Description
A legacy Azure Monitor log profile that omits Write, Action or Delete may not export those management operations to its destination. Azure’s activity log itself retains events for 90 days by default, so an export gap does not mean that all activity records are absent.
Potential impact
- The central destination may lack some resource creation, modification or deletion records.
- Audits and investigations beyond the default retention period may be harder.
Remediation
- Use subscription diagnostic settings to export required activity log categories instead of legacy log profiles. Microsoft lists September 2026 for the transition from legacy profiles to diagnostic settings.
- Verify the required regions, destination and retention policy, and confirm that actual change events arrive.
Examples
These excerpts compare categories in a legacy log profile. Destination and retention settings are omitted. Use diagnostic settings for new configurations.
Before
- name: 로그 프로필 생성
azure_rm_monitorlogprofile:
name: myProfile
location: eastus
locations:
- eastus
- westus
categories:
- Write
- Action
Delete is missing, so this profile’s export does not include deletion operations.
After
- name: 로그 프로필 생성
azure_rm_monitorlogprofile:
name: myProfile
location: eastus
locations:
- eastus
- westus
categories:
- Write
- Action
- Delete
All three legacy management-operation categories are included. This does not collect every data access or every category in the current activity log.