Azure RBAC and Authorization Azure-Microsoft.Authorization
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.Authorization rules that match the resource provider but no specific operation. | N | N |
| Microsoft.Authorization/ | Delete a deny assignment at the specified scope. | N | N |
| Microsoft.Authorization/ | Create a deny assignment at the specified scope. | N | N |
| Microsoft.Authorization/ | Delete diagnostics settings | N | N |
| Microsoft.Authorization/ | Create or update the information of diagnostics settings | N | N |
| Microsoft.Authorization/ | Grants the caller User Access Administrator access at the tenant scope | N | Y |
| Microsoft.Authorization/ | Delete locks at the specified scope. | Y | Y |
| Microsoft.Authorization/ | Add locks at the specified scope. | Y | N |
| Microsoft.Authorization/ | Action taken as a result of evaluation of Azure Policy with 'audit' effect | Y | Y |
| Microsoft.Authorization/ | Action taken as a result of evaluation of Azure Policy with 'auditIfNotExists' effect | Y | Y |
| Microsoft.Authorization/ | Action taken as a result of evaluation of Azure Policy with 'deny' effect | N | N |
| Microsoft.Authorization/ | Action taken as a result of evaluation of Azure Policy with 'deployIfNotExists' effect | N | Y |
| Microsoft.Authorization/ | Azure Policy 'modify' effect operation recorded in the activity log when a modify-effect policy assignment adds, updates, or removes properties or tags on a resource during a create or update. Sibling of the deny, audit, auditIfNotExists, and deployIfNotExists policy-effect operations already in the map. | N | N |
| Microsoft.Authorization/ | Delete a policy assignment at the specified scope. | N | N |
| Microsoft.Authorization/ | Exempt a policy assignment at the specified scope. | N | N |
| Microsoft.Authorization/ | Deletes a private link association. | N | N |
| Microsoft.Authorization/ | Creates or updates a private link association. | N | N |
| Microsoft.Authorization/ | Deletes a resource management private link. | N | N |
| Microsoft.Authorization/ | Deletes a private endpoint connection proxy. | N | N |
| Microsoft.Authorization/ | Validates a private endpoint connection proxy. | N | N |
| Microsoft.Authorization/ | Creates or updates a private endpoint connection proxy. | N | N |
| Microsoft.Authorization/ | Deletes a private endpoint connection. | N | N |
| Microsoft.Authorization/ | Creates or updates a private endpoint connection. | N | N |
| Microsoft.Authorization/ | Creates or updates a resource management private link. | N | N |
| Microsoft.Authorization/ | Create a policy assignment at the specified scope. | Y | N |
| Microsoft.Authorization/ | Delete a policy definition. | Y | N |
| Microsoft.Authorization/ | Delete a policy definition version. | N | N |
| Microsoft.Authorization/ | Create a custom policy definition version. | N | N |
| Microsoft.Authorization/ | Create a custom policy definition. | Y | N |
| Microsoft.Authorization/ | Delete a policy enrollment at the specified scope. | N | N |
| Microsoft.Authorization/ | Create a policy enrollment at the specified scope. | N | N |
| Microsoft.Authorization/ | Delete a policy exemption at the specified scope. | N | N |
| Microsoft.Authorization/ | Create a policy exemption at the specified scope. | N | N |
| Microsoft.Authorization/ | Delete a policy set definition. | N | N |
| Microsoft.Authorization/ | Delete a policy set definition version. | N | N |
| Microsoft.Authorization/ | Create a custom policy set definition version. | N | N |
| Microsoft.Authorization/ | Create a custom policy set definition. | N | N |
| Microsoft.Authorization/ | Delete a role assignment at the specified scope. | N | N |
| Microsoft.Authorization/ | Create a role assignment at the specified scope. | Y | Y |
| Microsoft.Authorization/ | Cancels a pending role assignment schedule request. | N | N |
| Microsoft.Authorization/ | Creates a role assignment schedule request at given scope. | N | N |
| Microsoft.Authorization/ | Delete the specified custom role definition. | N | N |
| Microsoft.Authorization/ | Create or update a custom role definition with specified permissions and assignable scopes. | Y | N |
| Microsoft.Authorization/ | Cancels a pending role eligibility schedule request. | N | N |
| Microsoft.Authorization/ | Creates a role eligibility schedule request at given scope when approval is required | N | N |
| Microsoft.Authorization/ | Creates a role eligibility schedule request at given scope. | N | N |
| Microsoft.Authorization/ | Update Role Management policy approval rule | N | N |
| Microsoft.Authorization/ | Update a role management policy | N | N |
any: Azure RBAC and Authorization (catch-all)
#- Namespace
- Microsoft.Authorization
Description
Catch-all for Azure-Microsoft.Authorization rules that match the resource provider but no specific operation.
