Description:
Create an Azure Activity Log Alert to detect when a Policy Assignment is deleted in a subscription. This ensures visibility into governance changes and prevents unnoticed removal of policy enforcement.
Rationale:
Monitoring delete events for Policy Assignments provides insight into changes made within Azure Policy – Assignments and helps reduce the time needed to detect unauthorized or accidental deletions. This improves security posture and ensures governance controls are restored quickly.
Impact:
Enabling this alert provides immediate notification when policy assignments are deleted, improving visibility and control. It helps detect unauthorized changes, supports compliance audits, reduces security risks, and enables faster incident response to policy enforcement gaps.
Default value:
By default, no monitoring alerts are configured for deleting Policy Assignments in Azure.
Test Plan:
Sign in to the Azure Portal at https://portal.azure.com
Navigate to Monitor
Select Alerts
Open Alert rules
Verify an Activity Log Alert exists for the operation "Delete policy assignment"
Verify the alert scope is set to the required subscription
Verify that an Action Group is associated
If no alert exists or the scope is incorrect, follow the implementation steps
Implementation steps:
Sign in to the Azure Portal at https://portal.azure.com
Navigate to Monitor
Select Alerts
Click Create and select Alert rule
Under Scope, select the target subscription
Under Condition, select Activity Log
Set Category to Policy
Under Condition, click See all signals, search for Operation name "Delete policy assignment", and select the signal.
Apply the condition
Under Actions, select an existing Action Group or create a new one
Under Details, select a resource group and provide an alert rule name
Click Review + Create
Click Create
Backout Plan:
Sign in to the Azure Portal at https://portal.azure.com
Navigate to Monitor
Select Alerts
Open Alert rules
Locate the Activity Log Alert for "Delete policy assignment."
Delete the alert rule
Confirm the deletion
Reference:
https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/activity-log
https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-activity-log
https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-overview
https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-group


