Azure AI Services (Cognitive Services) Azure-Microsoft.CognitiveServices

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.CognitiveServices rules that match the resource provider but no specific operation.NN
Microsoft.CognitiveServices/accounts/capabilityHosts/deleteDelete a capability hostNN
Microsoft.CognitiveServices/accounts/capabilityHosts/writeWrite a capability hostNN
Microsoft.CognitiveServices/accounts/commitmentplans/deleteDeletes commitment plans.NN
Microsoft.CognitiveServices/accounts/commitmentplans/writeWrites commitment plans.NN
Microsoft.CognitiveServices/accounts/connections/deleteDelete a connectionNN
Microsoft.CognitiveServices/accounts/connections/listsecrets/actionList secretsNN
Microsoft.CognitiveServices/accounts/connections/writeWrite a connectionNN
Microsoft.CognitiveServices/accounts/defenderForAISettings/deleteDeletes a custom Responsible AI policy that's not referenced by an existing deployment.NN
Microsoft.CognitiveServices/accounts/defenderForAISettings/writeCreate or update a custom Responsible AI policy.NN
Microsoft.CognitiveServices/accounts/deleteDeletes API accountsYN
Microsoft.CognitiveServices/accounts/deployments/deleteDeletes deployments.NN
Microsoft.CognitiveServices/accounts/deployments/writeWrites deployments.NN
Microsoft.CognitiveServices/accounts/encryptionScopes/deleteDeletes an Encryption Scope.NN
Microsoft.CognitiveServices/accounts/encryptionScopes/writeWrites an Encryption Scope.NN
Microsoft.CognitiveServices/accounts/joinPerimeter/actionAllow to join CognitiveServices account to an given perimeter.NN
Microsoft.CognitiveServices/accounts/listKeys/actionList keysNY
Microsoft.CognitiveServices/accounts/managedComputeDeployments/deleteDeletes Managed Compute Deployments.NN
Microsoft.CognitiveServices/accounts/managedComputeDeployments/writeCreates or updates Managed Compute Deployments.NN
Microsoft.CognitiveServices/accounts/managedNetworks/batchOutboundRules/actionManages the outbound rules of the managed network associated with the Cognitive Services Account.NN
Microsoft.CognitiveServices/accounts/managedNetworks/outboundRules/deleteDeletes an outbound rule of managed network associated with the Cognitive Services Account.NN
Microsoft.CognitiveServices/accounts/managedNetworks/outboundRules/writeCreates or updates an outbound rule of managed network associated with the Cognitive Services Account.NN
Microsoft.CognitiveServices/accounts/managedNetworks/writeCreates or updates the managed network associated with the Cognitive Services Account.NN
Microsoft.CognitiveServices/accounts/networkSecurityPerimeterAssociationProxies/deleteDeletes a network security perimeter association.NN
Microsoft.CognitiveServices/accounts/networkSecurityPerimeterAssociationProxies/writeWrites a network security perimeter association.NN
Microsoft.CognitiveServices/accounts/networkSecurityPerimeterConfigurations/reconcile/actionReconcile effective Network Security Perimeters configurationNN
Microsoft.CognitiveServices/accounts/privateEndpointConnectionProxies/deleteDeletes a private endpoint connections.NN
Microsoft.CognitiveServices/accounts/privateEndpointConnectionProxies/validate/actionValidates private endpoint connection proxies (internal use only).NN
Microsoft.CognitiveServices/accounts/privateEndpointConnectionProxies/writeWrites private endpoint connection proxies (internal use only).NN
Microsoft.CognitiveServices/accounts/privateEndpointConnections/deleteDeletes a private endpoint connections.NN
Microsoft.CognitiveServices/accounts/privateEndpointConnections/writeWrites a private endpoint connections.NN
Microsoft.CognitiveServices/accounts/privateEndpointConnectionsApproval/actionApproves Private EndpointNN
Microsoft.CognitiveServices/accounts/projects/applications/actionEnables or disables an applicationNN
Microsoft.CognitiveServices/accounts/projects/applications/agentdeployments/actionStarts or stops an application agent deploymentNN
Microsoft.CognitiveServices/accounts/projects/applications/agentdeployments/deleteDeletes an agent deployment under an applicationNN
Microsoft.CognitiveServices/accounts/projects/applications/agentdeployments/writeWrites an agent deployment for an applicationNN
Microsoft.CognitiveServices/accounts/projects/applications/deleteDeletes an applicationNN
Microsoft.CognitiveServices/accounts/projects/applications/writeWrites an applicationNN
Microsoft.CognitiveServices/accounts/projects/capabilityHosts/deleteDelete a capability hostNN
Microsoft.CognitiveServices/accounts/projects/capabilityHosts/writeWrite a capability hostNN
Microsoft.CognitiveServices/accounts/projects/connections/deleteDelete a connectionNN
Microsoft.CognitiveServices/accounts/projects/connections/listsecrets/actionList secretsNN
Microsoft.CognitiveServices/accounts/projects/connections/writeWrite a connectionNN
Microsoft.CognitiveServices/accounts/projects/deleteDelete a projectNN
Microsoft.CognitiveServices/accounts/projects/writeWrite a projectNN
Microsoft.CognitiveServices/accounts/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resource.NN
Microsoft.CognitiveServices/accounts/provisionManagedNetwork/actionProvision the managed network of the Cognitive Services Account.NN
Microsoft.CognitiveServices/accounts/raiBlocklists/addRaiBlocklistItems/actionBatch adds blocklist items under a blocklist.NN
Microsoft.CognitiveServices/accounts/raiBlocklists/deleteDeletes blocklists under a resourceNN
Microsoft.CognitiveServices/accounts/raiBlocklists/deleteRaiBlocklistItems/actionBatch deletes blocklist items under a blocklist.NN
Microsoft.CognitiveServices/accounts/raiBlocklists/raiBlocklistItems/deleteDeletes blocklist items under a blocklist.NN
Microsoft.CognitiveServices/accounts/raiBlocklists/raiBlocklistItems/writeModifies blocklist items under a blocklist.NN
Microsoft.CognitiveServices/accounts/raiBlocklists/writeModifies available blocklists under a resource.NN
Microsoft.CognitiveServices/accounts/raiIfcRules/deleteDeletes Ifc Rules under a resourceNN
Microsoft.CognitiveServices/accounts/raiIfcRules/writeModifies available Ifc Rules under a resource.NN
Microsoft.CognitiveServices/accounts/raiModerationlists/addRaiModerationTerms/actionBatch adds moderation terms under a moderation listNN
Microsoft.CognitiveServices/accounts/raiModerationlists/deleteDeletes moderation lists under a resourceNN
Microsoft.CognitiveServices/accounts/raiModerationlists/deleteRaiModerationTerms/actionBatch deletes moderation terms under a moderation listNN
Microsoft.CognitiveServices/accounts/raiModerationlists/raiModerationTerms/deleteDelete terms under a customer moderation listNN
Microsoft.CognitiveServices/accounts/raiModerationlists/raiModerationTerms/writeWrite Terms under a customer moderation listNN
Microsoft.CognitiveServices/accounts/raiModerationlists/writeModifies available moderation lists under a resource.NN
Microsoft.CognitiveServices/accounts/raiPolicies/deleteDeletes a custom Responsible AI policy that's not referenced by an existing deployment.NN
Microsoft.CognitiveServices/accounts/raiPolicies/writeCreate or update a custom Responsible AI policy.NN
Microsoft.CognitiveServices/accounts/raiToolLabels/deleteDeletes Tool Labels under a resourceNN
Microsoft.CognitiveServices/accounts/raiToolLabels/writeModifies available Tool Labels under a resource.NN
Microsoft.CognitiveServices/accounts/raiTopics/deleteDelete topic under a resourceNN
Microsoft.CognitiveServices/accounts/raiTopics/writeModifies available topics under a resourceNN
Microsoft.CognitiveServices/accounts/raiValidateExternalSafetyProvider/writeNN
Microsoft.CognitiveServices/accounts/regenerateKey/actionRegenerate KeyNN
Microsoft.CognitiveServices/accounts/writeWrites API Accounts.YN
Microsoft.CognitiveServices/attestations/writeWrites AttestationNN
Microsoft.CognitiveServices/capacityReservations/deleteDeletes API accountsNN
Microsoft.CognitiveServices/capacityReservations/writeWrites API Accounts.NN
Microsoft.CognitiveServices/checkDomainAvailability/actionReads available SKUs for a subscription.NN
Microsoft.CognitiveServices/locations/checkSkuAvailability/actionReads available SKUs for a subscription.NN
Microsoft.CognitiveServices/locations/deleteVirtualNetworkOrSubnets/actionNotification from Microsoft.Network of deleting VirtualNetworks or Subnets.NN
Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/deleteDeletes a network security perimeter.NN
Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/profileProxies/deleteDeletes a network security perimeter profile.NN
Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/profileProxies/writeWrites a network security perimeter profile.NN
Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/writeWrites a network security perimeter.NN
Microsoft.CognitiveServices/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/actionNotification from Microsoft.Network of NetworkSecurityPerimeter updates.NN
Microsoft.CognitiveServices/locations/resourceGroups/deletedAccounts/deletePurge deleted account.NN
Microsoft.CognitiveServices/raiExternalSafetyProviders/writeWrite External Safety ProvidersNN
Microsoft.CognitiveServices/raiPolicy/actionCreate or update Subscription RaiPolicyNN
Microsoft.CognitiveServices/register/actionSubscription Registration ActionYN

any: Azure AI Services (Cognitive Services) (catch-all)

#
Namespace
Microsoft.CognitiveServices

Description

Catch-all for Azure-Microsoft.CognitiveServices rules that match the resource provider but no specific operation.

Microsoft.CognitiveServices/accounts/capabilityHosts/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete a capability host

Microsoft.CognitiveServices/accounts/capabilityHosts/write

#
Namespace
Microsoft.CognitiveServices

Description

Write a capability host

Microsoft.CognitiveServices/accounts/commitmentplans/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes commitment plans.

Microsoft.CognitiveServices/accounts/commitmentplans/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes commitment plans.

Microsoft.CognitiveServices/accounts/connections/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete a connection

Microsoft.CognitiveServices/accounts/connections/listsecrets/action

#
Namespace
Microsoft.CognitiveServices

Description

List secrets

Microsoft.CognitiveServices/accounts/connections/write

#
Namespace
Microsoft.CognitiveServices

Description

Write a connection

Microsoft.CognitiveServices/accounts/defenderForAISettings/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a custom Responsible AI policy that's not referenced by an existing deployment.

Microsoft.CognitiveServices/accounts/defenderForAISettings/write

#
Namespace
Microsoft.CognitiveServices

Description

Create or update a custom Responsible AI policy.

Microsoft.CognitiveServices/accounts/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes API accounts

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "action": "Microsoft.CognitiveServices/accounts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "action": "Microsoft.CognitiveServices/accounts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "a43a5492-1d97-49a5-8ef5-430191270ef5",
  "EventDataId": "410abcfc-58ce-a24d-cbed-b92eddfc9f08",
  "EventSubmissionTimestamp": "2026-07-03T02:06:13.0816275Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COGNITIVESERVICES/ACCOUNTS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "message": "Microsoft.CognitiveServices/accounts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "410abcfc-58ce-a24d-cbed-b92eddfc9f08",
    "eventSubmissionTimestamp": "2026-07-03T02:06:13.0816275Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dcog",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "message": "Microsoft.CognitiveServices/accounts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "410abcfc-58ce-a24d-cbed-b92eddfc9f08",
    "eventSubmissionTimestamp": "2026-07-03T02:06:13.0816275Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dcog",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.CognitiveServices/accounts/deployments/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes deployments.

Microsoft.CognitiveServices/accounts/deployments/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes deployments.

Microsoft.CognitiveServices/accounts/encryptionScopes/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes an Encryption Scope.

