← AZ-104: Azure administration in production
07 / 7 · 23 MIN

Observability and operational recovery

Produce evidence helping RUN detect, diagnose, and recover.

Concept and mechanism

Azure Activity Log describes management-plane events useful for investigating who changed a resource. Resource logs provide another perspective and need appropriate collection and destination configuration, such as diagnostic settings. Guest telemetry collected by Azure Monitor Agent depends on applicable collection rules and associations; installing the agent does not demonstrate that every required event reaches the workspace. First define the operational question, then the source and query. Retention and evidence access should match diagnostic needs and data controls.

Guided application

An alert should connect signal, time-based condition, and action to an owner. For log errors, validate filtering, aggregation, and window; a CPU metric does not automatically replace that count. During maintenance, alert processing rules can suppress actions within bounded scope and schedule without deleting detection. Recovery requires more than green dashboards: Azure Backup provides restore options and Site Recovery supports failover drills. Prepare a test network, avoid duplicated real effects, validate representative transactions, measure timing, and clean up. Handover should include a runbook executable by the team taking responsibility.

IN PRACTICE

Replication is healthy, but a credential is missing in the recovery environment. A drill with RUN discovers the gap before a real incident.

Common pitfalls

Confusing installation with effective collection; silencing alerts indefinitely; measuring only VM startup; treating replication as validated restoration.

Related topics: Identities and effective access · Governance, protection, and costs

Take this idea with you

Confirm evidence arrives and the team can execute recovery.

Create account

Reference: Data collection rules · AZ-104; skills measured 2026-04-17