What Activity Logging is
Activity Logging keeps a record of what happens in your Virtual Desktops, such as who signed in, who connected to a desktop, which shared files were opened or changed, and what changed in your setup. Secureframe sets it up automatically when it creates your Virtual Desktops, so there is nothing to turn on. The records are stored in your own Azure Government environment, where you and your assessor can search them.
Secureframe turns on logging across your Virtual Desktops, from Microsoft sign-ins to the shared drive.
The records are sent to a log workspace in your Azure Government environment.
Secureframe sets the workspace to keep records for a year, locks it against deletion, and sets up email alerts if logging stops.
You or your assessor search the records in the Azure portal, using ready-made searches Secureframe adds for you.
Where your records are kept
Your records are stored in Azure Log Analytics, Microsoft's service for collecting and searching activity records. Secureframe creates a log workspace in your Azure Government environment and configures what goes into it. The records live there, alongside your desktops.
Control: Your records stay inside your own Azure Government environment. They are not stored in a Secureframe-owned account.
Cost: Storing your records appears on your Azure invoice, not your Secureframe invoice. Desktop activity adds only a handful of records each time someone signs in, so the cost is small. Microsoft sign-in records cover everyone in your organization's Microsoft account.
Why it matters for CMMC
CMMC requires you to keep a record of activity on any system that handles CUI, and to be able to show which person did what. Activity Logging gives you that record without having to build it yourself. Sign-ins, file access, and admin activity are each recorded with the account that did them. Each sign-in record also shows whether multi-factor sign-in was required, which is the evidence assessors ask for. A policy on its own isn't enough. Your workspace keeps records for a year, which covers the 90 days defense contractors must preserve records after reporting a cyber incident. CMMC also requires you to protect your records and to know if logging stops.
What Activity Logging records
Microsoft sign-ins: Every sign-in to your organization's Microsoft account, including when, from where, and whether multi-factor sign-in was required. This also includes sign-ins by automated tools, such as the one Secureframe uses to manage your setup, and changes to groups, admin roles, and sign-in rules. These records cover everyone in your Microsoft account, not only people who use Virtual Desktops.
Connections to a desktop: Who connected, from which location and device, how long they stayed, and connections that failed. It also records which desktops each person was offered when they opened their remote desktop app, which helps you spot someone who should no longer have access. Changes to your desktops, whether each desktop is healthy, and, on pooled desktops, when desktops were turned on or off around your core hours are recorded too.
Activity on a desktop: Windows on each desktop records sign-ins and sign-outs, failed sign-in attempts and why they failed, sign-ins with admin rights, accounts created directly on a desktop, and people added to groups on it. It also records antivirus detections, Windows errors, and, on pooled desktops, attempts to run software that isn't allowed.
Tracked files and folders: If your IT team turns on auditing for specific files or folders on a desktop, Windows records who opened them or changed their permissions. Secureframe doesn't choose these files and folders for you.
Shared drive (Z:): Every file opened, changed, or deleted, and who did it.
Password store: Each time a password kept in your setup's secure password store is read or changed, and by whom.
Network traffic: What your desktops connected to and what tried to connect to them, including connections that were blocked.
Searches of the records: Who searched your records, when, and what they searched for.
What isn't recorded
Activity Logging records actions, not content. It doesn't capture screens, keystrokes, or websites visited. It records who opened a file, but not what's in the file.
Files in someone's own profile aren't tracked one by one, so save shared work on the shared drive (Z:).
Changes elsewhere in your Azure environment aren't part of Activity Logging.
How your records are protected
Kept for a year: Your workspace keeps every record for 365 days. Detailed network traffic data is kept for 30 days, and a summary of it is kept in your workspace for the full year.
Locked against deletion: Secureframe locks your workspace so it can't be deleted by accident. Removing the lock requires Owner-level access to your Azure subscription, and removing it is recorded.
Alerted when something goes wrong: You get an email alert in three situations, so you can act right away:
A serious security event: Something that shouldn't happen in normal use, like someone clearing a desktop's records or changing what Windows records.
A desktop stops recording: A desktop is running but hasn't recorded any security activity in six hours.
A desktop stops reporting: A desktop has stopped sending records altogether. Pooled desktops don't get this alert, since they turn off on their own when no one is using them.
You choose who receives these alerts. From the Virtual Desktops page, open Settings, and on the General tab find Security alert notifications. Add or remove email addresses, then select Save alert recipients. Secureframe applies the change to your Azure environment, which can take a few minutes.
Finding your records
Your records are in a log workspace in your Azure Government environment. Its name ends in -log-analytics.
Sign in to the Azure Government portal at portal.azure.us.
In the search bar, type Log Analytics workspaces and open it.
Select the workspace whose name ends in -log-analytics.
Select Logs.
Open Queries, then find the Secureframe Audit Evidence group.
Pick a search and select Run.
Note: You need an Azure account with access to your Azure Government subscription to see the records. If your assessor doesn't have one, run the searches for them during the assessment or export the results.
Using the ready-made searches
Secureframe adds ready-made searches that answer the questions assessors ask most often. You'll find them under Secureframe Audit Evidence:
Remote access sessions: Who connected to a desktop, from which address, and for how long.
Sign-ins and sign-outs: Who signed in to a desktop, and how.
Failed sign-ins: Sign-in attempts that didn't work, and why.
Objects accessed: Who opened tracked files and folders, or changed their permissions.
Privileges assigned: Who was given admin rights, and sensitive actions taken with them.
Changes to audit policy: Any change to what Windows records, or to the records themselves.
Accounts created: Accounts created on a desktop, and changes to group membership.
Data share access: Who opened, changed, or deleted files on the shared drive (Z:).
Key vault reads and writes: Who read or changed a password in the secure password store.
Who queried the audit log: Who searched your records, and what they searched for.
Network flows: Network connections that were allowed or blocked, and the rule that decided.
Writing your own searches
If your IT team writes its own searches, this is where each type of record is kept in the workspace.
Records | Where to find them |
Microsoft sign-ins | SigninLogs, AADServicePrincipalSignInLogs, AuditLogs |
Connections to a desktop | WVDConnections, WVDErrors, WVDCheckpoints, WVDConnectionNetworkData, WVDFeeds, WVDSessionHostManagement, WVDManagement, WVDHostRegistrations, WVDAgentHealthStatus, WVDAutoscaleEvaluationPooled |
Activity on a desktop, tracked files and folders | Event |
Shared drive (Z:) | StorageFileLogs |
Password store | AZKVAuditLogs |
Network traffic | NTANetAnalytics |
Searches of the records | LAQueryLogs |
Frequently Asked Questions (FAQ)
Do I need to turn on Activity Logging?
No. Secureframe sets it up automatically when it creates your Virtual Desktops.
Does Secureframe store my records?
No. Secureframe sets up the log workspace and configures what goes into it, but the records are stored in your own Azure Government environment and appear on your Azure bill.
How long are records kept?
One year. Detailed network traffic data is kept for 30 days, with a summary kept for the full year.
Who can see the records?
Anyone with access to your Azure Government subscription who has permission to read the log workspace. Every search is recorded, so you can always see who looked.
Can anyone delete the records?
Secureframe adds a lock to your workspace so records can't be deleted by mistake or by someone without the right access. Owners of your Azure subscription can remove the lock at any time, and Azure records who removed it.
Who receives the alerts?
Everyone on your alert list. The person who set up your Virtual Desktops is added automatically, and you can add or remove people at any time. From the Virtual Desktops page, open Settings, and find Security alert notifications on the General tab.
Why don't I see Microsoft sign-in records yet?
Microsoft can take some time to start sending sign-in records after setup. Desktop and shared drive records show up sooner.
Does this record everyone in my organization?
Microsoft sign-in records and account changes cover everyone in your Microsoft account. Everything else covers only your Virtual Desktops.
Questions? Contact [email protected] or reach out to your CSM.