Microsoft.CognitiveServices/accounts/encryptionScopes/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes an Encryption Scope.

Microsoft.CognitiveServices/accounts/joinPerimeter/action

#
Namespace
Microsoft.CognitiveServices

Description

Allow to join CognitiveServices account to an given perimeter.

Microsoft.CognitiveServices/accounts/listKeys/action

#
Namespace
Microsoft.CognitiveServices

Description

List keys

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.CognitiveServices/accounts/managedComputeDeployments/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes Managed Compute Deployments.

Microsoft.CognitiveServices/accounts/managedComputeDeployments/write

#
Namespace
Microsoft.CognitiveServices

Description

Creates or updates Managed Compute Deployments.

Microsoft.CognitiveServices/accounts/managedNetworks/batchOutboundRules/action

#
Namespace
Microsoft.CognitiveServices

Description

Manages the outbound rules of the managed network associated with the Cognitive Services Account.

Microsoft.CognitiveServices/accounts/managedNetworks/outboundRules/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes an outbound rule of managed network associated with the Cognitive Services Account.

Microsoft.CognitiveServices/accounts/managedNetworks/outboundRules/write

#
Namespace
Microsoft.CognitiveServices

Description

Creates or updates an outbound rule of managed network associated with the Cognitive Services Account.

Microsoft.CognitiveServices/accounts/managedNetworks/write

#
Namespace
Microsoft.CognitiveServices

Description

Creates or updates the managed network associated with the Cognitive Services Account.

Microsoft.CognitiveServices/accounts/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a network security perimeter association.

Microsoft.CognitiveServices/accounts/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes a network security perimeter association.

Microsoft.CognitiveServices/accounts/networkSecurityPerimeterConfigurations/reconcile/action

#
Namespace
Microsoft.CognitiveServices

Description

Reconcile effective Network Security Perimeters configuration

Microsoft.CognitiveServices/accounts/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a private endpoint connections.

Microsoft.CognitiveServices/accounts/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.CognitiveServices

Description

Validates private endpoint connection proxies (internal use only).

Microsoft.CognitiveServices/accounts/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes private endpoint connection proxies (internal use only).

Microsoft.CognitiveServices/accounts/privateEndpointConnections/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a private endpoint connections.

Microsoft.CognitiveServices/accounts/privateEndpointConnections/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes a private endpoint connections.

Microsoft.CognitiveServices/accounts/privateEndpointConnectionsApproval/action

#
Namespace
Microsoft.CognitiveServices

Description

Approves Private Endpoint

Microsoft.CognitiveServices/accounts/projects/applications/action

#
Namespace
Microsoft.CognitiveServices

Description

Enables or disables an application

Microsoft.CognitiveServices/accounts/projects/applications/agentdeployments/action

#
Namespace
Microsoft.CognitiveServices

Description

Starts or stops an application agent deployment

Microsoft.CognitiveServices/accounts/projects/applications/agentdeployments/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes an agent deployment under an application

Microsoft.CognitiveServices/accounts/projects/applications/agentdeployments/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes an agent deployment for an application

Microsoft.CognitiveServices/accounts/projects/applications/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes an application

Microsoft.CognitiveServices/accounts/projects/applications/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes an application

Microsoft.CognitiveServices/accounts/projects/capabilityHosts/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete a capability host

Microsoft.CognitiveServices/accounts/projects/capabilityHosts/write

#
Namespace
Microsoft.CognitiveServices

Description

Write a capability host

Microsoft.CognitiveServices/accounts/projects/connections/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete a connection

Microsoft.CognitiveServices/accounts/projects/connections/listsecrets/action

#
Namespace
Microsoft.CognitiveServices

Description

List secrets

Microsoft.CognitiveServices/accounts/projects/connections/write

#
Namespace
Microsoft.CognitiveServices

Description

Write a connection

Microsoft.CognitiveServices/accounts/projects/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete a project

Microsoft.CognitiveServices/accounts/projects/write

#
Namespace
Microsoft.CognitiveServices

Description

Write a project

Microsoft.CognitiveServices/accounts/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.CognitiveServices

Description

Creates or updates the diagnostic setting for the resource.

Microsoft.CognitiveServices/accounts/provisionManagedNetwork/action

#
Namespace
Microsoft.CognitiveServices

Description

Provision the managed network of the Cognitive Services Account.

Microsoft.CognitiveServices/accounts/raiBlocklists/addRaiBlocklistItems/action

#
Namespace
Microsoft.CognitiveServices

Description

Batch adds blocklist items under a blocklist.

Microsoft.CognitiveServices/accounts/raiBlocklists/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes blocklists under a resource

Microsoft.CognitiveServices/accounts/raiBlocklists/deleteRaiBlocklistItems/action

#
Namespace
Microsoft.CognitiveServices

Description

Batch deletes blocklist items under a blocklist.

Microsoft.CognitiveServices/accounts/raiBlocklists/raiBlocklistItems/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes blocklist items under a blocklist.

Microsoft.CognitiveServices/accounts/raiBlocklists/raiBlocklistItems/write

#
Namespace
Microsoft.CognitiveServices

Description

Modifies blocklist items under a blocklist.

Microsoft.CognitiveServices/accounts/raiBlocklists/write

#
Namespace
Microsoft.CognitiveServices

Description

Modifies available blocklists under a resource.

Microsoft.CognitiveServices/accounts/raiIfcRules/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes Ifc Rules under a resource

Microsoft.CognitiveServices/accounts/raiIfcRules/write

#
Namespace
Microsoft.CognitiveServices

Description

Modifies available Ifc Rules under a resource.

Microsoft.CognitiveServices/accounts/raiModerationlists/addRaiModerationTerms/action

#
Namespace
Microsoft.CognitiveServices

Description

Batch adds moderation terms under a moderation list

Microsoft.CognitiveServices/accounts/raiModerationlists/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes moderation lists under a resource

Microsoft.CognitiveServices/accounts/raiModerationlists/deleteRaiModerationTerms/action

#
Namespace
Microsoft.CognitiveServices

Description

Batch deletes moderation terms under a moderation list

Microsoft.CognitiveServices/accounts/raiModerationlists/raiModerationTerms/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete terms under a customer moderation list

Microsoft.CognitiveServices/accounts/raiModerationlists/raiModerationTerms/write

#
Namespace
Microsoft.CognitiveServices

Description

Write Terms under a customer moderation list

Microsoft.CognitiveServices/accounts/raiModerationlists/write

#
Namespace
Microsoft.CognitiveServices

Description

Modifies available moderation lists under a resource.

Microsoft.CognitiveServices/accounts/raiPolicies/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a custom Responsible AI policy that's not referenced by an existing deployment.

Microsoft.CognitiveServices/accounts/raiPolicies/write

#
Namespace
Microsoft.CognitiveServices

Description

Create or update a custom Responsible AI policy.

Microsoft.CognitiveServices/accounts/raiToolLabels/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes Tool Labels under a resource

Microsoft.CognitiveServices/accounts/raiToolLabels/write

#
Namespace
Microsoft.CognitiveServices

Description

Modifies available Tool Labels under a resource.

Microsoft.CognitiveServices/accounts/raiTopics/delete

#
Namespace
Microsoft.CognitiveServices

Description

Delete topic under a resource

Microsoft.CognitiveServices/accounts/raiTopics/write

#
Namespace
Microsoft.CognitiveServices

Description

Modifies available topics under a resource

Microsoft.CognitiveServices/accounts/raiValidateExternalSafetyProvider/write

#
Namespace
Microsoft.CognitiveServices

Microsoft.CognitiveServices/accounts/regenerateKey/action

#
Namespace
Microsoft.CognitiveServices

Description

Regenerate Key

Microsoft.CognitiveServices/accounts/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes API Accounts.

