CLI reference / azure / unusual-activity / diagnose

stado azure unusual-activity diagnose

Invocation

stado azure unusual-activity diagnose [OPTIONS]

Purpose

Report inherited system-protected UnusualActivity deny assignments

Required inputs and options

Input or optionContract
--subscription <SUBSCRIPTION>Azure subscription to inspect; defaults to AZURE_SUBSCRIPTION_ID/config
--operator-item <OPERATOR_ITEM>Owner-only Skarbiec item containing the operator refresh token [default: stado-azure-operator]

Output and state effect

This is an inspection/reporting operation. It emits the result described above and does not change managed state unless an explicit option in this page says otherwise. Pass `--json` when the command exposes that machine-readable option.

Refusals

  • Before dispatch, Stado refuses a missing required token shown in the invocation, an unknown option, or a value outside a listed value set; argument-usage failures exit with code 2.