure AD tenant, including actions by users with administrative privileges. This is the most appropriate workbook for analyzing administrative activities.
LinearB 👍 1 Selected: A
To analyze actions performed by users with administrative privileges in your Microsoft Sentinel workspace, you should use the "Azure Activity" workbook. This workbook provides extensive insight into your organization's Azure activity by analyzing and correlating all user operations and events, including those performed by users with administrative privileges1.
chirva 👍 2 Selected: B
GPT4: To analyze actions performed by users that have administrative privileges to the subscription, you should use the workbook that focuses on audit logs related to administrative activities. The most appropriate workbook for this purpose is: B. Microsoft Entra Audit logs This workbook will provide you with detailed information about the actions performed by users with administrative privileges, allowing you to monitor and analyze their activities effectively.
sapphire 👍 3 Selected: A
The Azure Monitor Activity Log is a platform log that provides insight into subscription-level events. https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/activity-log-insights
Kristiannn 👍 2 Selected: B
I'll go with B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The question specifies actions by users with administrative privileges to the subscription. Subscription-scoped control-plane operations are captured by the Azure Activity log, and the Azure Activity workbook in Sentinel correlates and visualizes exactly those subscription-level events, including who took which administrative action.

Why the Other Options Are Wrong

Microsoft Entra Audit logs (B) record administrative actions inside the Entra tenant/directory, not Azure Resource Manager operations at the subscription level, so they do not answer the question. Microsoft Entra Sign-ins logs (C) show authentication events, not administrative actions. Identity & Access (D) is a broader identity workbook and is not the dedicated view for subscription administrative activity.

Community Comment Notes

The community is split (B 56 vs A 44). Sapphire points to the Azure Monitor Activity Log as the source of subscription-level insight, while chirva's GPT summary favors Entra Audit logs. The deciding factor is the word 'subscription': ARM/admin actions on the subscription live in the Azure Activity log, which is why the Azure Activity workbook is the right choice.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide