What is an administrator audit log?¶
An administrator audit log records actions carried out through elevated cloud roles or management functions.
It may show user creation, password resets, role assignments, permission changes, policy updates, application consent, logging changes and deletion.
What this means in practice¶
The administrator account may be shared, compromised or used through automation. A delegated administrator or managed-service provider may also act within the environment.
Investigators should identify the administrator account, exact role, permissions and whether the action was performed through a browser, API, script or management tool.
Role history matters. A person who is not currently an administrator may have held elevated access when the event occurred.
Where compromise is suspected, check for new administrators, hidden delegation, application consent, logging changes and persistence created after the first access.
Administrator audit records should be preserved before roles or accounts are removed where possible. Later deletion may leave the event intact, but it can make the identity and organisational context harder to reconstruct accurately much later operationally.
What this does not show on its own¶
The dangerous assumption is that any change attributed to an administrator proves that named person personally performed it.
What to do next¶
Check the time, target account or resource, previous and new values, IP address, session, application and outcome.
Compare administrator events with help-desk tickets, change approvals, work schedules and authentication records.
Do not assume the log is complete. Some services require enhanced logging or retain administrator records separately.
Key takeaway
Administrator audit logs can explain powerful changes in a cloud environment, but attribution depends on the role, session, access route and organisational context.