To meet strict regulatory compliance, we need to export D365 F&O security event logs (e.g., user role assignments, system administrator access, and critical security configuration changes) into Azure Monitor and a Log Analytics workspace for long-term, immutable retention.
What is the recommended architecture for this? Specifically:
Does the native Application Insights / Telemetry integration capture these specific security and role modification events out-of-the-box, or do we need to rely on custom Business Events and Database Logging routed through Dataverse?
How are you enforcing WORM (Write Once, Read Many) immutability on the destination side—are you using Log Analytics retention locks, or is it better to route the telemetry to an immutable Azure Storage Blob?
Are there any community-recommended KQL queries or standard workbooks for parsing F&O security telemetry once it reaches Azure Monitor?

Report
All responses (
Answers (