How to Configure Azure Alerts for Data Downloads and Deletions
Question details
The user needs to set up alerts in Microsoft Azure to monitor critical data activities, including large-scale downloads, deletions, and additions across production systems.

- Product
- Microsoft Azure
- Device & OS
- not provided
- Scenario
- Securing production environments and ensuring compliance by tracking unauthorized or significant data modifications and exfiltration.
- Observed behavior
- Establishing a robust alerting system that notifies administrators of specific data activities based on predefined thresholds.
Ensure you have the appropriate administrative permissions in your Azure subscription, such as Security Admin or Contributor roles, to create alert rules and configure audit logging.
Use Azure Monitor and Log Analytics to Create Alert Rules
Set up custom alert rules based on specific query thresholds using Azure Monitor and Log Analytics workspaces.
Azure Monitor allows you to collect, analyze, and act on telemetry data. By routing your service audit logs to a Log Analytics workspace, you can trigger alerts whenever data operations exceed normal thresholds.
Navigate to your specific Azure resource, select 'Diagnostic settings' from the left menu, and check the boxes for data read and write events to send them to a connected Log Analytics workspace.
Go to Azure Monitor, click 'Alerts', and select 'Create an alert rule'. Choose your Log Analytics workspace as the target resource scope.
Use Kusto Query Language (KQL) to filter for specific operations (e.g., Delete, Download) and set the threshold logic, such as triggering when there are greater than 100 events in a 5-minute window.
Specify who should be notified when the alert fires by creating or selecting an Action Group, adding your preferred notification methods like email, SMS, or webhook.

Implement Microsoft Purview for Compliance Monitoring
Utilize Microsoft Purview to track data access and modifications across your data estate, especially for sensitive information.
Analyze Azure Log Reports with WPS Office
While Azure handles your cloud infrastructure, you often need to analyze exported alert logs, document security policies, and present compliance data. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office with a familiar UI and seamless migration for managing all your cloud reporting needs.

Frequently Asked Questions
Can I test Azure alert rules before making them active in production?
Yes, you can run your Kusto Query Language (KQL) queries directly in the Log Analytics workspace to see how many results are returned over a historical period. This allows you to adjust your thresholds to prevent alert fatigue before officially enabling the rule.
Why am I not receiving notifications for my triggered Azure alerts?
Check your Action Group configurations within Azure Monitor. Ensure the email addresses, SMS numbers, or webhooks are typed correctly, and verify that your Azure subscription hasn't hit any automated rate limits for email or SMS notifications.
Does Microsoft Defender for Cloud automatically alert on data deletion?
Yes, Microsoft Defender for Cloud provides built-in threat protection alerts for anomalous activities, including unusual data extraction or mass deletion attempts on supported resources like Azure Storage, without requiring you to write complex custom queries.




