Azure Monitor Activity Log for AI agents
Azure Monitor Activity Log tracks control-plane events across an Azure subscription, letting engineers see who changed what resource and when for auditing and troubleshooting. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Azure Monitor Activity Log.
Investigate a recent resource change
List activity log events for a subscription to see who deleted or modified a resource around the time of an incident.
Check available event categories
List the event categories available before narrowing a query to just administrative or policy events.
Audit access before a change
Pull recent activity log events for a resource group as a read-only check before anyone approves a configuration change.
2 Azure Monitor Activity Log actions, graded by risk.
Every Azure Monitor Activity Log action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
2Look things up. Allowed by default.
- azure_monitor_activity_log.list_eventsList Activity Log Events
- azure_monitor_activity_log.list_event_categoriesList Event Categories
write
0Create and change things. Allow, or ask the user first.
- No write actions.
destructive
0Delete, cancel or archive. Ask first, or deny outright.
- No destructive actions.
Azure Monitor Activity Log in three steps.
- 01Your users connect Azure Monitor Activity LogThey sign in to Azure Monitor Activity Log on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, and writes like “updates” can wait for the user to approve.
- 03Any agent can actYour agent calls Azure Monitor Activity Log through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('azure_monitor_activity_log', { read: 'allow', write: 'ask', destructive: 'deny', }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Azure Monitor Activity Log connects.
Users sign in to Azure Monitor Activity Log on Arc0 Connect and approve the scopes you request. Build with Arc0’s Azure Monitor Activity Log OAuth app, or bring your own so the Azure Monitor Activity Log consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Azure Monitor Activity Log connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Azure Monitor Activity Log from any agent.
Azure Monitor Activity Log and Arc0, answered.
Can I use Azure Monitor Activity Log with Claude, ChatGPT or Cursor?
Yes. Connect Azure Monitor Activity Log to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Azure Monitor Activity Log actions you allow.
How do users connect Azure Monitor Activity Log?
Users sign in to Azure Monitor Activity Log on Arc0 Connect and approve the scopes you request. Build with Arc0’s Azure Monitor Activity Log OAuth app, or bring your own so the Azure Monitor Activity Log consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Azure Monitor Activity Log actions can my agent take?
2 in total: 2 read, 0 write and 0 destructive. Your policies decide which of them each agent may call.
Can I make my agent read-only in Azure Monitor Activity Log?
Yes. Allow read actions and deny writes in the Azure Monitor Activity Log policy. Your agent can still look things up, and any write it attempts is blocked and logged.
Can my own backend call Azure Monitor Activity Log too?
Yes. The same Azure Monitor Activity Log connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Azure Monitor Activity Log into your agent.
Your users connect Azure Monitor Activity Log once, under your brand. Your agent gets 2 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan