Overview
User activities in Business Applications records every management action taken by users across the module. You can view these logs to track who changed what, when, and at what scope — from module-level operations down to individual Azure resources.
Business value
A complete audit trail of user actions supports governance requirements and simplifies incident investigation. When something changes unexpectedly — a monitoring rule is updated, a service principal is deleted, or a user's permissions are modified — you can identify the responsible action and actor without manual investigation.
How it works
User activities logs are organized into five categories, each corresponding to a management domain in Business Applications:
- Business Application management — actions on individual Business Applications
- Business Application group management — actions on Business Application groups
- Service Principal management — actions on service principals
- Monitoring Profile management — actions on monitoring profiles
- User management — actions on users, groups, and roles
You can view activity logs at multiple scopes depending on what you need to investigate. Logs are available at the Business Applications product level, Business Application group level, Business Application level, Azure resource type level, and Azure resource level. For example, to see all activity for Event Grid Subscription resources inside a specific Business Application, open the resource type page and select User activities.
To access logs for a Business Application group or application, click the Context menu ( ⋮ ) next to the item in the tree view and select User activities.
Access to User activities depends on your role and scope:
- Module-level User activities is available to Account owner, Owner, and Contributor roles only. Users with custom roles cannot access it.
- Tree node-level User activities (Business Application group, application, resource type, and resource) is accessible to users with custom roles.
- Users with Specified access can only view User activities for the nodes within their assigned scope.
Business Application management
This category records all actions performed on individual Business Applications:
- Creating a Business Application
- Updating a Business Application
- Deleting a Business Application
- Moving a Business Application
- Adding or removing resources
- Updating a friendly name
- Updating monitoring rules and configuration
- Performing resource functions
- Managing automated tasks
- Managing service maps
- Managing dashboards
Business Application group management
This category records all actions performed on Business Application groups:
- Creating a Business Application group
- Updating a Business Application group
- Deleting a Business Application group
- Moving a Business Application group
Service Principal management
This category records all actions performed on service principals:
- Adding a service principal
- Updating a service principal
- Deleting a service principal
Monitoring Profile management
This category records all actions performed on monitoring profiles:
- Adding a monitoring profile
- Updating a monitoring profile
- Deleting a monitoring profile
User management
This category records all user access and role changes:
- Adding a new user or group
- Updating user permissions
- Removing an existing user or group
- Adding a new role
- Updating an existing role
- Deleting a role