Description:
Create an activity log alert for the Create Policy Assignment event. This control ensures proactive monitoring and alerting for Azure Policy assignments, improving governance visibility, reducing security risk, and supporting compliance requirements.
Rationale:
Monitoring for create policy assignment events gives insight into changes made in"Azure policy - assignments" and can reduce the time it takes to detect unsolicited changes.
Impact:
Enabling an Activity Log Alert for policy assignment creation ensures real-time governance visibility, strengthens security monitoring, and supports compliance with regulatory and industry standards.
Default Value:
By default, Azure logs policy assignment events but does not generate alerts or notifications when a policy assignment is created unless an Activity Log Alert rule is explicitly configured.
Pre-requisites:
Required permissions (Owner / Contributor / Monitoring Contributor).
Azure Policy assignments are available in the subscription.
Action Group is configured with at least one notification method.
Test Plan:
Sign in to the Azure Portal at https://portal.azure.com
Navigate to Monitor
Select Alerts
Open Alert rules
Verify an Activity Log Alert exists for the operation Create policy assignment
Verify the alert scope is set to the required subscription
Verify that an Action Group is associated
If no alert exists or the scope is incorrect, follow the implementation steps
Implementation Steps:
Sign in to the Azure Portal at https://portal.azure.com
Navigate to Monitor
Select Alerts, click Create, and select Alert rule
Under Scope, select the target subscription
Under Condition, select Activity Log
Set Category to Policy
Under Condition, click See all signals, search for Operation name "Create policy assignment.", and select the signal.
Apply the condition
Under Actions, select an existing Action Group or create a new one
Under Details, select a resource group and provide an alert rule name
Click Review + Create
Click Create
Backout Plan:
Sign in to the Azure Portal at https://portal.azure.com
Navigate to Monitor
Select Alerts
Open Alert rules
Locate the Activity Log Alert for "Create policy assignment."
Delete the alert rule
Confirm the deletion
References:
https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-activity-log
https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/activity-log-alerts