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "Conflict",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "action": "Microsoft.CognitiveServices/accounts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "action": "Microsoft.CognitiveServices/accounts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "ecbfcc51-9029-416c-8559-69fb3bcf0424",
  "EventDataId": "78f3765c-7d61-eb8d-4233-725462982980",
  "EventSubmissionTimestamp": "2026-07-03T02:18:24.3318857Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.COGNITIVESERVICES/ACCOUNTS/WRITE",
  "Properties": {
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "FlagMustBeSetForRestore",
        "message": "An existing resource with ID '/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog' has been soft-deleted. To restore the resource, you must specify 'restore' to be 'true' in the property. If you don't want to restore existing resource, please purge it first."
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "message": "Microsoft.CognitiveServices/accounts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "78f3765c-7d61-eb8d-4233-725462982980",
    "eventSubmissionTimestamp": "2026-07-03T02:18:24.3318857Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dcog",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "Conflict"
  },
  "Properties_d": {
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "FlagMustBeSetForRestore",
        "message": "An existing resource with ID '/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog' has been soft-deleted. To restore the resource, you must specify 'restore' to be 'true' in the property. If you don't want to restore existing resource, please purge it first."
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.CognitiveServices/accounts/dwhc6a93dcog",
    "message": "Microsoft.CognitiveServices/accounts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "78f3765c-7d61-eb8d-4233-725462982980",
    "eventSubmissionTimestamp": "2026-07-03T02:18:24.3318857Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dcog",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "Conflict"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.CognitiveServices/attestations/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes Attestation

Microsoft.CognitiveServices/capacityReservations/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes API accounts

Microsoft.CognitiveServices/capacityReservations/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes API Accounts.

Microsoft.CognitiveServices/checkDomainAvailability/action

#
Namespace
Microsoft.CognitiveServices

Description

Reads available SKUs for a subscription.

Microsoft.CognitiveServices/locations/checkSkuAvailability/action

#
Namespace
Microsoft.CognitiveServices

Description

Reads available SKUs for a subscription.

Microsoft.CognitiveServices/locations/deleteVirtualNetworkOrSubnets/action

#
Namespace
Microsoft.CognitiveServices

Description

Notification from Microsoft.Network of deleting VirtualNetworks or Subnets.

Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a network security perimeter.

Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/profileProxies/delete

#
Namespace
Microsoft.CognitiveServices

Description

Deletes a network security perimeter profile.

Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/profileProxies/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes a network security perimeter profile.

Microsoft.CognitiveServices/locations/networkSecurityPerimeterProxies/write

#
Namespace
Microsoft.CognitiveServices

Description

Writes a network security perimeter.

Microsoft.CognitiveServices/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action

#
Namespace
Microsoft.CognitiveServices

Description

Notification from Microsoft.Network of NetworkSecurityPerimeter updates.

Microsoft.CognitiveServices/locations/resourceGroups/deletedAccounts/delete

#
Namespace
Microsoft.CognitiveServices

Description

Purge deleted account.

Microsoft.CognitiveServices/raiExternalSafetyProviders/write

#
Namespace
Microsoft.CognitiveServices

Description

Write External Safety Providers

Microsoft.CognitiveServices/raiPolicy/action

#
Namespace
Microsoft.CognitiveServices

Description

Create or update Subscription RaiPolicy

Microsoft.CognitiveServices/register/action

#
Namespace
Microsoft.CognitiveServices

Description

Subscription Registration Action

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.CognitiveServices/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.CognitiveServices/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "3f470b22-cc48-49f4-b6b2-aab47762487a",
  "EventDataId": "771a6c1c-ec3d-9e88-ce50-57189c01e3b0",
  "EventSubmissionTimestamp": "2026-07-02T17:30:00.2184355Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COGNITIVESERVICES/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.CognitiveServices",
    "message": "Microsoft.CognitiveServices/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "771a6c1c-ec3d-9e88-ce50-57189c01e3b0",
    "eventSubmissionTimestamp": "2026-07-02T17:30:00.2184355Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.CognitiveServices",
    "message": "Microsoft.CognitiveServices/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "771a6c1c-ec3d-9e88-ce50-57189c01e3b0",
    "eventSubmissionTimestamp": "2026-07-02T17:30:00.2184355Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceProviderValue": "MICROSOFT.COGNITIVESERVICES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #