You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何定位停止Azure关键VM的操作用户?

How to Identify the User Who Stopped Your Azure VM (Without Dedicated Monitoring)

Hey Usha, sorry to hear your critical Azure VM went down unexpectedly—let’s walk through the steps you can take to track down the responsible user, even without a standalone monitoring tool configured:

  • Start with the Azure Activity Log
    This is your first and most reliable stop. Azure automatically logs all control-plane operations (like starting/stopping VMs) by default, and these logs are retained for 90 days. Here’s how to access them:

    • In the Azure Portal: Navigate to your VM → Under "Monitoring", select "Activity log". Filter for the Microsoft.Compute/virtualMachines/powerOff/action operation, and check the Caller column—it will show the user ID or UPN of the person who initiated the stop.
    • Using Azure CLI: Run this command to pull the relevant logs directly:
      az monitor activity-log list --resource-group <your-resource-group-name> --resource-type Microsoft.Compute/virtualMachines --filter "operationName eq 'Microsoft.Compute/virtualMachines/powerOff/action'" --output table
      
  • Cross-Reference with Azure AD Audit Logs
    If the operation was performed by an Azure AD user, you can get more context (like the user’s full name, IP address, or other related actions) by checking Azure AD’s audit logs:

    • Go to the Azure AD portal → Under "Monitoring", select "Audit logs". Filter for actions related to "Azure Resources" or specifically for the VM stop event. This will tie the Activity Log’s caller ID to a full user profile.
  • Check VM Boot Diagnostics (if enabled)
    While boot diagnostics primarily capture startup logs, if your VM had this feature enabled, it might contain timestamped logs that align with the stop event. This won’t directly give you the user, but it can help confirm the exact time of the stop and rule out any internal VM issues that might have caused a crash (as opposed to a manual stop).

  • Verify Resource Lock Changes
    If you had a resource lock on the VM, check the Activity Log for any Microsoft.Authorization/locks/delete operations around the time the VM stopped—someone might have removed the lock before initiating the stop.

Even without Application Insights or dedicated monitoring, Azure’s built-in logging should have the information you need. Start with the Activity Log—it’s the most straightforward way to find the caller.

内容的提问来源于stack exchange,提问作者usha chokka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:49:50