Choosing the Azure Activity workbook to analyze subscription-level administrative actions in Microsoft Sentinel
You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1. From Content Hub, you deploy the Microsoft Entra solution for Microsoft Sentinel and configure a connector. You need to analyze actions performed by users that have administrative privileges to the subscription. Which workbook should you use?
Community Votes
56% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Subscription-level administrative operations are recorded in the Azure Activity log; the Azure Activity workbook in Sentinel is the correct view for analyzing who performed what at subscription scope, as opposed to directory-level Entra activity.
After deploying the Microsoft Entra solution to a Sentinel workspace, you need to analyze actions performed by users with administrative privileges to the subscription; the Azure Activity workbook surfaces subscription-level Azure Resource Manager activity.
Picking Microsoft Entra Audit logs because the question mentions the Entra solution — those logs cover tenant/directory administrative actions, not the subscription-scoped Azure Resource Manager operations the question asks about.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The question specifies actions by users with administrative privileges to the subscription. Subscription-scoped control-plane operations are captured by the Azure Activity log, and the Azure Activity workbook in Sentinel correlates and visualizes exactly those subscription-level events, including who took which administrative action.Why the Other Options Are Wrong
Microsoft Entra Audit logs (B) record administrative actions inside the Entra tenant/directory, not Azure Resource Manager operations at the subscription level, so they do not answer the question. Microsoft Entra Sign-ins logs (C) show authentication events, not administrative actions. Identity & Access (D) is a broader identity workbook and is not the dedicated view for subscription administrative activity.Community Comment Notes
The community is split (B 56 vs A 44). Sapphire points to the Azure Monitor Activity Log as the source of subscription-level insight, while chirva's GPT summary favors Entra Audit logs. The deciding factor is the word 'subscription': ARM/admin actions on the subscription live in the Azure Activity log, which is why the Azure Activity workbook is the right choice.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →