Building a centralized security monitoring pipeline using Azure Activity Logs, Log Analytics Workspace, and KQL queries to detect administrative events and security anomalies.
Configuring Azure Monitor Alert Rules and Action Groups to automatically detect administrative events and send real-time email notifications for incident response.