Azure Compute Azure-Microsoft.Compute
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.Compute rules that match the resource provider but no specific operation. | N | N |
| Microsoft.Compute/ | Deletes the availability set | Y | N |
| Microsoft.Compute/ | Creates a new availability set or updates an existing one | Y | N |
| Microsoft.Compute/ | Deletes the capacity reservation | N | N |
| Microsoft.Compute/ | Creates a new capacity reservation or updates an existing capacity reservation | N | N |
| Microsoft.Compute/ | Deletes the capacity reservation group | Y | N |
| Microsoft.Compute/ | Deploy a new VM/VMSS using Capacity Reservation Group | N | N |
| Microsoft.Compute/ | Share the Capacity Reservation Group with one or more Subscriptionss | N | N |
| Microsoft.Compute/ | Creates a new capacity reservation group or updates an existing capacity reservation group | Y | N |
| Microsoft.Compute/ | Deletes the CloudService. | N | N |
| Microsoft.Compute/ | Deletes role instances in a CloudService. | N | N |
| Microsoft.Compute/ | Power off the CloudService. | N | N |
| Microsoft.Compute/ | Creates or updates the diagnostic setting for the CloudService. | N | N |
| Microsoft.Compute/ | Reimage all the role instances in a CloudService. | N | N |
| Microsoft.Compute/ | Rebuilds all the disks in the role instances in a CloudService. | N | N |
| Microsoft.Compute/ | Restarts one or more role instances in a CloudService. | N | N |
| Microsoft.Compute/ | Deletes a RoleInstance from CloudService. | N | N |
| Microsoft.Compute/ | Rebuild all the disks in a CloudService. | N | N |
| Microsoft.Compute/ | Reimage a role instance of a CloudService. | N | N |
| Microsoft.Compute/ | Restart a role instance of a CloudService | N | N |
| Microsoft.Compute/ | Creates or updates the diagnostic setting for the CloudService Roles | N | N |
| Microsoft.Compute/ | Scale instances in a Role | N | N |
| Microsoft.Compute/ | Starts the CloudService. | N | N |
| Microsoft.Compute/ | Created a new CloudService or Update an existing one. | N | N |
| Microsoft.Compute/ | Delete a DiskAccess resource | Y | N |
| Microsoft.Compute/ | Delete a Private Endpoint Connection Proxy | N | N |
| Microsoft.Compute/ | Validate a Private Endpoint Connection Proxy object | N | N |
| Microsoft.Compute/ | Create a new Private Endpoint Connection Proxy | N | N |
| Microsoft.Compute/ | Delete a Private Endpoint Connection | N | N |
| Microsoft.Compute/ | Approve or Reject a Private Endpoint Connection | N | N |
| Microsoft.Compute/ | Auto Approve a Private Endpoint Connection | N | N |
| Microsoft.Compute/ | Create a new DiskAccess resource or update an existing one | Y | N |
| Microsoft.Compute/ | Delete a disk encryption set | N | N |
| Microsoft.Compute/ | Create a new disk encryption set or update an existing one | N | N |
| Microsoft.Compute/ | Get the SAS URI of the Disk for blob access | N | Y |
| Microsoft.Compute/ | Deletes the Disk | Y | Y |
| Microsoft.Compute/ | Revoke the SAS URI of the Disk | N | N |
| Microsoft.Compute/ | Creates a new Disk or updates an existing one | Y | N |
| Microsoft.Compute/ | Deletes the Gallery Application | N | N |
| Microsoft.Compute/ | Deletes the Gallery Application Version | N | N |
| Microsoft.Compute/ | Creates a new Gallery Application Version or updates an existing one | N | Y |
| Microsoft.Compute/ | Creates a new Gallery Application or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the Gallery | Y | N |
| Microsoft.Compute/ | Deletes the Gallery Image | N | N |
| Microsoft.Compute/ | Deletes the Gallery Image Version | N | N |
| Microsoft.Compute/ | Creates a new Gallery Image Version or updates an existing one | N | N |
| Microsoft.Compute/ | Creates a new Gallery Image or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the Gallery In VM Access Control Profile | N | N |
| Microsoft.Compute/ | Deletes the Gallery In VM Access Control Profile Version | N | N |
| Microsoft.Compute/ | Creates a new Gallery In VM Access Control Profile Version or updates an existing one | N | N |
| Microsoft.Compute/ | Creates a new Gallery In VM Access Control Profile or updates an existing one | N | N |
| Microsoft.Compute/ | Get the SAS URI of the Gallery Remote Container Image for blob access | N | N |
| Microsoft.Compute/ | Deletes the Gallery Remote Container Image | N | N |
| Microsoft.Compute/ | Creates a new Gallery Remote Container Image or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the Gallery Service Artifact | N | N |
| Microsoft.Compute/ | Creates a new Gallery Service Artifact or updates an existing one | N | N |
| Microsoft.Compute/ | Shares a Gallery to different scopes | N | N |
| Microsoft.Compute/ | Creates a new Gallery or updates an existing one | Y | N |
| Microsoft.Compute/ | Deletes the host group | Y | N |
| Microsoft.Compute/ | Deletes the host | N | N |
| Microsoft.Compute/ | Creates a new host or updates an existing host | N | N |
| Microsoft.Compute/ | Creates a new host group or updates an existing host group | Y | N |
| Microsoft.Compute/ | Deletes the image | N | N |
| Microsoft.Compute/ | Creates a new Image or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the interconnect block | N | N |
| Microsoft.Compute/ | Deploy a new VM/VMSS using Interconnect Block | N | N |
| Microsoft.Compute/ | Creates a new interconnect block or updates an existing interconnect block | N | N |
| Microsoft.Compute/ | Create a request for generating recommendations | N | N |
| Microsoft.Compute/ | Create a request for running Diagnostics | N | N |
| Microsoft.Compute/ | Create logs to show total requests by time interval to aid throttling diagnostics. | N | N |
| Microsoft.Compute/ | Create logs to show aggregates of throttled requests grouped by ResourceName, OperationName, or the applied Throttle Policy. | N | N |
| Microsoft.Compute/ | Create a request for generating Placement Scores | N | N |
| Microsoft.Compute/ | Create a request for generating VMSize Recommendations | N | N |
| Microsoft.Compute/ | Deletes the Proximity Placement Group | Y | N |
| Microsoft.Compute/ | Creates a new Proximity Placement Group or updates an existing one | Y | N |
| Microsoft.Compute/ | Registers Subscription with Microsoft.Compute resource provider | Y | N |
| Microsoft.Compute/ | Deletes the restore point collection and contained restore points | N | Y |
| Microsoft.Compute/ | Deletes the restore point | N | N |
| Microsoft.Compute/ | Get the SAS URI of the incremental DiskRestorePoint | N | N |
| Microsoft.Compute/ | Revoke the SAS URI of the incremental DiskRestorePoint | N | N |
| Microsoft.Compute/ | Get the properties of a restore point along with blob SAS URIs | N | N |
| Microsoft.Compute/ | Creates a new restore point | N | N |
| Microsoft.Compute/ | Creates a new restore point collection or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the Shared VM Extension | N | N |
| Microsoft.Compute/ | Deletes the Shared VM Extension Version | N | N |
| Microsoft.Compute/ | Creates a new Shared VM Extension Version or updates an existing one | N | N |
| Microsoft.Compute/ | Creates a new Shared VM Extension or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the SharedVMImage | N | N |
| Microsoft.Compute/ | Delete a SharedVMImageVersion | N | N |
| Microsoft.Compute/ | Replicate a SharedVMImageVersion to target regions | N | N |
| Microsoft.Compute/ | Create a new SharedVMImageVersion or update an existing one | N | N |
| Microsoft.Compute/ | Creates a new SharedVMImage or updates an existing one | N | N |
| Microsoft.Compute/ | Get the SAS URI of the Snapshot for blob access | N | N |
| Microsoft.Compute/ | Delete a Snapshot | Y | Y |
| Microsoft.Compute/ | Revoke the SAS URI of the Snapshot | N | N |
| Microsoft.Compute/ | Create a new Snapshot or update an existing one | Y | Y |
| Microsoft.Compute/ | Deletes the SSH public key | Y | N |
| Microsoft.Compute/ | Generates a new SSH public/private key pair | Y | N |
| Microsoft.Compute/ | Creates a new SSH public key or updates an existing SSH public key | Y | N |
| Microsoft.Compute/ | Unregisters Subscription with Microsoft.Compute resource provider | N | N |
| Microsoft.Compute/ | Assesses the virtual machine and finds list of available OS update patches for it. | N | N |
| Microsoft.Compute/ | Attaches Detaches existing data disks to a virtual machine | N | N |
| Microsoft.Compute/ | Cancels the ongoing install OS update patch operation on the virtual machine. | N | N |
| Microsoft.Compute/ | Captures the virtual machine by copying virtual hard disks and generates a template that can be used to create similar virtual machines | N | N |
| Microsoft.Compute/ | Converts the blob based disks of the virtual machine to managed disks | N | N |
| Microsoft.Compute/ | Powers off the virtual machine and releases the compute resources | Y | N |
| Microsoft.Compute/ | Deletes the virtual machine | Y | Y |
| Microsoft.Compute/ | Deletes PreservedOSDisk on the Virtual Machine which belongs to Virtual Machine Scale Set with Flexible Orchestration Mode. | N | N |
| Microsoft.Compute/ | Executes a diagnostic script on the virtual machine | N | N |
| Microsoft.Compute/ | Deletes the virtual machine diagnostic run command | N | N |
| Microsoft.Compute/ | Creates a new virtual machine diagnostic run command or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the virtual machine extension | Y | Y |
| Microsoft.Compute/ | Creates a new virtual machine extension or updates an existing one | Y | Y |
| Microsoft.Compute/ | Sets the virtual machine state to Generalized and prepares the virtual machine for capture | N | N |
| Microsoft.Compute/ | Installs available OS update patches on the virtual machine based on parameters provided by user. Assessment results containing list of available patches will also get refreshed as part of this. | N | N |
| Microsoft.Compute/ | Perform OS Upgrade on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode. | N | N |
| Microsoft.Compute/ | Performs Maintenance Operation on the VM. | N | N |
| Microsoft.Compute/ | Powers off the virtual machine. Note that the virtual machine will continue to be billed. | Y | N |
| Microsoft.Compute/ | Creates or updates the diagnostic setting for the Virtual Machine. | N | N |
| Microsoft.Compute/ | Reapplies a virtual machine's current model | N | N |
| Microsoft.Compute/ | Redeploys virtual machine | Y | N |
| Microsoft.Compute/ | Reimages virtual machine which is using differencing disk. | N | N |
| Microsoft.Compute/ | Restarts the virtual machine | Y | N |
| Microsoft.Compute/ | Retrieves boot diagnostic logs blob URIs | N | Y |
| Microsoft.Compute/ | Rollback OSDisk on Virtual Machine after failed OS Upgrade invoked by Virtual Machine Scale Set with Flexible Orchestration Mode. | N | N |
| Microsoft.Compute/ | Executes a predefined script on the virtual machine | Y | Y |
| Microsoft.Compute/ | Deletes the virtual machine run command | N | N |
| Microsoft.Compute/ | Creates a new virtual machine run command or updates an existing one | N | Y |
| Microsoft.Compute/ | Sets health status on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode. | N | N |
| Microsoft.Compute/ | Simulates the eviction of spot Virtual Machine | N | N |
| Microsoft.Compute/ | Starts the virtual machine | Y | N |
| Microsoft.Compute/ | Upgrade version of VM Agent on Virtual Machine | N | N |
| Microsoft.Compute/ | Creates a new virtual machine or updates an existing virtual machine | Y | Y |
| Microsoft.Compute/ | Approves deferred rolling upgrades for the instances of a Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Powers off and releases the compute resources for the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Deletes the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Deletes the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Get the SAS URI of VirtualMachineScaleSets Disk | N | N |
| Microsoft.Compute/ | Deletes the Virtual Machine Scale Set Event Grid Filter | N | N |
| Microsoft.Compute/ | Creates a new Virtual Machine Scale Set Event Grid Filter or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the Virtual Machine Scale Set Extension | N | Y |
| Microsoft.Compute/ | Updates the properties of an existing Role in a Virtual Machine Scale Set with the Virtual Machine Runtime Service Extension | N | N |
| Microsoft.Compute/ | Creates a new Virtual Machine Scale Set Extension or updates an existing one | N | Y |
| Microsoft.Compute/ | Manually walk the platform update domains of a service fabric Virtual Machine Scale Set to finish a pending update that is stuck | N | N |
| Microsoft.Compute/ | Manually updates instances to latest model of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Starts a rolling upgrade to move all Virtual Machine Scale Set instances to the latest available Platform Image OS version. | N | N |
| Microsoft.Compute/ | Performs planned maintenance on the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Powers off the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Creates or updates the diagnostic setting for the Virtual Machine Scale set. | N | N |
| Microsoft.Compute/ | Reapply the Virtual Machine Scale Set Virtual Machine Profile to the Virtual Machine Instances | N | N |
| Microsoft.Compute/ | Redeploy the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Reimages the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Reimages all disks (OS Disk and Data Disks) for the instances of a Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Restarts the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Cancels the rolling upgrade of a Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Verify if an existing Virtual Machine Scale Set can Scale In/Scale Out to specified instance count | N | N |
| Microsoft.Compute/ | Sets the state of an orchestration service based on the action provided in operation input. | N | N |
| Microsoft.Compute/ | Sets health status on Virtual Machines belonging to Virtual Machine Scale Set. | N | N |
| Microsoft.Compute/ | Starts the instances of the Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Approves deferred rolling upgrade for Virtual Machine instance in a Virtual Machine Scale Set. | N | N |
| Microsoft.Compute/ | Attaches Detaches existing data disks to a Virtual Machine instance in a VM Scale Set | N | N |
| Microsoft.Compute/ | Powers off and releases the compute resources for a Virtual Machine in a VM Scale Set. | N | N |
| Microsoft.Compute/ | Delete a specific Virtual Machine in a VM Scale Set. | N | N |
| Microsoft.Compute/ | Executes a diagnostic script on a Virtual Machine instance in a Virtual Machine Scale Set. | N | N |
| Microsoft.Compute/ | Deletes the diagnostic run command for Virtual Machine in Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Creates a new diagnostic run command for Virtual Machine in Virtual Machine Scale Set or updates an existing one | N | N |
| Microsoft.Compute/ | Deletes the extension for Virtual Machine in Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Creates a new extension for Virtual Machine in Virtual Machine Scale Set or updates an existing one | N | N |
| Microsoft.Compute/ | Get properties of effective route table on network interface of a virtual machine created using Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Get properties of effective security groups on network interface of a virtual machine created using Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Performs planned maintenance on a Virtual Machine instance in a Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Powers Off a Virtual Machine instance in a VM Scale Set. | N | N |
| Microsoft.Compute/ | Redeploys a Virtual Machine instance in a Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Reimages a Virtual Machine instance in a Virtual Machine Scale Set. | N | N |
| Microsoft.Compute/ | Reimages all disks (OS Disk and Data Disks) for Virtual Machine instance in a Virtual Machine Scale Set. | N | N |
| Microsoft.Compute/ | Restarts a Virtual Machine instance in a VM Scale Set. | N | N |
| Microsoft.Compute/ | Retrieves boot diagnostic logs blob URIs of Virtual Machine instance in a Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Executes a predefined script on a Virtual Machine instance in a Virtual Machine Scale Set. | N | Y |
| Microsoft.Compute/ | Deletes the run command for Virtual Machine in Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Creates a new run command for Virtual Machine in Virtual Machine Scale Set or updates an existing one | N | Y |
| Microsoft.Compute/ | Simulates the eviction of spot Virtual Machine in Virtual Machine Scale Set | N | N |
| Microsoft.Compute/ | Starts a Virtual Machine instance in a VM Scale Set. | N | N |
| Microsoft.Compute/ | Updates the properties of a Virtual Machine in a VM Scale Set | N | N |
| Microsoft.Compute/ | Creates a new Virtual Machine Scale Set or updates an existing one | N | N |
| Microsoft.Compute/ | Force Restart VM containers in a Virtual Machine Scale Set | N | N |
any: Azure Compute (catch-all)
#Description
Catch-all for Azure-Microsoft.Compute rules that match the resource provider but no specific operation.
References #
Microsoft.Compute/availabilitySets/delete
#Description
Deletes the availability set
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"action": "Microsoft.Compute/availabilitySets/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"action": "Microsoft.Compute/availabilitySets/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "0c349462-39c1-4d1b-b994-8b93cccc3bb9",
"EventDataId": "29acf873-4cb3-2123-ff3b-833c128e6e42",
"EventSubmissionTimestamp": "2026-07-02T17:24:16.4890268Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/AVAILABILITYSETS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"message": "Microsoft.Compute/availabilitySets/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "29acf873-4cb3-2123-ff3b-833c128e6e42",
"eventSubmissionTimestamp": "2026-07-02T17:24:16.4890268Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0avset",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"message": "Microsoft.Compute/availabilitySets/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "29acf873-4cb3-2123-ff3b-833c128e6e42",
"eventSubmissionTimestamp": "2026-07-02T17:24:16.4890268Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0avset",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/availabilitySets/write
#Description
Creates a new availability set or updates an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"action": "Microsoft.Compute/availabilitySets/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"action": "Microsoft.Compute/availabilitySets/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "91190fed-7da0-4948-950a-a582ae0b5a65",
"EventDataId": "d4766d29-6c2a-5ce0-05ba-53e82c684fe4",
"EventSubmissionTimestamp": "2026-07-02T17:13:46.521546Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/AVAILABILITYSETS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"responseBody": {
"name": "dwh92eef0avset",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"type": "Microsoft.Compute/availabilitySets",
"location": "westus2",
"tags": {},
"properties": {
"platformUpdateDomainCount": 5,
"platformFaultDomainCount": 2,
"virtualMachineScaleSetMigrationInfo": {
"defaultVirtualMachineScaleSetInfo": {
"constrainedMaximumCapacity": true,
"defaultVirtualMachineScaleSet": {
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachineScaleSets/dwh92eef0avset"
}
}
}
},
"sku": {
"name": "Aligned"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"message": "Microsoft.Compute/availabilitySets/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d4766d29-6c2a-5ce0-05ba-53e82c684fe4",
"eventSubmissionTimestamp": "2026-07-02T17:13:46.521546Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0avset",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"message": "Microsoft.Compute/availabilitySets/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d4766d29-6c2a-5ce0-05ba-53e82c684fe4",
"eventSubmissionTimestamp": "2026-07-02T17:13:46.5215460Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0avset",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK",
"responseBody": {
"name": "dwh92eef0avset",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/availabilitySets/dwh92eef0avset",
"type": "Microsoft.Compute/availabilitySets",
"location": "westus2",
"tags": {},
"properties": {
"platformUpdateDomainCount": 5,
"platformFaultDomainCount": 2,
"virtualMachineScaleSetMigrationInfo": {
"defaultVirtualMachineScaleSetInfo": {
"constrainedMaximumCapacity": true,
"defaultVirtualMachineScaleSet": {
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachineScaleSets/dwh92eef0avset"
}
}
}
},
"sku": {
"name": "Aligned"
}
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/capacityReservationGroups/capacityReservations/delete
#Description
Deletes the capacity reservation
References #
Microsoft.Compute/capacityReservationGroups/capacityReservations/write
#Description
Creates a new capacity reservation or updates an existing capacity reservation
References #
Microsoft.Compute/capacityReservationGroups/delete
#Description
Deletes the capacity reservation group
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"action": "Microsoft.Compute/capacityReservationGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"action": "Microsoft.Compute/capacityReservationGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "454e5bf7-dd9f-4b8f-88ce-b3e0f6781c95",
"EventDataId": "bd47c0f0-c25a-f6bb-8d2a-2155f61915e1",
"EventSubmissionTimestamp": "2026-07-02T18:26:53.4859311Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/CAPACITYRESERVATIONGROUPS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"message": "Microsoft.Compute/capacityReservationGroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "bd47c0f0-c25a-f6bb-8d2a-2155f61915e1",
"eventSubmissionTimestamp": "2026-07-02T18:26:53.4859311Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afcapacityreserv",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"message": "Microsoft.Compute/capacityReservationGroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "bd47c0f0-c25a-f6bb-8d2a-2155f61915e1",
"eventSubmissionTimestamp": "2026-07-02T18:26:53.4859311Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afcapacityreserv",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/capacityReservationGroups/deploy/action
#Description
Deploy a new VM/VMSS using Capacity Reservation Group
References #
Microsoft.Compute/capacityReservationGroups/write
#Description
Creates a new capacity reservation group or updates an existing capacity reservation group
Example Resource Log Record #
{
"ActivityStatusValue": "Accept",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"action": "Microsoft.Compute/capacityReservationGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"action": "Microsoft.Compute/capacityReservationGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "8c62e44c-9676-41bc-88da-f0ddc26659ac",
"EventDataId": "00d3d045-6e3c-d112-c180-8f5d1c8f4691",
"EventSubmissionTimestamp": "2026-07-02T18:26:48.6274802Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/CAPACITYRESERVATIONGROUPS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"responseBody": {
"name": "dwh2220afcapacityreserv",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"type": "Microsoft.Compute/capacityReservationGroups",
"location": "westus2",
"properties": {
"provisioningState": "Creating"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"message": "Microsoft.Compute/capacityReservationGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "00d3d045-6e3c-d112-c180-8f5d1c8f4691",
"eventSubmissionTimestamp": "2026-07-02T18:26:48.6274802Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afcapacityreserv",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"message": "Microsoft.Compute/capacityReservationGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "00d3d045-6e3c-d112-c180-8f5d1c8f4691",
"eventSubmissionTimestamp": "2026-07-02T18:26:48.6274802Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afcapacityreserv",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created",
"responseBody": {
"name": "dwh2220afcapacityreserv",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/capacityReservationGroups/dwh2220afcapacityreserv",
"type": "Microsoft.Compute/capacityReservationGroups",
"location": "westus2",
"properties": {
"provisioningState": "Creating"
}
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/cloudServices/delete/action
#Description
Deletes role instances in a CloudService.
References #
Microsoft.Compute/cloudServices/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the CloudService.
References #
Microsoft.Compute/cloudServices/rebuild/action
#Description
Reimage all the role instances in a CloudService.
References #
Microsoft.Compute/cloudServices/reimage/action
#Description
Rebuilds all the disks in the role instances in a CloudService.
References #
Microsoft.Compute/cloudServices/restart/action
#Description
Restarts one or more role instances in a CloudService.
References #
Microsoft.Compute/cloudServices/roleInstances/delete
#Description
Deletes a RoleInstance from CloudService.
References #
Microsoft.Compute/cloudServices/roleInstances/rebuild/action
#Description
Rebuild all the disks in a CloudService.
References #
Microsoft.Compute/cloudServices/roleInstances/reimage/action
#Description
Reimage a role instance of a CloudService.
References #
Microsoft.Compute/cloudServices/roleInstances/restart/action
#Description
Restart a role instance of a CloudService
References #
Microsoft.Compute/cloudServices/roles/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the CloudService Roles
References #
Microsoft.Compute/cloudServices/write
#Description
Created a new CloudService or Update an existing one.
References #
Microsoft.Compute/diskAccesses/delete
#Description
Delete a DiskAccess resource
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"action": "Microsoft.Compute/diskAccesses/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"action": "Microsoft.Compute/diskAccesses/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "894445c1-2680-40fa-9499-cc6ab8a0b074",
"EventDataId": "d4b892b7-4cce-5b81-f08f-ad5aa46122a7",
"EventSubmissionTimestamp": "2026-07-02T18:27:39.7663832Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/DISKACCESSES/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"message": "Microsoft.Compute/diskAccesses/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d4b892b7-4cce-5b81-f08f-ad5aa46122a7",
"eventSubmissionTimestamp": "2026-07-02T18:27:39.7663832Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afdiskaccesses",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"message": "Microsoft.Compute/diskAccesses/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d4b892b7-4cce-5b81-f08f-ad5aa46122a7",
"eventSubmissionTimestamp": "2026-07-02T18:27:39.7663832Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afdiskaccesses",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/delete
#Description
Delete a Private Endpoint Connection Proxy
References #
Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/validate/action
#Description
Validate a Private Endpoint Connection Proxy object
References #
Microsoft.Compute/diskAccesses/privateEndpointConnectionProxies/write
#Description
Create a new Private Endpoint Connection Proxy
References #
Microsoft.Compute/diskAccesses/privateEndpointConnections/delete
#Description
Delete a Private Endpoint Connection
References #
Microsoft.Compute/diskAccesses/privateEndpointConnections/write
#Description
Approve or Reject a Private Endpoint Connection
References #
Microsoft.Compute/diskAccesses/privateEndpointConnectionsApproval/action
#Description
Auto Approve a Private Endpoint Connection
References #
Microsoft.Compute/diskAccesses/write
#Description
Create a new DiskAccess resource or update an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"action": "Microsoft.Compute/diskAccesses/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"action": "Microsoft.Compute/diskAccesses/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "63369ae2-717e-43b6-8989-3d653a539f95",
"EventDataId": "2d6ef75b-6685-16f7-86cd-b387efd744d0",
"EventSubmissionTimestamp": "2026-07-02T18:27:06.9958837Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/DISKACCESSES/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"message": "Microsoft.Compute/diskAccesses/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "2d6ef75b-6685-16f7-86cd-b387efd744d0",
"eventSubmissionTimestamp": "2026-07-02T18:27:06.9958837Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afdiskaccesses",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/diskAccesses/dwh2220afdiskaccesses",
"message": "Microsoft.Compute/diskAccesses/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "2d6ef75b-6685-16f7-86cd-b387efd744d0",
"eventSubmissionTimestamp": "2026-07-02T18:27:06.9958837Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afdiskaccesses",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/diskEncryptionSets/write
#Description
Create a new disk encryption set or update an existing one
References #
Microsoft.Compute/disks/beginGetAccess/action
#Description
Get the SAS URI of the Disk for blob access
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1530, T1567.002
References #
Microsoft.Compute/disks/delete
#Description
Deletes the Disk
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
"action": "Microsoft.Compute/disks/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
"action": "Microsoft.Compute/disks/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "3cfc3312-e78b-4dca-b619-fbede0317764",
"EventDataId": "3cbc01c6-3116-7346-ed49-602987b198b4",
"EventSubmissionTimestamp": "2026-06-29T18:07:14.0019028Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.COMPUTE/DISKS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
"message": "Microsoft.Compute/disks/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3cbc01c6-3116-7346-ed49-602987b198b4",
"eventSubmissionTimestamp": "2026-06-29T18:07:14.0019028Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm_disk1_b357687f7348480ca29adf88826cacda",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda",
"message": "Microsoft.Compute/disks/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3cbc01c6-3116-7346-ed49-602987b198b4",
"eventSubmissionTimestamp": "2026-06-29T18:07:14.0019028Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm_disk1_b357687f7348480ca29adf88826cacda",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:07:14.0019028Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/disks/zcvm_disk1_b357687f7348480ca29adf88826cacda"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490
References #
Microsoft.Compute/disks/write
#Description
Creates a new Disk or updates an existing one
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Accept",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Accepted",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
"action": "Microsoft.Compute/disks/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
"action": "Microsoft.Compute/disks/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "08d5e0fe-4661-4d2c-9f6f-eb11f4e0274c",
"EventDataId": "dfe94d83-2ee1-1215-44e0-459ab3347584",
"EventSubmissionTimestamp": "2026-06-29T19:03:08.1580603Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.COMPUTE/DISKS/WRITE",
"Properties": {
"statusCode": "Accepted",
"serviceRequestId": "",
"responseBody": {
"name": "zcdisk3",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
"type": "Microsoft.Compute/disks",
"location": "westus2",
"tags": {},
"sku": {
"name": "Standard_LRS"
},
"properties": {
"creationData": {
"createOption": "Empty"
},
"diskSizeGB": 4,
"provisioningState": "Updating"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
"message": "Microsoft.Compute/disks/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "dfe94d83-2ee1-1215-44e0-459ab3347584",
"eventSubmissionTimestamp": "2026-06-29T19:03:08.1580603Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcdisk3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Properties_d": {
"statusCode": "Accepted",
"serviceRequestId": "",
"responseBody": {
"name": "zcdisk3",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
"type": "Microsoft.Compute/disks",
"location": "westus2",
"tags": {},
"sku": {
"name": "Standard_LRS"
},
"properties": {
"creationData": {
"createOption": "Empty"
},
"diskSizeGB": 4,
"provisioningState": "Updating"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/disks/zcdisk3",
"message": "Microsoft.Compute/disks/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "dfe94d83-2ee1-1215-44e0-459ab3347584",
"eventSubmissionTimestamp": "2026-06-29T19:03:08.1580603Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcdisk3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:03:08.1580603Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/disks/zcdisk3"
}
References #
Microsoft.Compute/galleries/applications/delete
#Description
Deletes the Gallery Application
References #
Microsoft.Compute/galleries/applications/versions/delete
#Description
Deletes the Gallery Application Version
References #
Microsoft.Compute/galleries/applications/versions/write
#Description
Creates a new Gallery Application Version or updates an existing one
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachines/runCommand/action, Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action
References #
Microsoft.Compute/galleries/applications/write
#Description
Creates a new Gallery Application or updates an existing one
References #
Microsoft.Compute/galleries/delete
#Description
Deletes the Gallery
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"action": "Microsoft.Compute/galleries/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"action": "Microsoft.Compute/galleries/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "87f588e8-0f51-46a5-ad92-2798faf2c7d0",
"EventDataId": "fd67edef-574b-e9a0-dfa5-5081f436af83",
"EventSubmissionTimestamp": "2026-07-02T18:28:30.1506154Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/GALLERIES/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"message": "Microsoft.Compute/galleries/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "fd67edef-574b-e9a0-dfa5-5081f436af83",
"eventSubmissionTimestamp": "2026-07-02T18:28:30.1506154Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afgalleries",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"message": "Microsoft.Compute/galleries/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "fd67edef-574b-e9a0-dfa5-5081f436af83",
"eventSubmissionTimestamp": "2026-07-02T18:28:30.1506154Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afgalleries",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/galleries/images/versions/delete