Microsoft.Authorization/denyAssignments/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a deny assignment at the specified scope.
Microsoft.Authorization/denyAssignments/write
#- Namespace
- Microsoft.Authorization
Description
Create a deny assignment at the specified scope.
Microsoft.Authorization/diagnosticSettings/delete
#- Namespace
- Microsoft.Authorization
Description
Delete diagnostics settings
Microsoft.Authorization/diagnosticSettings/write
#- Namespace
- Microsoft.Authorization
Description
Create or update the information of diagnostics settings
Microsoft.Authorization/elevateAccess/action
#- Namespace
- Microsoft.Authorization
Description
Grants the caller User Access Administrator access at the tenant scope
Related events #
Events that co-occur with this one in the same detection rules (shared multi-event coverage), most-shared first. These are likely companion or next steps to pivot an investigation to.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004Panther #
T1078.004, T1098, T1098.003↳ also matches Microsoft.Authorization/roleAssignments/write
Microsoft.Authorization/locks/delete
#- Namespace
- Microsoft.Authorization
Description
Delete locks at the specified scope.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/dwharn-lock-7000408c",
"action": "Microsoft.Authorization/locks/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/dwharn-lock-7000408c",
"action": "Microsoft.Authorization/locks/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783008141",
"nbf": "1783008141",
"exp": "1783012267",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "joig862JV0W_vEH8aP97AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 8",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783008141",
"nbf": "1783008141",
"exp": "1783012267",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "joig862JV0W_vEH8aP97AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 8",
"xms_tcdt": "1768616282"
},
"CorrelationId": "eb328c31-a65f-4aa5-b6f4-abbe4cc25f17",
"EventDataId": "bcbaad75-f1f3-0357-2304-8088e778debe",
"EventSubmissionTimestamp": "2026-07-02T16:41:28.5825069Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/LOCKS/DELETE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/dwharn-lock-7000408c",
"message": "Microsoft.Authorization/locks/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "bcbaad75-f1f3-0357-2304-8088e778debe",
"eventSubmissionTimestamp": "2026-07-02T16:41:28.5825069Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwharn-lock-7000408c",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/dwharn-lock-7000408c",
"message": "Microsoft.Authorization/locks/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "bcbaad75-f1f3-0357-2304-8088e778debe",
"eventSubmissionTimestamp": "2026-07-02T16:41:28.5825069Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwharn-lock-7000408c",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1490, T1562, T1562.001
Microsoft.Authorization/locks/write
#- Namespace
- Microsoft.Authorization
Description
Add locks at the specified scope.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/zclock3",
"action": "Microsoft.Authorization/locks/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/zclock3",
"action": "Microsoft.Authorization/locks/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "c9510c65-de21-485f-907c-fc075a5017f0",
"EventDataId": "114d0225-5be2-797f-22b6-582734b9e3c9",
"EventSubmissionTimestamp": "2026-06-29T19:04:04.5851583Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/LOCKS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/zclock3",
"message": "Microsoft.Authorization/locks/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "114d0225-5be2-797f-22b6-582734b9e3c9",
"eventSubmissionTimestamp": "2026-06-29T19:04:04.5851583Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zclock3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/locks/zclock3",
"message": "Microsoft.Authorization/locks/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "114d0225-5be2-797f-22b6-582734b9e3c9",
"eventSubmissionTimestamp": "2026-06-29T19:04:04.5851583Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zclock3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:04:04.5851583Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.authorization/locks/zclock3"
}
Microsoft.Authorization/policies/audit/action
#- Namespace
- Microsoft.Authorization
Description
Action taken as a result of evaluation of Azure Policy with 'audit' effect
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Policy",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
