Review Azure Activity Log retention

Retain Activity Logs for investigation and audit needs, and check deletion policies at the actual destination.

Description

Activity Logs record management operations such as resource creation, updates, and deletion. If records are deleted too soon, a later incident investigation may lack necessary evidence. The default retention period is 90 days; longer retention requires export through diagnostic settings and retention management at the destination.

365 days is an example of an organizational requirement. Choose a period based on investigation needs, contractual or regulatory requirements, and storage costs.

Potential impact

  • Management records needed for incident investigations or audits may already have been deleted.
  • Change-history reviews and long-term analysis may become difficult.

Remediation

  • Compare the required retention period with the records that are actually available.
  • Export the required logs through diagnostic settings and configure destination controls, such as Log Analytics retention or Storage lifecycle policies.
  • Existing Log Profiles are scheduled to retire on September 30, 2026; migrate to diagnostic settings. Verify collection coverage, deletion policies, and access controls.

Examples

These examples compare retention settings in the legacy Log Profile format, not a recommended new configuration. Supply valid resource group and storage account names and authentication for the actual environment.

Before

yaml
- name: 로그 프로필 생성
  azure_rm_monitorlogprofile:
    name: myProfile
    location: eastus
    locations:
      - eastus
      - westus
    categories:
      - Write
      - Action
    retention_policy:
      enabled: false
    storage_account:
      resource_group: myResourceGroup
      name: myStorageAccount

enabled: false disables this retention policy, not log collection. It does not by itself mean that records will soon be deleted.

After

yaml
- name: 로그 프로필 생성
  azure_rm_monitorlogprofile:
    name: myProfile
    location: eastus
    locations:
      - eastus
      - westus
    categories:
      - Write
      - Action
    retention_policy:
      enabled: true
      days: 380
    storage_account:
      resource_group: myResourceGroup
      name: myStorageAccount

This legacy format specifies 380 days of retention. days: 0 means indefinite retention, but does not prevent other deletion policies. Manage current configurations through the actual export destination's retention and deletion controls.

References