Azure Compute Azure-Microsoft.Compute

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Compute rules that match the resource provider but no specific operation.NN
Microsoft.Compute/availabilitySets/deleteDeletes the availability setYN
Microsoft.Compute/availabilitySets/writeCreates a new availability set or updates an existing oneYN
Microsoft.Compute/capacityReservationGroups/capacityReservations/deleteDeletes the capacity reservationNN
Microsoft.Compute/capacityReservationGroups/capacityReservations/writeCreates a new capacity reservation or updates an existing capacity reservationNN
Microsoft.Compute/capacityReservationGroups/deleteDeletes the capacity reservation groupYN
Microsoft.Compute/capacityReservationGroups/deploy/actionDeploy a new VM/VMSS using Capacity Reservation GroupNN
Microsoft.Compute/capacityReservationGroups/share/actionShare the Capacity Reservation Group with one or more SubscriptionssNN
Microsoft.Compute/capacityReservationGroups/writeCreates a new capacity reservation group or updates an existing capacity reservation groupYN
Microsoft.Compute/cloudServices/deleteDeletes the CloudService.NN
Microsoft.Compute/cloudServices/delete/actionDeletes role instances in a CloudService.NN
Microsoft.Compute/cloudServices/poweroff/actionPower off the CloudService.NN
Microsoft.Compute/cloudServices/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the CloudService.NN
Microsoft.Compute/cloudServices/rebuild/actionReimage all the role instances in a CloudService.NN
Microsoft.Compute/cloudServices/reimage/actionRebuilds all the disks in the role instances in a CloudService.NN
Microsoft.Compute/cloudServices/restart/actionRestarts one or more role instances in a CloudService.NN
Microsoft.Compute/cloudServices/roleInstances/deleteDeletes a RoleInstance from CloudService.NN
Microsoft.Compute/cloudServices/roleInstances/rebuild/actionRebuild all the disks in a CloudService.NN
Microsoft.Compute/cloudServices/roleInstances/reimage/actionReimage a role instance of a CloudService.NN
Microsoft.Compute/cloudServices/roleInstances/restart/actionRestart a role instance of a CloudServiceNN
Microsoft.Compute/cloudServices/roles/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the CloudService RolesNN
Microsoft.Compute/cloudServices/roles/writeScale instances in a RoleNN
Microsoft.Compute/cloudServices/start/actionStarts the CloudService.NN
Microsoft.Compute/cloudServices/writeCreated a new CloudService or Update an existing one.NN
Microsoft.Compute/diskAccesses/deleteDelete a DiskAccess resourceYN
Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/deleteDelete a Private Endpoint Connection ProxyNN
Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/validate/actionValidate a Private Endpoint Connection Proxy objectNN
Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/writeCreate a new Private Endpoint Connection ProxyNN
Microsoft.Compute/diskAccesses/privateEndpointConnections/deleteDelete a Private Endpoint ConnectionNN
Microsoft.Compute/diskAccesses/privateEndpointConnections/writeApprove or Reject a Private Endpoint ConnectionNN
Microsoft.Compute/diskAccesses/privateEndpointConnectionsApproval/actionAuto Approve a Private Endpoint ConnectionNN
Microsoft.Compute/diskAccesses/writeCreate a new DiskAccess resource or update an existing oneYN
Microsoft.Compute/diskEncryptionSets/deleteDelete a disk encryption setNN
Microsoft.Compute/diskEncryptionSets/writeCreate a new disk encryption set or update an existing oneNN
Microsoft.Compute/disks/beginGetAccess/actionGet the SAS URI of the Disk for blob accessNY
Microsoft.Compute/disks/deleteDeletes the DiskYY
Microsoft.Compute/disks/endGetAccess/actionRevoke the SAS URI of the DiskNN
Microsoft.Compute/disks/writeCreates a new Disk or updates an existing oneYN
Microsoft.Compute/galleries/applications/deleteDeletes the Gallery ApplicationNN
Microsoft.Compute/galleries/applications/versions/deleteDeletes the Gallery Application VersionNN
Microsoft.Compute/galleries/applications/versions/writeCreates a new Gallery Application Version or updates an existing oneNY
Microsoft.Compute/galleries/applications/writeCreates a new Gallery Application or updates an existing oneNN
Microsoft.Compute/galleries/deleteDeletes the GalleryYN
Microsoft.Compute/galleries/images/deleteDeletes the Gallery ImageNN
Microsoft.Compute/galleries/images/versions/deleteDeletes the Gallery Image VersionNN
Microsoft.Compute/galleries/images/versions/writeCreates a new Gallery Image Version or updates an existing oneNN
Microsoft.Compute/galleries/images/writeCreates a new Gallery Image or updates an existing oneNN
Microsoft.Compute/galleries/inVMAccessControlProfiles/deleteDeletes the Gallery In VM Access Control ProfileNN
Microsoft.Compute/galleries/inVMAccessControlProfiles/versions/deleteDeletes the Gallery In VM Access Control Profile VersionNN
Microsoft.Compute/galleries/inVMAccessControlProfiles/versions/writeCreates a new Gallery In VM Access Control Profile Version or updates an existing oneNN
Microsoft.Compute/galleries/inVMAccessControlProfiles/writeCreates a new Gallery In VM Access Control Profile or updates an existing oneNN
Microsoft.Compute/galleries/remoteContainerImages/beginGetAccess/actionGet the SAS URI of the Gallery Remote Container Image for blob accessNN
Microsoft.Compute/galleries/remoteContainerImages/deleteDeletes the Gallery Remote Container ImageNN
Microsoft.Compute/galleries/remoteContainerImages/writeCreates a new Gallery Remote Container Image or updates an existing oneNN
Microsoft.Compute/galleries/serviceArtifacts/deleteDeletes the Gallery Service ArtifactNN
Microsoft.Compute/galleries/serviceArtifacts/writeCreates a new Gallery Service Artifact or updates an existing oneNN
Microsoft.Compute/galleries/share/actionShares a Gallery to different scopesNN
Microsoft.Compute/galleries/writeCreates a new Gallery or updates an existing oneYN
Microsoft.Compute/hostGroups/deleteDeletes the host groupYN
Microsoft.Compute/hostGroups/hosts/deleteDeletes the hostNN
Microsoft.Compute/hostGroups/hosts/writeCreates a new host or updates an existing hostNN
Microsoft.Compute/hostGroups/writeCreates a new host group or updates an existing host groupYN
Microsoft.Compute/images/deleteDeletes the imageNN
Microsoft.Compute/images/writeCreates a new Image or updates an existing oneNN
Microsoft.Compute/interconnectBlocks/deleteDeletes the interconnect blockNN
Microsoft.Compute/interconnectBlocks/deploy/actionDeploy a new VM/VMSS using Interconnect BlockNN
Microsoft.Compute/interconnectBlocks/writeCreates a new interconnect block or updates an existing interconnect blockNN
Microsoft.Compute/locations/diagnostics/generate/actionCreate a request for generating recommendationsNN
Microsoft.Compute/locations/diagnostics/run/actionCreate a request for running DiagnosticsNN
Microsoft.Compute/locations/logAnalytics/getRequestRateByInterval/actionCreate logs to show total requests by time interval to aid throttling diagnostics.NN
Microsoft.Compute/locations/logAnalytics/getThrottledRequests/actionCreate logs to show aggregates of throttled requests grouped by ResourceName, OperationName, or the applied Throttle Policy.NN
Microsoft.Compute/locations/placementScores/generate/actionCreate a request for generating Placement ScoresNN
Microsoft.Compute/locations/vmSizeRecommendations/generate/actionCreate a request for generating VMSize RecommendationsNN
Microsoft.Compute/proximityPlacementGroups/deleteDeletes the Proximity Placement GroupYN
Microsoft.Compute/proximityPlacementGroups/writeCreates a new Proximity Placement Group or updates an existing oneYN
Microsoft.Compute/register/actionRegisters Subscription with Microsoft.Compute resource providerYN
Microsoft.Compute/restorePointCollections/deleteDeletes the restore point collection and contained restore pointsNY
Microsoft.Compute/restorePointCollections/restorePoints/deleteDeletes the restore pointNN
Microsoft.Compute/restorePointCollections/restorePoints/diskRestorePoints/beginGetAccess/actionGet the SAS URI of the incremental DiskRestorePointNN
Microsoft.Compute/restorePointCollections/restorePoints/diskRestorePoints/endGetAccess/actionRevoke the SAS URI of the incremental DiskRestorePointNN
Microsoft.Compute/restorePointCollections/restorePoints/retrieveSasUris/actionGet the properties of a restore point along with blob SAS URIsNN
Microsoft.Compute/restorePointCollections/restorePoints/writeCreates a new restore pointNN
Microsoft.Compute/restorePointCollections/writeCreates a new restore point collection or updates an existing oneNN
Microsoft.Compute/sharedVMExtensions/deleteDeletes the Shared VM ExtensionNN
Microsoft.Compute/sharedVMExtensions/versions/deleteDeletes the Shared VM Extension VersionNN
Microsoft.Compute/sharedVMExtensions/versions/writeCreates a new Shared VM Extension Version or updates an existing oneNN
Microsoft.Compute/sharedVMExtensions/writeCreates a new Shared VM Extension or updates an existing oneNN
Microsoft.Compute/sharedVMImages/deleteDeletes the SharedVMImageNN
Microsoft.Compute/sharedVMImages/versions/deleteDelete a SharedVMImageVersionNN
Microsoft.Compute/sharedVMImages/versions/replicate/actionReplicate a SharedVMImageVersion to target regionsNN
Microsoft.Compute/sharedVMImages/versions/writeCreate a new SharedVMImageVersion or update an existing oneNN
Microsoft.Compute/sharedVMImages/writeCreates a new SharedVMImage or updates an existing oneNN
Microsoft.Compute/snapshots/beginGetAccess/actionGet the SAS URI of the Snapshot for blob accessNN
Microsoft.Compute/snapshots/deleteDelete a SnapshotYY
Microsoft.Compute/snapshots/endGetAccess/actionRevoke the SAS URI of the SnapshotNN
Microsoft.Compute/snapshots/writeCreate a new Snapshot or update an existing oneYY
Microsoft.Compute/sshPublicKeys/deleteDeletes the SSH public keyYN
Microsoft.Compute/sshPublicKeys/generateKeyPair/actionGenerates a new SSH public/private key pairYN
Microsoft.Compute/sshPublicKeys/writeCreates a new SSH public key or updates an existing SSH public keyYN
Microsoft.Compute/unregister/actionUnregisters Subscription with Microsoft.Compute resource providerNN
Microsoft.Compute/virtualMachines/assessPatches/actionAssesses the virtual machine and finds list of available OS update patches for it.NN
Microsoft.Compute/virtualMachines/attachDetachDataDisks/actionAttaches Detaches existing data disks to a virtual machineNN
Microsoft.Compute/virtualMachines/cancelPatchInstallation/actionCancels the ongoing install OS update patch operation on the virtual machine.NN
Microsoft.Compute/virtualMachines/capture/actionCaptures the virtual machine by copying virtual hard disks and generates a template that can be used to create similar virtual machinesNN
Microsoft.Compute/virtualMachines/convertToManagedDisks/actionConverts the blob based disks of the virtual machine to managed disksNN
Microsoft.Compute/virtualMachines/deallocate/actionPowers off the virtual machine and releases the compute resourcesYN
Microsoft.Compute/virtualMachines/deleteDeletes the virtual machineYY
Microsoft.Compute/virtualMachines/deletePreservedOSDisk/actionDeletes PreservedOSDisk on the Virtual Machine which belongs to Virtual Machine Scale Set with Flexible Orchestration Mode.NN
Microsoft.Compute/virtualMachines/diagnosticRunCommand/actionExecutes a diagnostic script on the virtual machineNN
Microsoft.Compute/virtualMachines/diagnosticRunCommands/deleteDeletes the virtual machine diagnostic run commandNN
Microsoft.Compute/virtualMachines/diagnosticRunCommands/writeCreates a new virtual machine diagnostic run command or updates an existing oneNN
Microsoft.Compute/virtualMachines/extensions/deleteDeletes the virtual machine extensionYY
Microsoft.Compute/virtualMachines/extensions/writeCreates a new virtual machine extension or updates an existing oneYY
Microsoft.Compute/virtualMachines/generalize/actionSets the virtual machine state to Generalized and prepares the virtual machine for captureNN
Microsoft.Compute/virtualMachines/installPatches/actionInstalls available OS update patches on the virtual machine based on parameters provided by user. Assessment results containing list of available patches will also get refreshed as part of this.NN
Microsoft.Compute/virtualMachines/osUpgradeInternal/actionPerform OS Upgrade on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode.NN
Microsoft.Compute/virtualMachines/performMaintenance/actionPerforms Maintenance Operation on the VM.NN
Microsoft.Compute/virtualMachines/powerOff/actionPowers off the virtual machine. Note that the virtual machine will continue to be billed.YN
Microsoft.Compute/virtualMachines/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the Virtual Machine.NN
Microsoft.Compute/virtualMachines/reapply/actionReapplies a virtual machine's current modelNN
Microsoft.Compute/virtualMachines/redeploy/actionRedeploys virtual machineYN
Microsoft.Compute/virtualMachines/reimage/actionReimages virtual machine which is using differencing disk.NN
Microsoft.Compute/virtualMachines/restart/actionRestarts the virtual machineYN
Microsoft.Compute/virtualMachines/retrieveBootDiagnosticsData/actionRetrieves boot diagnostic logs blob URIsNY
Microsoft.Compute/virtualMachines/rollbackOSDisk/actionRollback OSDisk on Virtual Machine after failed OS Upgrade invoked by Virtual Machine Scale Set with Flexible Orchestration Mode.NN
Microsoft.Compute/virtualMachines/runCommand/actionExecutes a predefined script on the virtual machineYY
Microsoft.Compute/virtualMachines/runCommands/deleteDeletes the virtual machine run commandNN
Microsoft.Compute/virtualMachines/runCommands/writeCreates a new virtual machine run command or updates an existing oneNY
Microsoft.Compute/virtualMachines/setVMHealth/actionSets health status on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode.NN
Microsoft.Compute/virtualMachines/simulateEviction/actionSimulates the eviction of spot Virtual MachineNN
Microsoft.Compute/virtualMachines/start/actionStarts the virtual machineYN
Microsoft.Compute/virtualMachines/upgradeVMAgent/actionUpgrade version of VM Agent on Virtual MachineNN
Microsoft.Compute/virtualMachines/writeCreates a new virtual machine or updates an existing virtual machineYY
Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/actionApproves deferred rolling upgrades for the instances of a Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/deallocate/actionPowers off and releases the compute resources for the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/deleteDeletes the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/delete/actionDeletes the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/disks/beginGetAccess/actionGet the SAS URI of VirtualMachineScaleSets DiskNN
Microsoft.Compute/virtualMachineScaleSets/eventGridFilters/deleteDeletes the Virtual Machine Scale Set Event Grid FilterNN
Microsoft.Compute/virtualMachineScaleSets/eventGridFilters/writeCreates a new Virtual Machine Scale Set Event Grid Filter or updates an existing oneNN
Microsoft.Compute/virtualMachineScaleSets/extensions/deleteDeletes the Virtual Machine Scale Set ExtensionNY
Microsoft.Compute/virtualMachineScaleSets/extensions/roles/writeUpdates the properties of an existing Role in a Virtual Machine Scale Set with the Virtual Machine Runtime Service ExtensionNN
Microsoft.Compute/virtualMachineScaleSets/extensions/writeCreates a new Virtual Machine Scale Set Extension or updates an existing oneNY
Microsoft.Compute/virtualMachineScaleSets/forceRecoveryServiceFabricPlatformUpdateDomainWalk/actionManually walk the platform update domains of a service fabric Virtual Machine Scale Set to finish a pending update that is stuckNN
Microsoft.Compute/virtualMachineScaleSets/manualUpgrade/actionManually updates instances to latest model of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/osRollingUpgrade/actionStarts a rolling upgrade to move all Virtual Machine Scale Set instances to the latest available Platform Image OS version.NN
Microsoft.Compute/virtualMachineScaleSets/performMaintenance/actionPerforms planned maintenance on the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/powerOff/actionPowers off the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the Virtual Machine Scale set.NN
Microsoft.Compute/virtualMachineScaleSets/reapply/actionReapply the Virtual Machine Scale Set Virtual Machine Profile to the Virtual Machine InstancesNN
Microsoft.Compute/virtualMachineScaleSets/redeploy/actionRedeploy the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/reimage/actionReimages the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/reimageAll/actionReimages all disks (OS Disk and Data Disks) for the instances of a Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/restart/actionRestarts the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/rollingUpgrades/actionCancels the rolling upgrade of a Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/scale/actionVerify if an existing Virtual Machine Scale Set can Scale In/Scale Out to specified instance countNN
Microsoft.Compute/virtualMachineScaleSets/setOrchestrationServiceState/actionSets the state of an orchestration service based on the action provided in operation input.NN
Microsoft.Compute/virtualMachineScaleSets/setVMHealth/actionSets health status on Virtual Machines belonging to Virtual Machine Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/start/actionStarts the instances of the Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/approveRollingUpgrade/actionApproves deferred rolling upgrade for Virtual Machine instance in a Virtual Machine Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/attachDetachDataDisks/actionAttaches Detaches existing data disks to a Virtual Machine instance in a VM Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/deallocate/actionPowers off and releases the compute resources for a Virtual Machine in a VM Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/deleteDelete a specific Virtual Machine in a VM Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommand/actionExecutes a diagnostic script on a Virtual Machine instance in a Virtual Machine Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommands/deleteDeletes the diagnostic run command for Virtual Machine in Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommands/writeCreates a new diagnostic run command for Virtual Machine in Virtual Machine Scale Set or updates an existing oneNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/extensions/deleteDeletes the extension for Virtual Machine in Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/extensions/writeCreates a new extension for Virtual Machine in Virtual Machine Scale Set or updates an existing oneNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/getEffectiveRouteTable/actionGet properties of effective route table on network interface of a virtual machine created using Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/getEffectiveSecurityGroups/actionGet properties of effective security groups on network interface of a virtual machine created using Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/performMaintenance/actionPerforms planned maintenance on a Virtual Machine instance in a Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/powerOff/actionPowers Off a Virtual Machine instance in a VM Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/redeploy/actionRedeploys a Virtual Machine instance in a Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/reimage/actionReimages a Virtual Machine instance in a Virtual Machine Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/reimageAll/actionReimages all disks (OS Disk and Data Disks) for Virtual Machine instance in a Virtual Machine Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/restart/actionRestarts a Virtual Machine instance in a VM Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/retrieveBootDiagnosticsData/actionRetrieves boot diagnostic logs blob URIs of Virtual Machine instance in a Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/actionExecutes a predefined script on a Virtual Machine instance in a Virtual Machine Scale Set.NY
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/deleteDeletes the run command for Virtual Machine in Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/writeCreates a new run command for Virtual Machine in Virtual Machine Scale Set or updates an existing oneNY
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/simulateEviction/actionSimulates the eviction of spot Virtual Machine in Virtual Machine Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/start/actionStarts a Virtual Machine instance in a VM Scale Set.NN
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/writeUpdates the properties of a Virtual Machine in a VM Scale SetNN
Microsoft.Compute/virtualMachineScaleSets/writeCreates a new Virtual Machine Scale Set or updates an existing oneNN
Microsoft.Compute/virtualMachineScaleSets/forceRestart/actionForce Restart VM containers in a Virtual Machine Scale SetNN

any: Azure Compute (catch-all)

#
Namespace
Microsoft.Compute

Description

Catch-all for Azure-Microsoft.Compute rules that match the resource provider but no specific operation.

References #

Microsoft.Compute/availabilitySets/delete

#
Namespace
Microsoft.Compute

Description

Deletes the availability set

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "action": "Microsoft.Compute/availabilitySets/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "action": "Microsoft.Compute/availabilitySets/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "0c349462-39c1-4d1b-b994-8b93cccc3bb9",
  "EventDataId": "29acf873-4cb3-2123-ff3b-833c128e6e42",
  "EventSubmissionTimestamp": "2026-07-02T17:24:16.4890268Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/AVAILABILITYSETS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "message": "Microsoft.Compute/availabilitySets/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "29acf873-4cb3-2123-ff3b-833c128e6e42",
    "eventSubmissionTimestamp": "2026-07-02T17:24:16.4890268Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0avset",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "message": "Microsoft.Compute/availabilitySets/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "29acf873-4cb3-2123-ff3b-833c128e6e42",
    "eventSubmissionTimestamp": "2026-07-02T17:24:16.4890268Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0avset",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/availabilitySets/write

#
Namespace
Microsoft.Compute

Description

Creates a new availability set or updates an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "action": "Microsoft.Compute/availabilitySets/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "action": "Microsoft.Compute/availabilitySets/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "91190fed-7da0-4948-950a-a582ae0b5a65",
  "EventDataId": "d4766d29-6c2a-5ce0-05ba-53e82c684fe4",
  "EventSubmissionTimestamp": "2026-07-02T17:13:46.521546Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/AVAILABILITYSETS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "responseBody": {
      "name": "dwh92eef0avset",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
      "type": "Microsoft.Compute/availabilitySets",
      "location": "westus2",
      "tags": {},
      "properties": {
        "platformUpdateDomainCount": 5,
        "platformFaultDomainCount": 2,
        "virtualMachineScaleSetMigrationInfo": {
          "defaultVirtualMachineScaleSetInfo": {
            "constrainedMaximumCapacity": true,
            "defaultVirtualMachineScaleSet": {
              "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachineScaleSets/dwh92eef0avset"
            }
          }
        }
      },
      "sku": {
        "name": "Aligned"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "message": "Microsoft.Compute/availabilitySets/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "d4766d29-6c2a-5ce0-05ba-53e82c684fe4",
    "eventSubmissionTimestamp": "2026-07-02T17:13:46.521546Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0avset",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
    "message": "Microsoft.Compute/availabilitySets/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "d4766d29-6c2a-5ce0-05ba-53e82c684fe4",
    "eventSubmissionTimestamp": "2026-07-02T17:13:46.5215460Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0avset",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK",
    "responseBody": {
      "name": "dwh92eef0avset",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
      "type": "Microsoft.Compute/availabilitySets",
      "location": "westus2",
      "tags": {},
      "properties": {
        "platformUpdateDomainCount": 5,
        "platformFaultDomainCount": 2,
        "virtualMachineScaleSetMigrationInfo": {
          "defaultVirtualMachineScaleSetInfo": {
            "constrainedMaximumCapacity": true,
            "defaultVirtualMachineScaleSet": {
              "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachineScaleSets/dwh92eef0avset"
            }
          }
        }
      },
      "sku": {
        "name": "Aligned"
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/capacityReservationGroups/capacityReservations/delete

#
Namespace
Microsoft.Compute

Description

Deletes the capacity reservation

References #

Microsoft.Compute/capacityReservationGroups/capacityReservations/write

#
Namespace
Microsoft.Compute

Description

Creates a new capacity reservation or updates an existing capacity reservation

References #

Microsoft.Compute/capacityReservationGroups/delete

#
Namespace
Microsoft.Compute

Description

Deletes the capacity reservation group

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "action": "Microsoft.Compute/capacityReservationGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "action": "Microsoft.Compute/capacityReservationGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "454e5bf7-dd9f-4b8f-88ce-b3e0f6781c95",
  "EventDataId": "bd47c0f0-c25a-f6bb-8d2a-2155f61915e1",
  "EventSubmissionTimestamp": "2026-07-02T18:26:53.4859311Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/CAPACITYRESERVATIONGROUPS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "message": "Microsoft.Compute/capacityReservationGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bd47c0f0-c25a-f6bb-8d2a-2155f61915e1",
    "eventSubmissionTimestamp": "2026-07-02T18:26:53.4859311Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afcapacityreserv",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "message": "Microsoft.Compute/capacityReservationGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bd47c0f0-c25a-f6bb-8d2a-2155f61915e1",
    "eventSubmissionTimestamp": "2026-07-02T18:26:53.4859311Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afcapacityreserv",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/capacityReservationGroups/deploy/action

#
Namespace
Microsoft.Compute

Description

Deploy a new VM/VMSS using Capacity Reservation Group

References #

Microsoft.Compute/capacityReservationGroups/share/action

#
Namespace
Microsoft.Compute

Description

Share the Capacity Reservation Group with one or more Subscriptionss

References #

Microsoft.Compute/capacityReservationGroups/write

#
Namespace
Microsoft.Compute

Description

Creates a new capacity reservation group or updates an existing capacity reservation group

Example Resource Log Record #

{
  "ActivityStatusValue": "Accept",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "action": "Microsoft.Compute/capacityReservationGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "action": "Microsoft.Compute/capacityReservationGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "8c62e44c-9676-41bc-88da-f0ddc26659ac",
  "EventDataId": "00d3d045-6e3c-d112-c180-8f5d1c8f4691",
  "EventSubmissionTimestamp": "2026-07-02T18:26:48.6274802Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/CAPACITYRESERVATIONGROUPS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "dwh2220afcapacityreserv",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
      "type": "Microsoft.Compute/capacityReservationGroups",
      "location": "westus2",
      "properties": {
        "provisioningState": "Creating"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "message": "Microsoft.Compute/capacityReservationGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "00d3d045-6e3c-d112-c180-8f5d1c8f4691",
    "eventSubmissionTimestamp": "2026-07-02T18:26:48.6274802Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afcapacityreserv",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
    "message": "Microsoft.Compute/capacityReservationGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "00d3d045-6e3c-d112-c180-8f5d1c8f4691",
    "eventSubmissionTimestamp": "2026-07-02T18:26:48.6274802Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afcapacityreserv",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created",
    "responseBody": {
      "name": "dwh2220afcapacityreserv",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
      "type": "Microsoft.Compute/capacityReservationGroups",
      "location": "westus2",
      "properties": {
        "provisioningState": "Creating"
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/cloudServices/delete

#
Namespace
Microsoft.Compute

Description

Deletes the CloudService.

References #

Microsoft.Compute/cloudServices/delete/action

#
Namespace
Microsoft.Compute

Description

Deletes role instances in a CloudService.

References #

Microsoft.Compute/cloudServices/poweroff/action

#
Namespace
Microsoft.Compute

Description

Power off the CloudService.

References #

Microsoft.Compute/cloudServices/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Compute

Description

Creates or updates the diagnostic setting for the CloudService.

References #

Microsoft.Compute/cloudServices/rebuild/action

#
Namespace
Microsoft.Compute

Description

Reimage all the role instances in a CloudService.

References #

Microsoft.Compute/cloudServices/reimage/action

#
Namespace
Microsoft.Compute

Description

Rebuilds all the disks in the role instances in a CloudService.

References #

Microsoft.Compute/cloudServices/restart/action

#
Namespace
Microsoft.Compute

Description

Restarts one or more role instances in a CloudService.

References #

Microsoft.Compute/cloudServices/roleInstances/delete

#
Namespace
Microsoft.Compute

Description

Deletes a RoleInstance from CloudService.

References #

Microsoft.Compute/cloudServices/roleInstances/rebuild/action

#
Namespace
Microsoft.Compute

Description

Rebuild all the disks in a CloudService.

References #

Microsoft.Compute/cloudServices/roleInstances/reimage/action

#
Namespace
Microsoft.Compute

Description

Reimage a role instance of a CloudService.

References #

Microsoft.Compute/cloudServices/roleInstances/restart/action

#
Namespace
Microsoft.Compute

Description

Restart a role instance of a CloudService

References #

Microsoft.Compute/cloudServices/roles/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Compute

Description

Creates or updates the diagnostic setting for the CloudService Roles

References #

Microsoft.Compute/cloudServices/roles/write

#
Namespace
Microsoft.Compute

Description

Scale instances in a Role

References #

Microsoft.Compute/cloudServices/start/action

#
Namespace
Microsoft.Compute

Description

Starts the CloudService.

References #

Microsoft.Compute/cloudServices/write

#
Namespace
Microsoft.Compute

Description

Created a new CloudService or Update an existing one.

References #

Microsoft.Compute/diskAccesses/delete

#
Namespace
Microsoft.Compute

Description

Delete a DiskAccess resource

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "action": "Microsoft.Compute/diskAccesses/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "action": "Microsoft.Compute/diskAccesses/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "894445c1-2680-40fa-9499-cc6ab8a0b074",
  "EventDataId": "d4b892b7-4cce-5b81-f08f-ad5aa46122a7",
  "EventSubmissionTimestamp": "2026-07-02T18:27:39.7663832Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/DISKACCESSES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "message": "Microsoft.Compute/diskAccesses/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "d4b892b7-4cce-5b81-f08f-ad5aa46122a7",
    "eventSubmissionTimestamp": "2026-07-02T18:27:39.7663832Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdiskaccesses",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "message": "Microsoft.Compute/diskAccesses/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "d4b892b7-4cce-5b81-f08f-ad5aa46122a7",
    "eventSubmissionTimestamp": "2026-07-02T18:27:39.7663832Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdiskaccesses",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.Compute

Description

Delete a Private Endpoint Connection Proxy

References #

Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Compute

Description

Validate a Private Endpoint Connection Proxy object

References #

Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.Compute

Description

Create a new Private Endpoint Connection Proxy

References #

Microsoft.Compute/diskAccesses/privateEndpointConnections/delete

#
Namespace
Microsoft.Compute

Description

Delete a Private Endpoint Connection

References #

Microsoft.Compute/diskAccesses/privateEndpointConnections/write

#
Namespace
Microsoft.Compute

Description

Approve or Reject a Private Endpoint Connection

References #

Microsoft.Compute/diskAccesses/privateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Compute

Description

Auto Approve a Private Endpoint Connection

References #

Microsoft.Compute/diskAccesses/write

#
Namespace
Microsoft.Compute

Description

Create a new DiskAccess resource or update an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "action": "Microsoft.Compute/diskAccesses/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "action": "Microsoft.Compute/diskAccesses/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "63369ae2-717e-43b6-8989-3d653a539f95",
  "EventDataId": "2d6ef75b-6685-16f7-86cd-b387efd744d0",
  "EventSubmissionTimestamp": "2026-07-02T18:27:06.9958837Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/DISKACCESSES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "message": "Microsoft.Compute/diskAccesses/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2d6ef75b-6685-16f7-86cd-b387efd744d0",
    "eventSubmissionTimestamp": "2026-07-02T18:27:06.9958837Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdiskaccesses",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
    "message": "Microsoft.Compute/diskAccesses/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2d6ef75b-6685-16f7-86cd-b387efd744d0",
    "eventSubmissionTimestamp": "2026-07-02T18:27:06.9958837Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdiskaccesses",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/diskEncryptionSets/delete

#
Namespace
Microsoft.Compute

Description

Delete a disk encryption set

References #

Microsoft.Compute/diskEncryptionSets/write

#
Namespace
Microsoft.Compute

Description

Create a new disk encryption set or update an existing one

References #

Microsoft.Compute/disks/beginGetAccess/action

#
Namespace
Microsoft.Compute

Description

Get the SAS URI of the Disk for blob access

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure VM Disk SAS URI Generated source high: Detects when a Shared Access Signature (SAS) URI is generated for an Azure VM disk. SAS URIs provide time-limited, unauthenticated access to download disk contents directly from Azure Storage. Adversaries can generate SAS URIs to exfiltrate entire virtual machine disks, including operating systems, applications, and all data. This allows offline analysis to extract credentials, secrets, and sensitive data without detection. This is a critical indicator of data exfiltration and should be investigated immediately.T1530, T1567.002

References #

Microsoft.Compute/disks/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Disk

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
    "action": "Microsoft.Compute/disks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
    "action": "Microsoft.Compute/disks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "3cfc3312-e78b-4dca-b619-fbede0317764",
  "EventDataId": "3cbc01c6-3116-7346-ed49-602987b198b4",
  "EventSubmissionTimestamp": "2026-06-29T18:07:14.0019028Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.COMPUTE/DISKS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
    "message": "Microsoft.Compute/disks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "3cbc01c6-3116-7346-ed49-602987b198b4",
    "eventSubmissionTimestamp": "2026-06-29T18:07:14.0019028Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvm_disk1_b357687f7348480ca29adf88826cacda",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
    "message": "Microsoft.Compute/disks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "3cbc01c6-3116-7346-ed49-602987b198b4",
    "eventSubmissionTimestamp": "2026-06-29T18:07:14.0019028Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvm_disk1_b357687f7348480ca29adf88826cacda",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:07:14.0019028Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Disk Deleted source informational: Detects when an Azure managed disk is deleted. Unauthorized disk deletion can indicate ransomware activity where attackers destroy data or delete backup disks to prevent recovery. This may also indicate legitimate cleanup operations.T1485, T1490

References #

Microsoft.Compute/disks/endGetAccess/action

#
Namespace
Microsoft.Compute

Description

Revoke the SAS URI of the Disk

References #

Microsoft.Compute/disks/write

#
Namespace
Microsoft.Compute

Description

Creates a new Disk or updates an existing one

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Accepted",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
    "action": "Microsoft.Compute/disks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
    "action": "Microsoft.Compute/disks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "08d5e0fe-4661-4d2c-9f6f-eb11f4e0274c",
  "EventDataId": "dfe94d83-2ee1-1215-44e0-459ab3347584",
  "EventSubmissionTimestamp": "2026-06-29T19:03:08.1580603Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.COMPUTE/DISKS/WRITE",
  "Properties": {
    "statusCode": "Accepted",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcdisk3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
      "type": "Microsoft.Compute/disks",
      "location": "westus2",
      "tags": {},
      "sku": {
        "name": "Standard_LRS"
      },
      "properties": {
        "creationData": {
          "createOption": "Empty"
        },
        "diskSizeGB": 4,
        "provisioningState": "Updating"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
    "message": "Microsoft.Compute/disks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "dfe94d83-2ee1-1215-44e0-459ab3347584",
    "eventSubmissionTimestamp": "2026-06-29T19:03:08.1580603Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcdisk3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Properties_d": {
    "statusCode": "Accepted",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcdisk3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
      "type": "Microsoft.Compute/disks",
      "location": "westus2",
      "tags": {},
      "sku": {
        "name": "Standard_LRS"
      },
      "properties": {
        "creationData": {
          "createOption": "Empty"
        },
        "diskSizeGB": 4,
        "provisioningState": "Updating"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
    "message": "Microsoft.Compute/disks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "dfe94d83-2ee1-1215-44e0-459ab3347584",
    "eventSubmissionTimestamp": "2026-06-29T19:03:08.1580603Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcdisk3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:03:08.1580603Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/disks/zcdisk3"
}

References #

Microsoft.Compute/galleries/applications/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery Application

References #

Microsoft.Compute/galleries/applications/versions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery Application Version

References #

Microsoft.Compute/galleries/applications/versions/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery Application Version or updates an existing one

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

Microsoft.Compute/galleries/applications/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery Application or updates an existing one

References #

Microsoft.Compute/galleries/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "action": "Microsoft.Compute/galleries/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "action": "Microsoft.Compute/galleries/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "87f588e8-0f51-46a5-ad92-2798faf2c7d0",
  "EventDataId": "fd67edef-574b-e9a0-dfa5-5081f436af83",
  "EventSubmissionTimestamp": "2026-07-02T18:28:30.1506154Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/GALLERIES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "message": "Microsoft.Compute/galleries/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "fd67edef-574b-e9a0-dfa5-5081f436af83",
    "eventSubmissionTimestamp": "2026-07-02T18:28:30.1506154Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afgalleries",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "message": "Microsoft.Compute/galleries/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "fd67edef-574b-e9a0-dfa5-5081f436af83",
    "eventSubmissionTimestamp": "2026-07-02T18:28:30.1506154Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afgalleries",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/galleries/images/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery Image

References #

Microsoft.Compute/galleries/images/versions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery Image Version

References #

Microsoft.Compute/galleries/images/versions/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery Image Version or updates an existing one

References #

Microsoft.Compute/galleries/images/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery Image or updates an existing one

References #

Microsoft.Compute/galleries/inVMAccessControlProfiles/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery In VM Access Control Profile

References #

Microsoft.Compute/galleries/inVMAccessControlProfiles/versions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery In VM Access Control Profile Version

References #

Microsoft.Compute/galleries/inVMAccessControlProfiles/versions/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery In VM Access Control Profile Version or updates an existing one

References #

Microsoft.Compute/galleries/inVMAccessControlProfiles/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery In VM Access Control Profile or updates an existing one

References #

Microsoft.Compute/galleries/remoteContainerImages/beginGetAccess/action

#
Namespace
Microsoft.Compute

Description

Get the SAS URI of the Gallery Remote Container Image for blob access

References #

Microsoft.Compute/galleries/remoteContainerImages/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery Remote Container Image

References #

Microsoft.Compute/galleries/remoteContainerImages/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery Remote Container Image or updates an existing one

References #

Microsoft.Compute/galleries/serviceArtifacts/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Gallery Service Artifact

References #

Microsoft.Compute/galleries/serviceArtifacts/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery Service Artifact or updates an existing one

References #

Microsoft.Compute/galleries/share/action

#
Namespace
Microsoft.Compute

Description

Shares a Gallery to different scopes

References #

Microsoft.Compute/galleries/write

#
Namespace
Microsoft.Compute

Description

Creates a new Gallery or updates an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "action": "Microsoft.Compute/galleries/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "action": "Microsoft.Compute/galleries/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "07900c1e-81df-44bc-8f37-d2e795d88d77",
  "EventDataId": "e1cdb2fa-0e1e-472a-c914-0c039e9bdc09",
  "EventSubmissionTimestamp": "2026-07-02T18:27:59.3026249Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/GALLERIES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "message": "Microsoft.Compute/galleries/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e1cdb2fa-0e1e-472a-c914-0c039e9bdc09",
    "eventSubmissionTimestamp": "2026-07-02T18:27:59.3026249Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afgalleries",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
    "message": "Microsoft.Compute/galleries/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e1cdb2fa-0e1e-472a-c914-0c039e9bdc09",
    "eventSubmissionTimestamp": "2026-07-02T18:27:59.3026249Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afgalleries",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/hostGroups/delete

#
Namespace
Microsoft.Compute

Description

Deletes the host group

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
    "action": "Microsoft.Compute/hostGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
    "action": "Microsoft.Compute/hostGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "9a5abe0d-9cbf-4419-b982-a14132277d0c",
  "EventDataId": "cc892eb3-a1ae-a496-8175-30c1aa9e2c87",
  "EventSubmissionTimestamp": "2026-07-03T02:28:58.6026803Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/HOSTGROUPS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
    "message": "Microsoft.Compute/hostGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "cc892eb3-a1ae-a496-8175-30c1aa9e2c87",
    "eventSubmissionTimestamp": "2026-07-03T02:28:58.6026803Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dhostgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
    "message": "Microsoft.Compute/hostGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "cc892eb3-a1ae-a496-8175-30c1aa9e2c87",
    "eventSubmissionTimestamp": "2026-07-03T02:28:58.6026803Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dhostgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/hostGroups/hosts/delete

#
Namespace
Microsoft.Compute

Description

Deletes the host

References #

Microsoft.Compute/hostGroups/hosts/write

#
Namespace
Microsoft.Compute

Description

Creates a new host or updates an existing host

References #

Microsoft.Compute/hostGroups/write

#
Namespace
Microsoft.Compute

Description

Creates a new host group or updates an existing host group

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
    "action": "Microsoft.Compute/hostGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
    "action": "Microsoft.Compute/hostGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "4668a2cd-1a2a-446d-a9f7-2b806ab4be86",
  "EventDataId": "9b1f1bea-66b4-a8cf-0da0-c15b592b9090",
  "EventSubmissionTimestamp": "2026-07-02T18:38:31.7179525Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/HOSTGROUPS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
    "message": "Microsoft.Compute/hostGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9b1f1bea-66b4-a8cf-0da0-c15b592b9090",
    "eventSubmissionTimestamp": "2026-07-02T18:38:31.7179525Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afhostgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
    "message": "Microsoft.Compute/hostGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9b1f1bea-66b4-a8cf-0da0-c15b592b9090",
    "eventSubmissionTimestamp": "2026-07-02T18:38:31.7179525Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afhostgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/images/delete

#
Namespace
Microsoft.Compute

Description

Deletes the image

References #

Microsoft.Compute/images/write

#
Namespace
Microsoft.Compute

Description

Creates a new Image or updates an existing one

References #

Microsoft.Compute/interconnectBlocks/delete

#
Namespace
Microsoft.Compute

Description

Deletes the interconnect block

References #

Microsoft.Compute/interconnectBlocks/deploy/action

#
Namespace
Microsoft.Compute

Description

Deploy a new VM/VMSS using Interconnect Block

References #

Microsoft.Compute/interconnectBlocks/write

#
Namespace
Microsoft.Compute

Description

Creates a new interconnect block or updates an existing interconnect block

References #

Microsoft.Compute/locations/diagnostics/generate/action

#
Namespace
Microsoft.Compute

Description

Create a request for generating recommendations

References #

Microsoft.Compute/locations/diagnostics/run/action

#
Namespace
Microsoft.Compute

Description

Create a request for running Diagnostics

References #

Microsoft.Compute/locations/logAnalytics/getRequestRateByInterval/action

#
Namespace
Microsoft.Compute

Description

Create logs to show total requests by time interval to aid throttling diagnostics.

References #

Microsoft.Compute/locations/logAnalytics/getThrottledRequests/action

#
Namespace
Microsoft.Compute

Description

Create logs to show aggregates of throttled requests grouped by ResourceName, OperationName, or the applied Throttle Policy.

References #

Microsoft.Compute/locations/placementScores/generate/action

#
Namespace
Microsoft.Compute

Description

Create a request for generating Placement Scores

References #

Microsoft.Compute/locations/vmSizeRecommendations/generate/action

#
Namespace
Microsoft.Compute

Description

Create a request for generating VMSize Recommendations

References #

Microsoft.Compute/proximityPlacementGroups/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Proximity Placement Group

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "action": "Microsoft.Compute/proximityPlacementGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "action": "Microsoft.Compute/proximityPlacementGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "d8692a11-d74a-45dd-84ea-ce8e9b57d182",
  "EventDataId": "43846790-a3dd-39e4-d409-cfc14133458c",
  "EventSubmissionTimestamp": "2026-07-02T17:14:23.4972934Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/PROXIMITYPLACEMENTGROUPS/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "message": "Microsoft.Compute/proximityPlacementGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "43846790-a3dd-39e4-d409-cfc14133458c",
    "eventSubmissionTimestamp": "2026-07-02T17:14:23.4972934Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0ppg",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "message": "Microsoft.Compute/proximityPlacementGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "43846790-a3dd-39e4-d409-cfc14133458c",
    "eventSubmissionTimestamp": "2026-07-02T17:14:23.4972934Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0ppg",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/proximityPlacementGroups/write

#
Namespace
Microsoft.Compute

Description

Creates a new Proximity Placement Group or updates an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "action": "Microsoft.Compute/proximityPlacementGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "action": "Microsoft.Compute/proximityPlacementGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "4c9eb9aa-4d96-47eb-8861-e33e357cf0b9",
  "EventDataId": "50a1e27d-5d47-2e04-57ee-2b9f8150aded",
  "EventSubmissionTimestamp": "2026-07-02T17:14:21.9472157Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/PROXIMITYPLACEMENTGROUPS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "dwh92eef0ppg",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
      "type": "Microsoft.Compute/proximityPlacementGroups",
      "location": "westus2",
      "properties": {
        "proximityPlacementGroupType": "Standard"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "message": "Microsoft.Compute/proximityPlacementGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "50a1e27d-5d47-2e04-57ee-2b9f8150aded",
    "eventSubmissionTimestamp": "2026-07-02T17:14:21.9472157Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0ppg",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
    "message": "Microsoft.Compute/proximityPlacementGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "50a1e27d-5d47-2e04-57ee-2b9f8150aded",
    "eventSubmissionTimestamp": "2026-07-02T17:14:21.9472157Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0ppg",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created",
    "responseBody": {
      "name": "dwh92eef0ppg",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
      "type": "Microsoft.Compute/proximityPlacementGroups",
      "location": "westus2",
      "properties": {
        "proximityPlacementGroupType": "Standard"
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/register/action

#
Namespace
Microsoft.Compute

Description

Registers Subscription with Microsoft.Compute resource provider

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Compute/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Compute/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "56cd70e1-88f7-4ab2-a48a-1e2223f3a719",
  "EventDataId": "8bbf885c-6367-c09e-14c0-d0cb1588bd9c",
  "EventSubmissionTimestamp": "2026-07-28T04:08:58.2002834Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Compute",
    "message": "Microsoft.Compute/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8bbf885c-6367-c09e-14c0-d0cb1588bd9c",
    "eventSubmissionTimestamp": "2026-07-28T04:08:58.2002834Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Compute",
    "message": "Microsoft.Compute/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8bbf885c-6367-c09e-14c0-d0cb1588bd9c",
    "eventSubmissionTimestamp": "2026-07-28T04:08:58.2002834Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/restorePointCollections/delete

#
Namespace
Microsoft.Compute

Description

Deletes the restore point collection and contained restore points

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)eqmicrosoft.compute/restorepointcollections/delete2 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Compute Restore Point Collection Deleted by Unusual User source medium: Identifies the deletion of Azure Restore Point Collections by a user who has not previously performed this activity. Restore Point Collections contain recovery points for virtual machines, enabling point-in-time recovery capabilities. Adversaries may delete these collections to prevent recovery during ransomware attacks or to cover their tracks during malicious operations.T1490
  • Azure Compute Restore Point Collections Deleted source high: Identifies multiple Azure Restore Point Collections being deleted by a single user within a short time period. Restore Point Collections contain recovery points for virtual machines, enabling point-in-time recovery capabilities. Mass deletion of these collections is a common tactic used by adversaries during ransomware attacks to prevent victim recovery or to maximize impact during destructive operations. Multiple deletions in rapid succession may indicate malicious intent.T1490

Panther #

  • Azure Restore Point Collection Deleted source medium: Detects when an Azure restore point collection is deleted. Restore point collections contain crash-consistent and application-consistent recovery points for virtual machines. Adversaries may delete these collections to prevent system recovery, destroy forensic evidence, or undermine backup strategies before launching ransomware attacks. This is a strong indicator of inhibiting system recovery capabilities.T1485, T1490

References #

Microsoft.Compute/restorePointCollections/restorePoints/delete

#
Namespace
Microsoft.Compute

Description

Deletes the restore point

References #

Microsoft.Compute/restorePointCollections/restorePoints/diskRestorePoints/beginGetAccess/action

#
Namespace
Microsoft.Compute

Description

Get the SAS URI of the incremental DiskRestorePoint

References #

Microsoft.Compute/restorePointCollections/restorePoints/diskRestorePoints/endGetAccess/action

#
Namespace
Microsoft.Compute

Description

Revoke the SAS URI of the incremental DiskRestorePoint

References #

Microsoft.Compute/restorePointCollections/restorePoints/retrieveSasUris/action

#
Namespace
Microsoft.Compute

Description

Get the properties of a restore point along with blob SAS URIs

References #

Microsoft.Compute/restorePointCollections/restorePoints/write

#
Namespace
Microsoft.Compute

Description

Creates a new restore point

References #

Microsoft.Compute/restorePointCollections/write

#
Namespace
Microsoft.Compute

Description

Creates a new restore point collection or updates an existing one

References #

Microsoft.Compute/sharedVMExtensions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Shared VM Extension

References #

Microsoft.Compute/sharedVMExtensions/versions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Shared VM Extension Version

References #

Microsoft.Compute/sharedVMExtensions/versions/write

#
Namespace
Microsoft.Compute

Description

Creates a new Shared VM Extension Version or updates an existing one

References #

Microsoft.Compute/sharedVMExtensions/write

#
Namespace
Microsoft.Compute

Description

Creates a new Shared VM Extension or updates an existing one

References #

Microsoft.Compute/sharedVMImages/delete

#
Namespace
Microsoft.Compute

Description

Deletes the SharedVMImage

References #

Microsoft.Compute/sharedVMImages/versions/delete

#
Namespace
Microsoft.Compute

Description

Delete a SharedVMImageVersion

References #

Microsoft.Compute/sharedVMImages/versions/replicate/action

#
Namespace
Microsoft.Compute

Description

Replicate a SharedVMImageVersion to target regions

References #

Microsoft.Compute/sharedVMImages/versions/write

#
Namespace
Microsoft.Compute

Description

Create a new SharedVMImageVersion or update an existing one

References #

Microsoft.Compute/sharedVMImages/write

#
Namespace
Microsoft.Compute

Description

Creates a new SharedVMImage or updates an existing one

References #

Microsoft.Compute/snapshots/beginGetAccess/action

#
Namespace
Microsoft.Compute

Description

Get the SAS URI of the Snapshot for blob access

References #

Microsoft.Compute/snapshots/delete

#
Namespace
Microsoft.Compute

Description

Delete a Snapshot

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
    "action": "Microsoft.Compute/snapshots/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
    "action": "Microsoft.Compute/snapshots/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "9e9b38be-b4c1-4678-80cd-ffef49c8a318",
  "EventDataId": "95db2ab3-8c63-ea2b-4ca9-01f28d5621b8",
  "EventSubmissionTimestamp": "2026-07-28T04:12:23.442875Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/SNAPSHOTS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
    "message": "Microsoft.Compute/snapshots/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "95db2ab3-8c63-ea2b-4ca9-01f28d5621b8",
    "eventSubmissionTimestamp": "2026-07-28T04:12:23.442875Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665snap",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
    "message": "Microsoft.Compute/snapshots/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "95db2ab3-8c63-ea2b-4ca9-01f28d5621b8",
    "eventSubmissionTimestamp": "2026-07-28T04:12:23.4428750Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665snap",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.activitylogs.identity.claims_initiated_by_user.name (elastic rule field)is_not_null2 ruleselastic
azure.activitylogs.properties.status_code (elastic rule field)eqaccepted2 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Compute Snapshot Deletion by Unusual User and Resource Group source low: Identifies when an Azure disk snapshot is deleted by an unusual user in a specific resource group. Snapshots are critical for backup, disaster recovery, and forensic analysis. Adversaries may delete snapshots to prevent data recovery, eliminate forensic evidence, or disrupt backup strategies before executing ransomware or other destructive attacks. Monitoring snapshot deletions is essential for detecting potential attacks targeting backup and recovery capabilities.T1485, T1490
  • Azure Compute Snapshot Deletions by User source medium: Identifies when a single user or service principal deletes multiple Azure disk snapshots within a short time period. This behavior may indicate an adversary attempting to inhibit system recovery capabilities, destroy backup evidence, or prepare for a ransomware attack. Mass deletion of snapshots eliminates restore points and significantly impacts disaster recovery capabilities, making it a critical indicator of potentially malicious activity.T1485, T1490

Panther #

  • Azure VM Snapshot Deleted source low: Detects when an Azure disk snapshot is deleted. Snapshots serve critical functions for backup, disaster recovery, and forensic analysis. Adversaries may target snapshots to prevent data recovery, destroy forensic evidence, or undermine backup strategies before launching ransomware or destructive operations.T1485, T1490

References #

Microsoft.Compute/snapshots/endGetAccess/action

#
Namespace
Microsoft.Compute

Description

Revoke the SAS URI of the Snapshot

References #

Microsoft.Compute/snapshots/write

#
Namespace
Microsoft.Compute

Description

Create a new Snapshot or update an existing one

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
    "action": "Microsoft.Compute/snapshots/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
    "action": "Microsoft.Compute/snapshots/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "0969a0c7-44b8-4252-837c-e21b42e5d586",
  "EventDataId": "4aed47ad-3481-6455-71af-7e2a0fa15c87",
  "EventSubmissionTimestamp": "2026-06-29T19:03:14.6313372Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.COMPUTE/SNAPSHOTS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
    "message": "Microsoft.Compute/snapshots/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "4aed47ad-3481-6455-71af-7e2a0fa15c87",
    "eventSubmissionTimestamp": "2026-06-29T19:03:14.6313372Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcsnap3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
    "message": "Microsoft.Compute/snapshots/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "4aed47ad-3481-6455-71af-7e2a0fa15c87",
    "eventSubmissionTimestamp": "2026-06-29T19:03:14.6313372Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcsnap3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:03:14.6313372Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/snapshots/zcsnap3"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ActivityStatusValue (kusto rule field)eqsuccess1 rulekusto
count_ (kusto rule field)ge51 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Microsoft.Compute/sshPublicKeys/delete

#
Namespace
Microsoft.Compute

Description

Deletes the SSH public key

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
    "action": "Microsoft.Compute/sshPublicKeys/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
    "action": "Microsoft.Compute/sshPublicKeys/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "18f1dffc-51f2-46df-b203-158f5a735f76",
  "EventDataId": "82fdf158-43ac-8fed-e2f0-5c79180a72b2",
  "EventSubmissionTimestamp": "2026-07-03T02:29:00.2040497Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/SSHPUBLICKEYS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
    "message": "Microsoft.Compute/sshPublicKeys/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "82fdf158-43ac-8fed-e2f0-5c79180a72b2",
    "eventSubmissionTimestamp": "2026-07-03T02:29:00.2040497Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsshpublickeys",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
    "message": "Microsoft.Compute/sshPublicKeys/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "82fdf158-43ac-8fed-e2f0-5c79180a72b2",
    "eventSubmissionTimestamp": "2026-07-03T02:29:00.2040497Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsshpublickeys",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/sshPublicKeys/generateKeyPair/action

#
Namespace
Microsoft.Compute

Description

Generates a new SSH public/private key pair

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "action": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "action": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "da1e1936-e633-4437-b268-5de2beff681b",
  "EventDataId": "283d0f94-a8bb-cb10-a70f-2a4c18193709",
  "EventSubmissionTimestamp": "2026-07-02T18:28:34.1562356Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/SSHPUBLICKEYS/GENERATEKEYPAIR/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "message": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "283d0f94-a8bb-cb10-a70f-2a4c18193709",
    "eventSubmissionTimestamp": "2026-07-02T18:28:34.1562356Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afsshpublickeys",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "message": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "283d0f94-a8bb-cb10-a70f-2a4c18193709",
    "eventSubmissionTimestamp": "2026-07-02T18:28:34.1562356Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afsshpublickeys",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/sshPublicKeys/write

#
Namespace
Microsoft.Compute

Description

Creates a new SSH public key or updates an existing SSH public key

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "action": "Microsoft.Compute/sshPublicKeys/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "action": "Microsoft.Compute/sshPublicKeys/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "aae59fcf-d2b4-46e2-a5a0-96513ba1f1bf",
  "EventDataId": "439d9215-d076-6fb8-7410-d07f00aaccf3",
  "EventSubmissionTimestamp": "2026-07-02T18:38:34.2965052Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/SSHPUBLICKEYS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "message": "Microsoft.Compute/sshPublicKeys/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "439d9215-d076-6fb8-7410-d07f00aaccf3",
    "eventSubmissionTimestamp": "2026-07-02T18:38:34.2965052Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afsshpublickeys",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
    "message": "Microsoft.Compute/sshPublicKeys/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "439d9215-d076-6fb8-7410-d07f00aaccf3",
    "eventSubmissionTimestamp": "2026-07-02T18:38:34.2965052Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afsshpublickeys",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/unregister/action

#
Namespace
Microsoft.Compute

Description

Unregisters Subscription with Microsoft.Compute resource provider

References #

Microsoft.Compute/virtualMachines/assessPatches/action

#
Namespace
Microsoft.Compute

Description

Assesses the virtual machine and finds list of available OS update patches for it.

References #

Microsoft.Compute/virtualMachines/attachDetachDataDisks/action

#
Namespace
Microsoft.Compute

Description

Attaches Detaches existing data disks to a virtual machine

References #

Microsoft.Compute/virtualMachines/cancelPatchInstallation/action

#
Namespace
Microsoft.Compute

Description

Cancels the ongoing install OS update patch operation on the virtual machine.

References #

Microsoft.Compute/virtualMachines/capture/action

#
Namespace
Microsoft.Compute

Description

Captures the virtual machine by copying virtual hard disks and generates a template that can be used to create similar virtual machines

References #

Microsoft.Compute/virtualMachines/convertToManagedDisks/action

#
Namespace
Microsoft.Compute

Description

Converts the blob based disks of the virtual machine to managed disks

References #

Microsoft.Compute/virtualMachines/deallocate/action

#
Namespace
Microsoft.Compute

Description

Powers off the virtual machine and releases the compute resources

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "action": "Microsoft.Compute/virtualMachines/deallocate/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "action": "Microsoft.Compute/virtualMachines/deallocate/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "f9124087-f7d7-4101-aa0b-9925397fe95a",
  "EventDataId": "dde5c871-73d7-1e33-3648-156b72abe63b",
  "EventSubmissionTimestamp": "2026-07-28T04:12:33.6376326Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/DEALLOCATE/ACTION",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "message": "Microsoft.Compute/virtualMachines/deallocate/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "dde5c871-73d7-1e33-3648-156b72abe63b",
    "eventSubmissionTimestamp": "2026-07-28T04:12:33.6376326Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh7075e5vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "message": "Microsoft.Compute/virtualMachines/deallocate/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "dde5c871-73d7-1e33-3648-156b72abe63b",
    "eventSubmissionTimestamp": "2026-07-28T04:12:33.6376326Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh7075e5vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/virtualMachines/delete

#
Namespace
Microsoft.Compute

Description

Deletes the virtual machine

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "3387cf7f-24b2-482f-9f4e-1ef7ceb08c14",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
    "action": "Microsoft.Compute/virtualMachines/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
    "action": "Microsoft.Compute/virtualMachines/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE",
  "Properties": {
    "statusCode": "Accepted",
    "serviceRequestId": "4b895e78-45c6-421a-a904-adb1f810bf99",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
    "message": "Microsoft.Compute/virtualMachines/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "9a0ebf0f-aa1f-4a59-b0d6-cb0f10e134ec",
    "eventSubmissionTimestamp": "2021-04-28T14:36:53.2672695Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "linux01",
    "resourceGroup": "VM-RG01",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Properties_d": {
    "statusCode": "Accepted",
    "serviceRequestId": "4b895e78-45c6-421a-a904-adb1f810bf99",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
    "message": "Microsoft.Compute/virtualMachines/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "9a0ebf0f-aa1f-4a59-b0d6-cb0f10e134ec",
    "eventSubmissionTimestamp": "2021-04-28T14:36:53.2672695Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "linux01",
    "resourceGroup": "VM-RG01",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "9a0ebf0f-aa1f-4a59-b0d6-cb0f10e134ec",
  "EventSubmissionTimestamp": "4/28/2021, 2:36:53.267 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "VM-RG01",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatusValue": "Accepted",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:36:53.267 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Virtual Machine Deleted source informational: Detects when an Azure Virtual Machine is deleted. VM deletion may indicate normal deprovisioning or could be part of a larger attack pattern to disrupt services.T1485, T1489

References #

Microsoft.Compute/virtualMachines/deletePreservedOSDisk/action

#
Namespace
Microsoft.Compute

Description

Deletes PreservedOSDisk on the Virtual Machine which belongs to Virtual Machine Scale Set with Flexible Orchestration Mode.

References #

Microsoft.Compute/virtualMachines/diagnosticRunCommand/action

#
Namespace
Microsoft.Compute

Description

Executes a diagnostic script on the virtual machine

References #

Microsoft.Compute/virtualMachines/diagnosticRunCommands/delete

#
Namespace
Microsoft.Compute

Description

Deletes the virtual machine diagnostic run command

References #

Microsoft.Compute/virtualMachines/diagnosticRunCommands/write

#
Namespace
Microsoft.Compute

Description

Creates a new virtual machine diagnostic run command or updates an existing one

References #

Microsoft.Compute/virtualMachines/extensions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the virtual machine extension

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "action": "Microsoft.Compute/virtualMachines/extensions/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "action": "Microsoft.Compute/virtualMachines/extensions/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "c33a76f7-d376-4511-9268-9cf10eaa4c16",
  "EventDataId": "2112148f-fec0-7c47-d0e2-79f0f4e87fb3",
  "EventSubmissionTimestamp": "2026-07-28T04:13:22.2789062Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "message": "Microsoft.Compute/virtualMachines/extensions/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2112148f-fec0-7c47-d0e2-79f0f4e87fb3",
    "eventSubmissionTimestamp": "2026-07-28T04:13:22.2789062Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm/dwharn-custom-script",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "message": "Microsoft.Compute/virtualMachines/extensions/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2112148f-fec0-7c47-d0e2-79f0f4e87fb3",
    "eventSubmissionTimestamp": "2026-07-28T04:13:22.2789062Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm/dwharn-custom-script",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)inmicrosoft.compute/virtualmachines/extensions/write1 ruleelastic
EventType (elastic rule field)inmicrosoft.compute/virtualmachinescalesets/extensions/write1 ruleelastic
azure.resource.name (elastic rule field)is_not_null1 ruleelastic
source.as.number (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Microsoft.Compute/virtualMachines/extensions/write

#
Namespace
Microsoft.Compute

Description

Creates a new virtual machine extension or updates an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Accept",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "action": "Microsoft.Compute/virtualMachines/extensions/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "action": "Microsoft.Compute/virtualMachines/extensions/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "09fbcf5c-8980-4973-a79a-4b75b6dd8ffe",
  "EventDataId": "e527e5ca-060d-cee6-1d83-b67dd38195e8",
  "EventSubmissionTimestamp": "2026-07-28T04:11:14.8174458Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "dwharn-custom-script",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
      "type": "Microsoft.Compute/virtualMachines/extensions",
      "location": "westus2",
      "properties": {
        "autoUpgradeMinorVersion": true,
        "provisioningState": "Creating",
        "publisher": "Microsoft.Azure.Extensions",
        "type": "CustomScript",
        "typeHandlerVersion": "2.1",
        "settings": "******"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "message": "Microsoft.Compute/virtualMachines/extensions/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e527e5ca-060d-cee6-1d83-b67dd38195e8",
    "eventSubmissionTimestamp": "2026-07-28T04:11:14.8174458Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm/dwharn-custom-script",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "dwharn-custom-script",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
      "type": "Microsoft.Compute/virtualMachines/extensions",
      "location": "westus2",
      "properties": {
        "autoUpgradeMinorVersion": true,
        "provisioningState": "Creating",
        "publisher": "Microsoft.Azure.Extensions",
        "type": "CustomScript",
        "typeHandlerVersion": "2.1",
        "settings": "******"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
    "message": "Microsoft.Compute/virtualMachines/extensions/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e527e5ca-060d-cee6-1d83-b67dd38195e8",
    "eventSubmissionTimestamp": "2026-07-28T04:11:14.8174458Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm/dwharn-custom-script",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)inmicrosoft.compute/virtualmachines/extensions/write2 ruleselastic
EventType (elastic rule field)inmicrosoft.compute/virtualmachinescalesets/extensions/write2 ruleselastic
azure.activitylogs.identity.authorization.evidence.principal_type (elastic rule field)equser1 ruleelastic
azure.resource.name (elastic rule field)is_not_null1 ruleelastic
azure_ad::operation_name_value (kusto rule field)eqmicrosoft.compute/virtualmachines/runcommand/action1 rulekusto
source.as.number (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Unusual Azure VM Extension Detected source medium: Identifies the first time a given VM extension name is created or updated on an Azure virtual machine or VM scale set within the rule's lookback window. VM extensions run with high privilege on the guest (SYSTEM on Windows, root on Linux) and are a common code-execution and persistence primitive. The extension instance name is attacker-controlled and the Azure activity log records only that name, not the publisher or type, so the control plane cannot reliably identify the extension family (for example CustomScript). This rule therefore takes a type-agnostic ES|QL new-terms approach: it derives the host and the extension instance name from azure.resource.name and alerts the first time a given (host, extension name) pair is observed in the window, surfacing novel extension deployments while suppressing names a host routinely uses.T1037, T1651↳ also matches Microsoft.Compute/virtualMachineScaleSets/extensions/write
  • Azure VM Extension Deployment by User source medium: Identifies the successful deployment of a high-risk Azure Virtual Machine extension by an interactive user principal. Attackers with privileged Azure RBAC roles can abuse VM extensions such as VMAccess, CustomScriptExtension, and RunCommand to execute arbitrary code, create backdoor accounts, harvest credentials, and establish persistence on Azure-hosted virtual machines without requiring direct network access to the VM.T1098, T1578, T1578.002, T1651
  • Azure VM Extension CRUD Operation with Unusual Source ASN source medium: Identifies create, read, update, or delete (CRUD) operations against Azure VM or VM scale set extensions ("MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/*" or the scale set equivalent) where the combination of the targeted extension resource name and the source autonomous system (AS) number has not been observed recently. VM extensions such as CustomScript and DSC run with high privilege on the guest (SYSTEM on Windows, root on Linux), so writing, modifying, or removing them is a common code-execution and persistence primitive. By keying a new terms approach on the extension resource name and the source AS number, this rule surfaces extension operations originating from networks that have not historically managed that extension, while routine first-party Microsoft automation (which originates from well-known Microsoft AS numbers) is excluded.T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/delete, Microsoft.Compute/virtualMachineScaleSets/extensions/delete, Microsoft.Compute/virtualMachineScaleSets/extensions/write

Kusto #

Panther #

References #

Microsoft.Compute/virtualMachines/generalize/action

#
Namespace
Microsoft.Compute

Description

Sets the virtual machine state to Generalized and prepares the virtual machine for capture

References #

Microsoft.Compute/virtualMachines/installPatches/action

#
Namespace
Microsoft.Compute

Description

Installs available OS update patches on the virtual machine based on parameters provided by user. Assessment results containing list of available patches will also get refreshed as part of this.

References #

Microsoft.Compute/virtualMachines/osUpgradeInternal/action

#
Namespace
Microsoft.Compute

Description

Perform OS Upgrade on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode.

References #

Microsoft.Compute/virtualMachines/performMaintenance/action

#
Namespace
Microsoft.Compute

Description

Performs Maintenance Operation on the VM.

References #

Microsoft.Compute/virtualMachines/powerOff/action

#
Namespace
Microsoft.Compute

Description

Powers off the virtual machine. Note that the virtual machine will continue to be billed.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "action": "Microsoft.Compute/virtualMachines/powerOff/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "action": "Microsoft.Compute/virtualMachines/powerOff/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "fd29bd3d-2a1a-41b9-85e6-d0eb81a7d776",
  "EventDataId": "6df95355-6b97-2aa6-398c-4c860669ad00",
  "EventSubmissionTimestamp": "2026-07-28T04:11:39.2147507Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/POWEROFF/ACTION",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "message": "Microsoft.Compute/virtualMachines/powerOff/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6df95355-6b97-2aa6-398c-4c860669ad00",
    "eventSubmissionTimestamp": "2026-07-28T04:11:39.2147507Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "message": "Microsoft.Compute/virtualMachines/powerOff/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6df95355-6b97-2aa6-398c-4c860669ad00",
    "eventSubmissionTimestamp": "2026-07-28T04:11:39.2147507Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/virtualMachines/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Compute

Description

Creates or updates the diagnostic setting for the Virtual Machine.

References #

Microsoft.Compute/virtualMachines/reapply/action

#
Namespace
Microsoft.Compute

Description

Reapplies a virtual machine's current model

References #

Microsoft.Compute/virtualMachines/redeploy/action

#
Namespace
Microsoft.Compute

Description

Redeploys virtual machine

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "action": "Microsoft.Compute/virtualMachines/redeploy/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "action": "Microsoft.Compute/virtualMachines/redeploy/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "5dc589b9-807b-400a-b947-5fe3bde9c350",
  "EventDataId": "3e537189-3402-dacb-f9e7-60a666d61a64",
  "EventSubmissionTimestamp": "2026-06-29T18:06:01.4781071Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/REDEPLOY/ACTION",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "message": "Microsoft.Compute/virtualMachines/redeploy/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "3e537189-3402-dacb-f9e7-60a666d61a64",
    "eventSubmissionTimestamp": "2026-06-29T18:06:01.4781071Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvm",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "message": "Microsoft.Compute/virtualMachines/redeploy/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "3e537189-3402-dacb-f9e7-60a666d61a64",
    "eventSubmissionTimestamp": "2026-06-29T18:06:01.4781071Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvm",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:06:01.4781071Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/virtualmachines/zcvm"
}

References #

Microsoft.Compute/virtualMachines/reimage/action

#
Namespace
Microsoft.Compute

Description

Reimages virtual machine which is using differencing disk.

References #

Microsoft.Compute/virtualMachines/restart/action

#
Namespace
Microsoft.Compute

Description

Restarts the virtual machine

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "action": "Microsoft.Compute/virtualMachines/restart/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "action": "Microsoft.Compute/virtualMachines/restart/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "4b7dc080-afa6-482a-aa4e-a5ce11b59e2c",
  "EventDataId": "f9d30760-fc4c-f524-59d3-5f36195f8f72",
  "EventSubmissionTimestamp": "2026-07-28T04:13:19.849199Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/RESTART/ACTION",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "message": "Microsoft.Compute/virtualMachines/restart/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "f9d30760-fc4c-f524-59d3-5f36195f8f72",
    "eventSubmissionTimestamp": "2026-07-28T04:13:19.849199Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "message": "Microsoft.Compute/virtualMachines/restart/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "f9d30760-fc4c-f524-59d3-5f36195f8f72",
    "eventSubmissionTimestamp": "2026-07-28T04:13:19.8491990Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/virtualMachines/retrieveBootDiagnosticsData/action

#
Namespace
Microsoft.Compute

Description

Retrieves boot diagnostic logs blob URIs

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure VM Boot Diagnostics Retrieved source medium: Identifies retrieval of Azure VM boot diagnostics data ("MICROSOFT.COMPUTE/VIRTUALMACHINES/RETRIEVEBOOTDIAGNOSTICSDATA/ACTION") by an identity that has not performed this operation recently. Boot diagnostics expose the VM serial console log and a console screenshot, which frequently contain plaintext boot-time output such as credentials, tokens, cloud-init/agent secrets, and command history. An adversary with VM read/contributor rights can retrieve this data over the control plane, without logging into the guest or touching the network, to harvest credentials.T1552

References #

Microsoft.Compute/virtualMachines/rollbackOSDisk/action

#
Namespace
Microsoft.Compute

Description

Rollback OSDisk on Virtual Machine after failed OS Upgrade invoked by Virtual Machine Scale Set with Flexible Orchestration Mode.

References #

Microsoft.Compute/virtualMachines/runCommand/action

#
Namespace
Microsoft.Compute

Description

Executes a predefined script on the virtual machine

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "action": "Microsoft.Compute/virtualMachines/runCommand/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "action": "Microsoft.Compute/virtualMachines/runCommand/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "fbf9e650-38a1-4cc1-9be1-d46eee1e7943",
  "EventDataId": "a129a816-7505-0425-f064-472eddd81b75",
  "EventSubmissionTimestamp": "2026-07-28T04:10:33.4448075Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "message": "Microsoft.Compute/virtualMachines/runCommand/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a129a816-7505-0425-f064-472eddd81b75",
    "eventSubmissionTimestamp": "2026-07-28T04:10:33.4448075Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
    "message": "Microsoft.Compute/virtualMachines/runCommand/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a129a816-7505-0425-f064-472eddd81b75",
    "eventSubmissionTimestamp": "2026-07-28T04:10:33.4448075Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure_ad::operation_name_value (kusto rule field)eqmicrosoft.compute/virtualmachines/runcommand/action4 ruleskusto
Authorization (kusto rule field)containsvirtualmachines3 ruleskusto
list_ActivityStatusValue (kusto rule field)containssucceeded3 ruleskusto
list_ActivityStatusValue (kusto rule field)containssuccess3 ruleskusto
ActionUncommonlyPerformedByUser (kusto rule field)eqTrue2 ruleskusto
StartTime (kusto rule field)geUEBAWindowStart2 ruleskusto
StartTime (kusto rule field)leUEBAWindowEnd2 ruleskusto
UEBASourceIPLocation (kusto rule field)is_not_null2 ruleskusto
aws::eventSource (kusto rule field)eqAzure AD2 ruleskusto
user (kusto rule field)is_not_null2 ruleskusto
ParentCommandLine (elastic rule field)eqpowershell -executionpolicy unrestricted -file script?.ps11 ruleelastic
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field)is_not_null1 ruleelastic
azure.resource.name (elastic rule field)is_not_null1 ruleelastic
event.module (elastic rule field)eqazure1 ruleelastic
parent_process_name (elastic rule field)eqpowershell.exe1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Run Command Correlated with Process Execution source medium: Correlates successful Azure Virtual Machine Run Command operations with endpoint process execution on the same host within minutes. Adversaries abuse Run Command to run scripts remotely as SYSTEM or root while activity logs only record the control-plane action; Elastic Defend process telemetry reveals the on-guest payload.T1059, T1059.001, T1651
  • Azure Compute VM Command Executed source medium: Identifies synchronous command execution on a virtual machine (VM) or virtual machine scale set (VMSS) in Azure via the action-based Run Command ("runCommand/action"). A Virtual Machine Contributor role lets you manage virtual machines, but not access them, nor access the virtual network or storage account they’re connected to. However, commands can be run on the VM via the Run Command feature, which execute as System (Windows) or root (Linux). Other roles, such as certain Administrator roles, may be able to execute commands on a VM as well.T1651↳ also matches Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action

Kusto #

Panther #

References #

Microsoft.Compute/virtualMachines/runCommands/delete

#
Namespace
Microsoft.Compute

Description

Deletes the virtual machine run command

References #

Microsoft.Compute/virtualMachines/runCommands/write

#
Namespace
Microsoft.Compute

Description

Creates a new virtual machine run command or updates an existing one

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure VM Managed Run Command Created or Updated with Unusual Principal source medium: Identifies the creation or update of a managed Azure Run Command resource ("MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMANDS/WRITE" or the virtual machine scale set equivalent) by an identity that has not performed this operation recently. Unlike the action-based Run Command ("runCommand/action"), the managed Run Command is a persistent resource on the VM whose creation or update executes the supplied script as System (Windows) or root (Linux). Because creating a managed run command both executes code and leaves a durable object, adversaries can use it as an alternative to the action invocation to evade detections that only watch "runCommand/action". Alerting on the first time a given principal performs this operation surfaces unusual or unauthorized use while suppressing routine automation that repeatedly manages the same run commands.T1651↳ also matches Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/write

References #

Microsoft.Compute/virtualMachines/setVMHealth/action

#
Namespace
Microsoft.Compute

Description

Sets health status on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode.

References #

Microsoft.Compute/virtualMachines/simulateEviction/action

#
Namespace
Microsoft.Compute

Description

Simulates the eviction of spot Virtual Machine

References #

Microsoft.Compute/virtualMachines/start/action

#
Namespace
Microsoft.Compute

Description

Starts the virtual machine

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "action": "Microsoft.Compute/virtualMachines/start/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "action": "Microsoft.Compute/virtualMachines/start/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "b66f156b-f58c-4f6d-9228-9bdc2e287840",
  "EventDataId": "c9664ee1-485c-9e29-6be8-f13a77c7f902",
  "EventSubmissionTimestamp": "2026-07-28T04:11:30.2954394Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/START/ACTION",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "message": "Microsoft.Compute/virtualMachines/start/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c9664ee1-485c-9e29-6be8-f13a77c7f902",
    "eventSubmissionTimestamp": "2026-07-28T04:11:30.2954394Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh7075e5vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
    "message": "Microsoft.Compute/virtualMachines/start/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c9664ee1-485c-9e29-6be8-f13a77c7f902",
    "eventSubmissionTimestamp": "2026-07-28T04:11:30.2954394Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh7075e5vm",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Compute/virtualMachines/upgradeVMAgent/action

#
Namespace
Microsoft.Compute

Description

Upgrade version of VM Agent on Virtual Machine

References #

Microsoft.Compute/virtualMachines/write

#
Namespace
Microsoft.Compute

Description

Creates a new virtual machine or updates an existing virtual machine

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "action": "Microsoft.Compute/virtualMachines/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "action": "Microsoft.Compute/virtualMachines/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
  "EventDataId": "48040b10-7e19-6001-932a-01ad7012e6d2",
  "EventSubmissionTimestamp": "2026-06-29T18:02:44.4196985Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcvm",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
      "type": "Microsoft.Compute/virtualMachines",
      "location": "westus2",
      "tags": {},
      "properties": {
        "hardwareProfile": {
          "vmSize": "Standard_D2s_v3"
        },
        "provisioningState": "Creating",
        "vmId": "67e9390f-4bb1-40ad-8753-f2b24bb00b00",
        "storageProfile": {
          "imageReference": {
            "publisher": "Canonical",
            "offer": "0001-com-ubuntu-server-jammy",
            "sku": "22_04-lts-gen2",
            "version": "latest",
            "exactVersion": "22.04.202606110"
          },
          "osDisk": {
            "osType": "Linux",
            "createOption": "FromImage",
            "caching": "ReadWrite",
            "managedDisk": {
              "storageAccountType": "Premium_LRS"
            },
            "deleteOption": "Detach",
            "diskSizeGB": 30
          },
          "dataDisks": [],
          "diskControllerType": "SCSI"
        },
        "osProfile": {
          "computerName": "zcvm",
          "linuxConfiguration": {
            "disablePasswordAuthentication": true,
            "ssh": {
              "publicKeys": [
                {
                  "path": "/home/zcadmin/.ssh/authorized_keys",
                  "keyData": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDeBZQWg6fCUl6IoZTp9kJVQLvhQRcJmmXpcZUXXyxfcH7WkuVs65rODvYVIrgr7i41XF7BBobWLdy+y5ib+c2t/E7sEXPe+CvaCLevc+rBIuD8UCZhWtp+Lp0QdL2UHDFE0mLRb1j+LTtkTkSVQfRT73JnVaDOLYuUiXx7UQ6iO97+PwE0BvVZceE9HTyXG5gfdwOvo+13ZbOssHFxSVczJ+XockGoljSrCwHMSVKcZhS/jKzgwJKeT+/Y3Rav9uUR0vBlyZFlbrANkirxPJDQ52NSraQFD0pRX4CYR5JQ59UsWmuMRV7b5gjN8fFw/AtVOs79s8TCRrL5fu2+J4LB"
                }
              ]
            },
            "provisionVMAgent": true,
            "patchSettings": {
              "patchMode": "ImageDefault",
              "assessmentMode": "ImageDefault"
            }
          },
          "secrets": [],
          "allowExtensionOperations": true,
          "requireGuestProvisionSignal": true,
          "adminUsername": "zcadmin"
        },
        "securityProfile": {
          "uefiSettings": {
            "secureBootEnabled": true,
            "vTpmEnabled": true
          },
          "securityType": "TrustedLaunch"
        },
        "networkProfile": {
          "networkInterfaces": [
            {
              "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic"
            }
          ]
        },
        "timeCreated": "2026-06-29T18:02:43.0495493+00:00"
      },
      "etag": "\"1\""
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "message": "Microsoft.Compute/virtualMachines/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "48040b10-7e19-6001-932a-01ad7012e6d2",
    "eventSubmissionTimestamp": "2026-06-29T18:02:44.4196985Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvm",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
    "message": "Microsoft.Compute/virtualMachines/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "48040b10-7e19-6001-932a-01ad7012e6d2",
    "eventSubmissionTimestamp": "2026-06-29T18:02:44.4196985Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvm",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.COMPUTE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcvm",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
      "type": "Microsoft.Compute/virtualMachines",
      "location": "westus2",
      "tags": {},
      "properties": {
        "hardwareProfile": {
          "vmSize": "Standard_D2s_v3"
        },
        "provisioningState": "Creating",
        "vmId": "67e9390f-4bb1-40ad-8753-f2b24bb00b00",
        "storageProfile": {
          "imageReference": {
            "publisher": "Canonical",
            "offer": "0001-com-ubuntu-server-jammy",
            "sku": "22_04-lts-gen2",
            "version": "latest",
            "exactVersion": "22.04.202606110"
          },
          "osDisk": {
            "osType": "Linux",
            "createOption": "FromImage",
            "caching": "ReadWrite",
            "managedDisk": {
              "storageAccountType": "Premium_LRS"
            },
            "deleteOption": "Detach",
            "diskSizeGB": 30
          },
          "dataDisks": [],
          "diskControllerType": "SCSI"
        },
        "osProfile": {
          "computerName": "zcvm",
          "linuxConfiguration": {
            "disablePasswordAuthentication": true,
            "ssh": {
              "publicKeys": [
                {
                  "path": "/home/zcadmin/.ssh/authorized_keys",
                  "keyData": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDeBZQWg6fCUl6IoZTp9kJVQLvhQRcJmmXpcZUXXyxfcH7WkuVs65rODvYVIrgr7i41XF7BBobWLdy+y5ib+c2t/E7sEXPe+CvaCLevc+rBIuD8UCZhWtp+Lp0QdL2UHDFE0mLRb1j+LTtkTkSVQfRT73JnVaDOLYuUiXx7UQ6iO97+PwE0BvVZceE9HTyXG5gfdwOvo+13ZbOssHFxSVczJ+XockGoljSrCwHMSVKcZhS/jKzgwJKeT+/Y3Rav9uUR0vBlyZFlbrANkirxPJDQ52NSraQFD0pRX4CYR5JQ59UsWmuMRV7b5gjN8fFw/AtVOs79s8TCRrL5fu2+J4LB"
                }
              ]
            },
            "provisionVMAgent": true,
            "patchSettings": {
              "patchMode": "ImageDefault",
              "assessmentMode": "ImageDefault"
            }
          },
          "secrets": [],
          "allowExtensionOperations": true,
          "requireGuestProvisionSignal": true,
          "adminUsername": "zcadmin"
        },
        "securityProfile": {
          "uefiSettings": {
            "secureBootEnabled": true,
            "vTpmEnabled": true
          },
          "securityType": "TrustedLaunch"
        },
        "networkProfile": {
          "networkInterfaces": [
            {
              "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic"
            }
          ]
        },
        "timeCreated": "2026-06-29T18:02:43.0495493+00:00"
      },
      "etag": "\"1\""
    },
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.COMPUTE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:02:44.4196985Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/virtualmachines/zcvm"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure_ad::operation_name_value (kusto rule field)inmicrosoft.compute/virtualmachines/write4 ruleskusto
azure_ad::operation_name_value (kusto rule field)inmicrosoft.resources/deployments/write4 ruleskusto
ActivityStatusValue (kusto rule field)starts_withAccept2 ruleskusto
Properties (kusto rule field)containsvmsize2 ruleskusto
vmSize (kusto rule field)cross_field_comparetoken2 ruleskusto
anomalies (kusto rule field)gt01 rulekusto
baseline (kusto rule field)gt01 rulekusto
properties.statusCode (sigma rule field)eqcreated1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Azure Virtual Machine Configuration Modified source low: Identifies a successful write to an Azure virtual machine resource ("MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE"). This operation is the parent action behind VM userData injection, where an adversary with VM contributor rights writes a base64 startup payload into the VM "userData" field that executes on the next reboot (a control-plane persistence technique requiring no guest access). The Azure activity log does not record the "userData" value or which property changed, so this behavior is indistinguishable from any other VM write at detection time. This is a building block rule and does not generate alerts on its own; it captures the VM write population so it can be correlated with other signals and baselined over time to tune a higher-fidelity userData-injection detection. To investigate a candidate, retrieve the live "userData" from the VM with an Azure Resource Manager GET using "$expand=userData".T1037, T1651

Kusto #

References #

Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/action

#
Namespace
Microsoft.Compute

Description

Approves deferred rolling upgrades for the instances of a Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/deallocate/action

#
Namespace
Microsoft.Compute

Description

Powers off and releases the compute resources for the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/delete/action

#
Namespace
Microsoft.Compute

Description

Deletes the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/disks/beginGetAccess/action

#
Namespace
Microsoft.Compute

Description

Get the SAS URI of VirtualMachineScaleSets Disk

References #

Microsoft.Compute/virtualMachineScaleSets/eventGridFilters/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Virtual Machine Scale Set Event Grid Filter

References #

Microsoft.Compute/virtualMachineScaleSets/eventGridFilters/write

#
Namespace
Microsoft.Compute

Description

Creates a new Virtual Machine Scale Set Event Grid Filter or updates an existing one

References #

Microsoft.Compute/virtualMachineScaleSets/extensions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the Virtual Machine Scale Set Extension

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)inmicrosoft.compute/virtualmachines/extensions/write1 ruleelastic
EventType (elastic rule field)inmicrosoft.compute/virtualmachinescalesets/extensions/write1 ruleelastic
azure.resource.name (elastic rule field)is_not_null1 ruleelastic
source.as.number (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Microsoft.Compute/virtualMachineScaleSets/extensions/roles/write

#
Namespace
Microsoft.Compute

Description

Updates the properties of an existing Role in a Virtual Machine Scale Set with the Virtual Machine Runtime Service Extension

References #

Microsoft.Compute/virtualMachineScaleSets/extensions/write

#
Namespace
Microsoft.Compute

Description

Creates a new Virtual Machine Scale Set Extension or updates an existing one

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventType (elastic rule field)inmicrosoft.compute/virtualmachines/extensions/write2 ruleselastic
EventType (elastic rule field)inmicrosoft.compute/virtualmachinescalesets/extensions/write2 ruleselastic
azure.resource.name (elastic rule field)is_not_null1 ruleelastic
source.as.number (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure VM Extension CRUD Operation with Unusual Source ASN source medium: Identifies create, read, update, or delete (CRUD) operations against Azure VM or VM scale set extensions ("MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/*" or the scale set equivalent) where the combination of the targeted extension resource name and the source autonomous system (AS) number has not been observed recently. VM extensions such as CustomScript and DSC run with high privilege on the guest (SYSTEM on Windows, root on Linux), so writing, modifying, or removing them is a common code-execution and persistence primitive. By keying a new terms approach on the extension resource name and the source AS number, this rule surfaces extension operations originating from networks that have not historically managed that extension, while routine first-party Microsoft automation (which originates from well-known Microsoft AS numbers) is excluded.T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/delete, Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachineScaleSets/extensions/delete
  • Unusual Azure VM Extension Detected source medium: Identifies the first time a given VM extension name is created or updated on an Azure virtual machine or VM scale set within the rule's lookback window. VM extensions run with high privilege on the guest (SYSTEM on Windows, root on Linux) and are a common code-execution and persistence primitive. The extension instance name is attacker-controlled and the Azure activity log records only that name, not the publisher or type, so the control plane cannot reliably identify the extension family (for example CustomScript). This rule therefore takes a type-agnostic ES|QL new-terms approach: it derives the host and the extension instance name from azure.resource.name and alerts the first time a given (host, extension name) pair is observed in the window, surfacing novel extension deployments while suppressing names a host routinely uses.T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/write

References #

Microsoft.Compute/virtualMachineScaleSets/forceRecoveryServiceFabricPlatformUpdateDomainWalk/action

#
Namespace
Microsoft.Compute

Description

Manually walk the platform update domains of a service fabric Virtual Machine Scale Set to finish a pending update that is stuck

References #

Microsoft.Compute/virtualMachineScaleSets/manualUpgrade/action

#
Namespace
Microsoft.Compute

Description

Manually updates instances to latest model of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/osRollingUpgrade/action

#
Namespace
Microsoft.Compute

Description

Starts a rolling upgrade to move all Virtual Machine Scale Set instances to the latest available Platform Image OS version.

References #

Microsoft.Compute/virtualMachineScaleSets/performMaintenance/action

#
Namespace
Microsoft.Compute

Description

Performs planned maintenance on the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/powerOff/action

#
Namespace
Microsoft.Compute

Description

Powers off the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Compute

Description

Creates or updates the diagnostic setting for the Virtual Machine Scale set.

References #

Microsoft.Compute/virtualMachineScaleSets/reapply/action

#
Namespace
Microsoft.Compute

Description

Reapply the Virtual Machine Scale Set Virtual Machine Profile to the Virtual Machine Instances

References #

Microsoft.Compute/virtualMachineScaleSets/redeploy/action

#
Namespace
Microsoft.Compute

Description

Redeploy the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/reimage/action

#
Namespace
Microsoft.Compute

Description

Reimages the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/reimageAll/action

#
Namespace
Microsoft.Compute

Description

Reimages all disks (OS Disk and Data Disks) for the instances of a Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/restart/action

#
Namespace
Microsoft.Compute

Description

Restarts the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/rollingUpgrades/action

#
Namespace
Microsoft.Compute

Description

Cancels the rolling upgrade of a Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/scale/action

#
Namespace
Microsoft.Compute

Description

Verify if an existing Virtual Machine Scale Set can Scale In/Scale Out to specified instance count

References #

Microsoft.Compute/virtualMachineScaleSets/setOrchestrationServiceState/action

#
Namespace
Microsoft.Compute

Description

Sets the state of an orchestration service based on the action provided in operation input.

References #

Microsoft.Compute/virtualMachineScaleSets/setVMHealth/action

#
Namespace
Microsoft.Compute

Description

Sets health status on Virtual Machines belonging to Virtual Machine Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/start/action

#
Namespace
Microsoft.Compute

Description

Starts the instances of the Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/approveRollingUpgrade/action

#
Namespace
Microsoft.Compute

Description

Approves deferred rolling upgrade for Virtual Machine instance in a Virtual Machine Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/attachDetachDataDisks/action

#
Namespace
Microsoft.Compute

Description

Attaches Detaches existing data disks to a Virtual Machine instance in a VM Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/deallocate/action

#
Namespace
Microsoft.Compute

Description

Powers off and releases the compute resources for a Virtual Machine in a VM Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/delete

#
Namespace
Microsoft.Compute

Description

Delete a specific Virtual Machine in a VM Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommand/action

#
Namespace
Microsoft.Compute

Description

Executes a diagnostic script on a Virtual Machine instance in a Virtual Machine Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommands/delete

#
Namespace
Microsoft.Compute

Description

Deletes the diagnostic run command for Virtual Machine in Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommands/write

#
Namespace
Microsoft.Compute

Description

Creates a new diagnostic run command for Virtual Machine in Virtual Machine Scale Set or updates an existing one

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/extensions/delete

#
Namespace
Microsoft.Compute

Description

Deletes the extension for Virtual Machine in Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/extensions/write

#
Namespace
Microsoft.Compute

Description

Creates a new extension for Virtual Machine in Virtual Machine Scale Set or updates an existing one

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/getEffectiveRouteTable/action

#
Namespace
Microsoft.Compute

Description

Get properties of effective route table on network interface of a virtual machine created using Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/getEffectiveSecurityGroups/action

#
Namespace
Microsoft.Compute

Description

Get properties of effective security groups on network interface of a virtual machine created using Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/performMaintenance/action

#
Namespace
Microsoft.Compute

Description

Performs planned maintenance on a Virtual Machine instance in a Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/powerOff/action

#
Namespace
Microsoft.Compute

Description

Powers Off a Virtual Machine instance in a VM Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/redeploy/action

#
Namespace
Microsoft.Compute

Description

Redeploys a Virtual Machine instance in a Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/reimage/action

#
Namespace
Microsoft.Compute

Description

Reimages a Virtual Machine instance in a Virtual Machine Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/reimageAll/action

#
Namespace
Microsoft.Compute

Description

Reimages all disks (OS Disk and Data Disks) for Virtual Machine instance in a Virtual Machine Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/restart/action

#
Namespace
Microsoft.Compute

Description

Restarts a Virtual Machine instance in a VM Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/retrieveBootDiagnosticsData/action

#
Namespace
Microsoft.Compute

Description

Retrieves boot diagnostic logs blob URIs of Virtual Machine instance in a Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action

#
Namespace
Microsoft.Compute

Description

Executes a predefined script on a Virtual Machine instance in a Virtual Machine Scale Set.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field)is_not_null1 ruleelastic
azure.resource.name (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Compute VM Command Executed source medium: Identifies synchronous command execution on a virtual machine (VM) or virtual machine scale set (VMSS) in Azure via the action-based Run Command ("runCommand/action"). A Virtual Machine Contributor role lets you manage virtual machines, but not access them, nor access the virtual network or storage account they’re connected to. However, commands can be run on the VM via the Run Command feature, which execute as System (Windows) or root (Linux). Other roles, such as certain Administrator roles, may be able to execute commands on a VM as well.T1651↳ also matches Microsoft.Compute/virtualMachines/runCommand/action

Panther #

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/delete

#
Namespace
Microsoft.Compute

Description

Deletes the run command for Virtual Machine in Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/write

#
Namespace
Microsoft.Compute

Description

Creates a new run command for Virtual Machine in Virtual Machine Scale Set or updates an existing one

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure VM Managed Run Command Created or Updated with Unusual Principal source medium: Identifies the creation or update of a managed Azure Run Command resource ("MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMANDS/WRITE" or the virtual machine scale set equivalent) by an identity that has not performed this operation recently. Unlike the action-based Run Command ("runCommand/action"), the managed Run Command is a persistent resource on the VM whose creation or update executes the supplied script as System (Windows) or root (Linux). Because creating a managed run command both executes code and leaves a durable object, adversaries can use it as an alternative to the action invocation to evade detections that only watch "runCommand/action". Alerting on the first time a given principal performs this operation surfaces unusual or unauthorized use while suppressing routine automation that repeatedly manages the same run commands.T1651↳ also matches Microsoft.Compute/virtualMachines/runCommands/write

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/simulateEviction/action

#
Namespace
Microsoft.Compute

Description

Simulates the eviction of spot Virtual Machine in Virtual Machine Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/start/action

#
Namespace
Microsoft.Compute

Description

Starts a Virtual Machine instance in a VM Scale Set.

References #

Microsoft.Compute/virtualMachineScaleSets/virtualMachines/write

#
Namespace
Microsoft.Compute

Description

Updates the properties of a Virtual Machine in a VM Scale Set

References #

Microsoft.Compute/virtualMachineScaleSets/write

#
Namespace
Microsoft.Compute

Description

Creates a new Virtual Machine Scale Set or updates an existing one

References #

Microsoft.Compute/virtualMachineScaleSets/forceRestart/action

#
Namespace
Microsoft.Compute

Description

Force Restart VM containers in a Virtual Machine Scale Set

References #