"EventDataId": "397a6f34-dcf2-d346-d6ec-c89380dcce97",
"EventSubmissionTimestamp": "2026-06-29T18:13:41.3482697Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "",
"Level": "Warning",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/POLICIES/AUDIT/ACTION",
"Properties": {
"isComplianceCheck": "False",
"resourceLocation": "westus2",
"ancestors": "11111111-1111-1111-1111-111111111111",
"policies": [
{
"policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/9daedab3-fb2d-461e-b861-71790eead4f6",
"policySetDefinitionId": "/providers/Microsoft.Authorization/policySetDefinitions/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"policyDefinitionReferenceId": "nextGenerationFirewallMonitoring",
"policySetDefinitionName": "1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"policySetDefinitionDisplayName": "Microsoft cloud security benchmark",
"policySetDefinitionVersion": "57.56.0",
"policyDefinitionName": "9daedab3-fb2d-461e-b861-71790eead4f6",
"policyDefinitionDisplayName": "All network ports should be restricted on network security groups associated to your virtual machine",
"policyDefinitionVersion": "3.0.0",
"policyDefinitionEffect": "AuditIfNotExists",
"policyAssignmentId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn",
"policyAssignmentName": "SecurityCenterBuiltIn",
"policyAssignmentDisplayName": "ASC Default (subscription: 22222222-2222-2222-2222-222222222222)",
"policyAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"policyAssignmentEnforcementMode": "Default",
"policyExemptionIds": [],
"policyEnrollmentIds": []
}
],
"eventCategory": "Policy",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Authorization/policies/audit/action",
"hierarchy": "",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "397a6f34-dcf2-d346-d6ec-c89380dcce97",
"eventSubmissionTimestamp": "2026-06-29T18:13:41.3482697Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Policy",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Authorization/policies/audit/action",
"hierarchy": "",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "397a6f34-dcf2-d346-d6ec-c89380dcce97",
"eventSubmissionTimestamp": "2026-06-29T18:13:41.3482697Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"isComplianceCheck": "False",
"resourceLocation": "westus2",
"ancestors": "11111111-1111-1111-1111-111111111111",
"policies": [
{
"policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/9daedab3-fb2d-461e-b861-71790eead4f6",
"policySetDefinitionId": "/providers/Microsoft.Authorization/policySetDefinitions/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"policyDefinitionReferenceId": "nextGenerationFirewallMonitoring",
"policySetDefinitionName": "1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"policySetDefinitionDisplayName": "Microsoft cloud security benchmark",
"policySetDefinitionVersion": "57.56.0",
"policyDefinitionName": "9daedab3-fb2d-461e-b861-71790eead4f6",
"policyDefinitionDisplayName": "All network ports should be restricted on network security groups associated to your virtual machine",
"policyDefinitionVersion": "3.0.0",
"policyDefinitionEffect": "AuditIfNotExists",
"policyAssignmentId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn",
"policyAssignmentName": "SecurityCenterBuiltIn",
"policyAssignmentDisplayName": "ASC Default (subscription: 22222222-2222-2222-2222-222222222222)",
"policyAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"policyAssignmentEnforcementMode": "Default",
"policyExemptionIds": [],
"policyEnrollmentIds": []
}
]
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:13:41.3482697Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/virtualmachines/zcvm"
}
Related events #
Events that co-occur with this one in the same detection rules (shared multi-event coverage), most-shared first. These are likely companion or next steps to pivot an investigation to.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
Microsoft.Authorization/policies/auditIfNotExists/action
#- Namespace
- Microsoft.Authorization
Description
Action taken as a result of evaluation of Azure Policy with 'auditIfNotExists' effect
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Policy",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
"EventDataId": "4c8c2573-aeba-7513-e94f-ffd84069adee",
"EventSubmissionTimestamp": "2026-06-29T18:13:41.3482697Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/POLICIES/AUDITIFNOTEXISTS/ACTION",
"Properties": {
"isComplianceCheck": "False",
"resourceLocation": "westus2",
"ancestors": "11111111-1111-1111-1111-111111111111",
"policies": [
{
"policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/9daedab3-fb2d-461e-b861-71790eead4f6",
"policySetDefinitionId": "/providers/Microsoft.Authorization/policySetDefinitions/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"policyDefinitionReferenceId": "nextGenerationFirewallMonitoring",
"policySetDefinitionVersion": "57.56.0",
"policyDefinitionVersion": "3.0.0",
"policyAssignmentId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn",
"policyEnrollmentIds": []
}
],
"eventCategory": "Policy",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Authorization/policies/auditIfNotExists/action",
"hierarchy": "",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "4c8c2573-aeba-7513-e94f-ffd84069adee",
"eventSubmissionTimestamp": "2026-06-29T18:13:41.3482697Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Policy",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Authorization/policies/auditIfNotExists/action",
"hierarchy": "",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "4c8c2573-aeba-7513-e94f-ffd84069adee",
"eventSubmissionTimestamp": "2026-06-29T18:13:41.3482697Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"isComplianceCheck": "False",
"resourceLocation": "westus2",
"ancestors": "11111111-1111-1111-1111-111111111111",
"policies": [
{
"policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/9daedab3-fb2d-461e-b861-71790eead4f6",
"policySetDefinitionId": "/providers/Microsoft.Authorization/policySetDefinitions/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"policyDefinitionReferenceId": "nextGenerationFirewallMonitoring",
"policySetDefinitionVersion": "57.56.0",
"policyDefinitionVersion": "3.0.0",
"policyAssignmentId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn",
"policyEnrollmentIds": []
}
]
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:13:41.3482697Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/virtualmachines/zcvm"
}
Related events #
Events that co-occur with this one in the same detection rules (shared multi-event coverage), most-shared first. These are likely companion or next steps to pivot an investigation to.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
Microsoft.Authorization/policies/deny/action
#- Namespace
- Microsoft.Authorization
Description
Action taken as a result of evaluation of Azure Policy with 'deny' effect
Microsoft.Authorization/policies/deployIfNotExists/action
#- Namespace
- Microsoft.Authorization
Description
Action taken as a result of evaluation of Azure Policy with 'deployIfNotExists' effect
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1078.004, T1564
Microsoft.Authorization/policies/modify/action
#- Namespace
- Microsoft.Authorization
Description
Azure Policy 'modify' effect operation recorded in the activity log when a modify-effect policy assignment adds, updates, or removes properties or tags on a resource during a create or update. Sibling of the deny, audit, auditIfNotExists, and deployIfNotExists policy-effect operations already in the map.
Microsoft.Authorization/policyAssignments/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy assignment at the specified scope.
Microsoft.Authorization/policyAssignments/exempt/action
#- Namespace
- Microsoft.Authorization
Description
Exempt a policy assignment at the specified scope.
Microsoft.Authorization/policyAssignments/privateLinkAssociations/delete
#- Namespace
- Microsoft.Authorization
Description
Deletes a private link association.
Microsoft.Authorization/policyAssignments/privateLinkAssociations/write
#- Namespace
- Microsoft.Authorization
Description
Creates or updates a private link association.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/delete
#- Namespace
- Microsoft.Authorization
Description
Deletes a resource management private link.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/delete
#- Namespace
- Microsoft.Authorization
Description
Deletes a private endpoint connection proxy.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/validate/action
#- Namespace
- Microsoft.Authorization
Description
Validates a private endpoint connection proxy.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnectionProxies/write
#- Namespace
- Microsoft.Authorization
Description
Creates or updates a private endpoint connection proxy.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnections/delete
#- Namespace
- Microsoft.Authorization
Description
Deletes a private endpoint connection.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/privateEndpointConnections/write
#- Namespace
- Microsoft.Authorization
Description
Creates or updates a private endpoint connection.
Microsoft.Authorization/policyAssignments/resourceManagementPrivateLinks/write
#- Namespace
- Microsoft.Authorization
Description
Creates or updates a resource management private link.
Microsoft.Authorization/policyAssignments/write
#- Namespace
- Microsoft.Authorization
Description
Create a policy assignment at the specified scope.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/policyAssignments/zcpola",
"action": "Microsoft.Authorization/policyAssignments/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/policyAssignments/zcpola",
"action": "Microsoft.Authorization/policyAssignments/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "c9090719-2009-4330-8794-c6806fdec5b1",
"EventDataId": "9daf4cff-4eee-ae4e-6782-4ead9eea43d5",
"EventSubmissionTimestamp": "2026-06-29T17:39:17.6253711Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/POLICYASSIGNMENTS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/policyAssignments/zcpola",
"message": "Microsoft.Authorization/policyAssignments/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9daf4cff-4eee-ae4e-6782-4ead9eea43d5",
"eventSubmissionTimestamp": "2026-06-29T17:39:17.6253711Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcpola",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/policyAssignments/zcpola",
"message": "Microsoft.Authorization/policyAssignments/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9daf4cff-4eee-ae4e-6782-4ead9eea43d5",
"eventSubmissionTimestamp": "2026-06-29T17:39:17.6253711Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcpola",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created",
"resourceGroup": "RG-LOGCAPTURE-GEN"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:39:17.6253711Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.authorization/policyassignments/zcpola"
}
Microsoft.Authorization/policyDefinitions/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy definition.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/dwh2220afpolicydefiniti",
"action": "Microsoft.Authorization/policyDefinitions/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/dwh2220afpolicydefiniti",
"action": "Microsoft.Authorization/policyDefinitions/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "0db54d31-89ff-4def-9440-99c4ec1f0ad5",
"EventDataId": "d9e22407-2166-4fd5-70f1-bf1f382eed95",
"EventSubmissionTimestamp": "2026-07-02T18:26:47.1420128Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/POLICYDEFINITIONS/DELETE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"responseBody": {
"properties": {
"policyType": "Custom",
"mode": "Indexed",
"metadata": "******",
"version": "1.0.0",
"policyRule": "******",
"versions": [
"1.0.0"
]
},
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/dwh2220afpolicydefiniti",
"type": "Microsoft.Authorization/policyDefinitions",
"name": "dwh2220afpolicydefiniti",
"systemData": {
"createdBy": "adminuser@example.onmicrosoft.com",
"createdByType": "User",
"createdAt": "2026-07-02T18:26:45.2815764Z",
"lastModifiedBy": "adminuser@example.onmicrosoft.com",
"lastModifiedByType": "User",
"lastModifiedAt": "2026-07-02T18:26:45.2815764Z"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/dwh2220afpolicydefiniti",
"message": "Microsoft.Authorization/policyDefinitions/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d9e22407-2166-4fd5-70f1-bf1f382eed95",
"eventSubmissionTimestamp": "2026-07-02T18:26:47.1420128Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afpolicydefiniti",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/dwh2220afpolicydefiniti",
"message": "Microsoft.Authorization/policyDefinitions/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d9e22407-2166-4fd5-70f1-bf1f382eed95",
"eventSubmissionTimestamp": "2026-07-02T18:26:47.1420128Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afpolicydefiniti",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK",
"responseBody": {
"properties": {
"policyType": "Custom",
"mode": "Indexed",
"metadata": "******",
"version": "1.0.0",
"policyRule": "******",
"versions": [
"1.0.0"
]
},
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/dwh2220afpolicydefiniti",
"type": "Microsoft.Authorization/policyDefinitions",
"name": "dwh2220afpolicydefiniti",
"systemData": {
"createdBy": "adminuser@example.onmicrosoft.com",
"createdByType": "User",
"createdAt": "2026-07-02T18:26:45.2815764Z",
"lastModifiedBy": "adminuser@example.onmicrosoft.com",
"lastModifiedByType": "User",
"lastModifiedAt": "2026-07-02T18:26:45.2815764Z"
}
}
},
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Authorization/policyDefinitions/versions/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy definition version.
Microsoft.Authorization/policyDefinitions/versions/write
#- Namespace
- Microsoft.Authorization
Description
Create a custom policy definition version.
Microsoft.Authorization/policyDefinitions/write
#- Namespace
- Microsoft.Authorization
Description
Create a custom policy definition.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/zcpol",
"action": "Microsoft.Authorization/policyDefinitions/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/zcpol",
"action": "Microsoft.Authorization/policyDefinitions/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "70b299cc-f378-4158-abe6-3514fdd6e886",
"EventDataId": "d3ee7466-6d26-de90-1cbd-ef1f548bf80c",
"EventSubmissionTimestamp": "2026-06-29T17:39:12.5892933Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/POLICYDEFINITIONS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/zcpol",
"message": "Microsoft.Authorization/policyDefinitions/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d3ee7466-6d26-de90-1cbd-ef1f548bf80c",
"eventSubmissionTimestamp": "2026-06-29T17:39:12.5892933Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcpol",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/policyDefinitions/zcpol",
"message": "Microsoft.Authorization/policyDefinitions/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d3ee7466-6d26-de90-1cbd-ef1f548bf80c",
"eventSubmissionTimestamp": "2026-06-29T17:39:12.5892933Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcpol",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created"
},
"Resource": "",
"ResourceGroup": "",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:39:12.5892933Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.authorization/policydefinitions/zcpol"
}
Microsoft.Authorization/policyEnrollments/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy enrollment at the specified scope.
Microsoft.Authorization/policyEnrollments/write
#- Namespace
- Microsoft.Authorization
Description
Create a policy enrollment at the specified scope.
Microsoft.Authorization/policyExemptions/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy exemption at the specified scope.
Microsoft.Authorization/policyExemptions/write
#- Namespace
- Microsoft.Authorization
Description
Create a policy exemption at the specified scope.
Microsoft.Authorization/policySetDefinitions/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy set definition.
Microsoft.Authorization/policySetDefinitions/versions/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a policy set definition version.
Microsoft.Authorization/policySetDefinitions/versions/write
#- Namespace
- Microsoft.Authorization
Description
Create a custom policy set definition version.
Microsoft.Authorization/policySetDefinitions/write
#- Namespace
- Microsoft.Authorization
Description
Create a custom policy set definition.
Microsoft.Authorization/roleAssignments/delete
#- Namespace
- Microsoft.Authorization
Description
Delete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/write
#- Namespace
- Microsoft.Authorization
Description
Create a role assignment at the specified scope.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/roleAssignments/b06cd430-a8c6-4557-ba13-fe96179df71a",
"action": "Microsoft.Authorization/roleAssignments/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/roleAssignments/b06cd430-a8c6-4557-ba13-fe96179df71a",
"action": "Microsoft.Authorization/roleAssignments/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "d06e860a-50ae-44cb-b0d3-a9e48005cc62",
"EventDataId": "16cdac08-266a-fb51-3c78-c5e2ebc1785e",
"EventSubmissionTimestamp": "2026-06-29T18:29:27.4873736Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/roleAssignments/b06cd430-a8c6-4557-ba13-fe96179df71a",
"message": "Microsoft.Authorization/roleAssignments/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "16cdac08-266a-fb51-3c78-c5e2ebc1785e",
"eventSubmissionTimestamp": "2026-06-29T18:29:27.4873736Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "b06cd430-a8c6-4557-ba13-fe96179df71a",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Authorization/roleAssignments/b06cd430-a8c6-4557-ba13-fe96179df71a",
"message": "Microsoft.Authorization/roleAssignments/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "16cdac08-266a-fb51-3c78-c5e2ebc1785e",
"eventSubmissionTimestamp": "2026-06-29T18:29:27.4873736Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "b06cd430-a8c6-4557-ba13-fe96179df71a",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created",
"resourceGroup": "RG-LOGCAPTURE-GEN"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:29:27.4873736Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.authorization/roleassignments/b06cd430-a8c6-4557-ba13-fe96179df71a"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
count_ (kusto rule field) | ge | 5 | 1 rule | kusto |
properties.statusCode (sigma rule field) | eq | created | 1 rule | sigma |
Related events #
Events that co-occur with this one in the same detection rules (shared multi-event coverage), most-shared first. These are likely companion or next steps to pivot an investigation to.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1098.003Elastic #
T1098, T1098.003Kusto #
T1098, T1548Panther #
T1078.004, T1098, T1098.003↳ also matches Microsoft.Authorization/elevateAccess/action
Microsoft.Authorization/roleAssignmentScheduleRequests/cancel/action
#- Namespace
- Microsoft.Authorization
Description
Cancels a pending role assignment schedule request.
Microsoft.Authorization/roleAssignmentScheduleRequests/write
#- Namespace
- Microsoft.Authorization
Description
Creates a role assignment schedule request at given scope.
Microsoft.Authorization/roleDefinitions/delete
#- Namespace
- Microsoft.Authorization
Description
Delete the specified custom role definition.
Microsoft.Authorization/roleDefinitions/write
#- Namespace
- Microsoft.Authorization
Description
Create or update a custom role definition with specified permissions and assignable scopes.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/roleDefinitions/b6245d76-350e-401e-8fcf-3b66e2ce7b1f",
"action": "Microsoft.Authorization/roleDefinitions/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/roleDefinitions/b6245d76-350e-401e-8fcf-3b66e2ce7b1f",
"action": "Microsoft.Authorization/roleDefinitions/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "4b0b1024-cdd1-4f56-b7b9-dd0fa23e5222",
"EventDataId": "702e9d2e-9d17-690a-d372-7b29635b8dd3",
"EventSubmissionTimestamp": "2026-06-29T19:04:08.0408527Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.AUTHORIZATION/ROLEDEFINITIONS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/roleDefinitions/b6245d76-350e-401e-8fcf-3b66e2ce7b1f",
"message": "Microsoft.Authorization/roleDefinitions/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "702e9d2e-9d17-690a-d372-7b29635b8dd3",
"eventSubmissionTimestamp": "2026-06-29T19:04:08.0408527Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "b6245d76-350e-401e-8fcf-3b66e2ce7b1f",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Authorization/roleDefinitions/b6245d76-350e-401e-8fcf-3b66e2ce7b1f",
"message": "Microsoft.Authorization/roleDefinitions/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "702e9d2e-9d17-690a-d372-7b29635b8dd3",
"eventSubmissionTimestamp": "2026-06-29T19:04:08.0408527Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "b6245d76-350e-401e-8fcf-3b66e2ce7b1f",
"resourceProviderValue": "MICROSOFT.AUTHORIZATION",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Resource": "",
"ResourceGroup": "",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.AUTHORIZATION",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:04:08.0408527Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.authorization/roledefinitions/b6245d76-350e-401e-8fcf-3b66e2ce7b1f"
}
Microsoft.Authorization/roleEligibilityScheduleRequests/cancel/action
#- Namespace
- Microsoft.Authorization
Description
Cancels a pending role eligibility schedule request.
Microsoft.Authorization/roleEligibilityScheduleRequests/whenApprovalRequired/write
#- Namespace
- Microsoft.Authorization
Description
Creates a role eligibility schedule request at given scope when approval is required
Microsoft.Authorization/roleEligibilityScheduleRequests/write
#- Namespace
- Microsoft.Authorization
Description
Creates a role eligibility schedule request at given scope.
Microsoft.Authorization/roleManagementPolicies/approvalRule/action
#- Namespace
- Microsoft.Authorization
Description
Update Role Management policy approval rule
Microsoft.Authorization/roleManagementPolicies/write
#- Namespace
- Microsoft.Authorization
Description
Update a role management policy