Azure Monitor Activity Log for AI agents

Azure Monitor Activity Log tracks control-plane events across an Azure subscription, letting engineers see who changed what resource and when for auditing and troubleshooting. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

DevOps and monitoringOAuth 2.0MCP + RESTazure.microsoft.com
AUDIT LOG · AZURE MONITOR ACTIVITY LOGPOLICY: acme-support
09:41:07 · claude · u_8f2read
azure_monitor_activity_log.list_events
List Activity Log Events✓ allowed · 212ms
09:41:08 · claude · u_8f2read
azure_monitor_activity_log.list_event_categories
List Event Categories✓ allowed · 164ms
EVERY AZURE MONITOR ACTIVITY LOG CALL, ON THE RECORD
01 · USE CASES

What agents do in Azure Monitor Activity Log.

01

Investigate a recent resource change

List activity log events for a subscription to see who deleted or modified a resource around the time of an incident.

02

Check available event categories

List the event categories available before narrowing a query to just administrative or policy events.

03

Audit access before a change

Pull recent activity log events for a resource group as a read-only check before anyone approves a configuration change.

02 · ACTIONS

2 Azure Monitor Activity Log actions, graded by risk.

Every Azure Monitor Activity Log action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

2

Look things up. Allowed by default.

  • azure_monitor_activity_log.list_events
    List Activity Log Events
  • azure_monitor_activity_log.list_event_categories
    List Event Categories

write

0

Create and change things. Allow, or ask the user first.

  • No write actions.

destructive

0

Delete, cancel or archive. Ask first, or deny outright.

  • No destructive actions.
03 · HOW IT WORKS

Azure Monitor Activity Log in three steps.

  1. 01Your users connect Azure Monitor Activity LogThey sign in to Azure Monitor Activity Log on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, and writes like “updates” can wait for the user to approve.
  3. 03Any agent can actYour agent calls Azure Monitor Activity Log through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('azure_monitor_activity_log', {
  read: 'allow',
  write: 'ask',        
  destructive: 'deny',  
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Azure Monitor Activity Log connects.

Users sign in to Azure Monitor Activity Log on Arc0 Connect and approve the scopes you request. Build with Arc0’s Azure Monitor Activity Log OAuth app, or bring your own so the Azure Monitor Activity Log consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Azure Monitor Activity Log connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Azure Monitor Activity Log from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Azure Monitor Activity Log and Arc0, answered.

Q01

Can I use Azure Monitor Activity Log with Claude, ChatGPT or Cursor?

Yes. Connect Azure Monitor Activity Log to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Azure Monitor Activity Log actions you allow.

Q02

How do users connect Azure Monitor Activity Log?

Users sign in to Azure Monitor Activity Log on Arc0 Connect and approve the scopes you request. Build with Arc0’s Azure Monitor Activity Log OAuth app, or bring your own so the Azure Monitor Activity Log consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Azure Monitor Activity Log actions can my agent take?

2 in total: 2 read, 0 write and 0 destructive. Your policies decide which of them each agent may call.

Q04

Can I make my agent read-only in Azure Monitor Activity Log?

Yes. Allow read actions and deny writes in the Azure Monitor Activity Log policy. Your agent can still look things up, and any write it attempts is blocked and logged.

Q05

Can my own backend call Azure Monitor Activity Log too?

Yes. The same Azure Monitor Activity Log connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Azure Monitor Activity Log into your agent.

Your users connect Azure Monitor Activity Log once, under your brand. Your agent gets 2 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan