An Azure NoSQL database service for app development.
Hi Anil Kumar,
Welcome to Microsoft Q&A,
With key-based auth, this can't be answered per person, and your logs are behaving as documented. The account key is a shared secret, so every request looks the same. The UserId column in MongoRequests is only populated when role-based access control is enabled, and it stays empty otherwise. Here is how to get real attribution:
- Enable RBAC on the account. Add the
EnableMongoRoleBasedAccessControlcapability (Azure portal > your account > Features, or via CLI). Then create roles and users in each database and give every person or app its own user with only the privileges it needs. Steps and commands: How to set up RBAC. - Move clients to those users. Apps connect with username and password (SCRAM-SHA-256) instead of the account key. Once a request is made with a user,
UserIdinCDBMongoRequestsshows who ran it. This only works going forward, not for past requests. - Get the query text.
PIICommandTextis empty until you opt in to full-text query logging, which you can request for the account. Use it together withOperationName,DatabaseNameandCollectionNameto see what changed. See the CDBMongoRequests table. - For account or collection changes made through the portal, CLI or ARM, the caller is in the Activity Log, not in
CDBControlPlaneRequests. Export it to your workspace: Azure Monitor > Activity log > Export Activity Logs, then query theAzureActivitytable. See Azure Monitor activity log. - For the history you already have, the best you can do is what you found: the client IP in
AddressandUserAgent(a .NET app on Windows Server 2022) tell you which application or server made the calls, not which person.
Please note that the account key still works after RBAC is turned on. Rotate it or restrict who has it once your apps use user credentials; otherwise, anyone with the key can still bypass attribution.
Please click Accept Answer and upvote if this helped.