#Description
Deletes the Gallery Image Version
References #
Microsoft.Compute/galleries/images/versions/write
#Description
Creates a new Gallery Image Version or updates an existing one
References #
Microsoft.Compute/galleries/images/write
#Description
Creates a new Gallery Image or updates an existing one
References #
Microsoft.Compute/galleries/inVMAccessControlProfiles/delete
#Description
Deletes the Gallery In VM Access Control Profile
References #
Microsoft.Compute/galleries/inVMAccessControlProfiles/versions/delete
#Description
Deletes the Gallery In VM Access Control Profile Version
References #
Microsoft.Compute/galleries/inVMAccessControlProfiles/write
#Description
Creates a new Gallery In VM Access Control Profile or updates an existing one
References #
Microsoft.Compute/galleries/remoteContainerImages/beginGetAccess/action
#Description
Get the SAS URI of the Gallery Remote Container Image for blob access
References #
Microsoft.Compute/galleries/remoteContainerImages/delete
#Description
Deletes the Gallery Remote Container Image
References #
Microsoft.Compute/galleries/remoteContainerImages/write
#Description
Creates a new Gallery Remote Container Image or updates an existing one
References #
Microsoft.Compute/galleries/serviceArtifacts/delete
#Description
Deletes the Gallery Service Artifact
References #
Microsoft.Compute/galleries/serviceArtifacts/write
#Description
Creates a new Gallery Service Artifact or updates an existing one
References #
Microsoft.Compute/galleries/write
#Description
Creates a new Gallery or updates an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"action": "Microsoft.Compute/galleries/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"action": "Microsoft.Compute/galleries/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "07900c1e-81df-44bc-8f37-d2e795d88d77",
"EventDataId": "e1cdb2fa-0e1e-472a-c914-0c039e9bdc09",
"EventSubmissionTimestamp": "2026-07-02T18:27:59.3026249Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/GALLERIES/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"message": "Microsoft.Compute/galleries/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e1cdb2fa-0e1e-472a-c914-0c039e9bdc09",
"eventSubmissionTimestamp": "2026-07-02T18:27:59.3026249Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afgalleries",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/galleries/dwh2220afgalleries",
"message": "Microsoft.Compute/galleries/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e1cdb2fa-0e1e-472a-c914-0c039e9bdc09",
"eventSubmissionTimestamp": "2026-07-02T18:27:59.3026249Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afgalleries",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/hostGroups/delete
#Description
Deletes the host group
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
"action": "Microsoft.Compute/hostGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
"action": "Microsoft.Compute/hostGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "9a5abe0d-9cbf-4419-b982-a14132277d0c",
"EventDataId": "cc892eb3-a1ae-a496-8175-30c1aa9e2c87",
"EventSubmissionTimestamp": "2026-07-03T02:28:58.6026803Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/HOSTGROUPS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
"message": "Microsoft.Compute/hostGroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "cc892eb3-a1ae-a496-8175-30c1aa9e2c87",
"eventSubmissionTimestamp": "2026-07-03T02:28:58.6026803Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dhostgroups",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwhc6a93dhostgroups",
"message": "Microsoft.Compute/hostGroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "cc892eb3-a1ae-a496-8175-30c1aa9e2c87",
"eventSubmissionTimestamp": "2026-07-03T02:28:58.6026803Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dhostgroups",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/hostGroups/hosts/write
#Description
Creates a new host or updates an existing host
References #
Microsoft.Compute/hostGroups/write
#Description
Creates a new host group or updates an existing host group
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
"action": "Microsoft.Compute/hostGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
"action": "Microsoft.Compute/hostGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "4668a2cd-1a2a-446d-a9f7-2b806ab4be86",
"EventDataId": "9b1f1bea-66b4-a8cf-0da0-c15b592b9090",
"EventSubmissionTimestamp": "2026-07-02T18:38:31.7179525Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/HOSTGROUPS/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
"message": "Microsoft.Compute/hostGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9b1f1bea-66b4-a8cf-0da0-c15b592b9090",
"eventSubmissionTimestamp": "2026-07-02T18:38:31.7179525Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afhostgroups",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/hostGroups/dwh2220afhostgroups",
"message": "Microsoft.Compute/hostGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9b1f1bea-66b4-a8cf-0da0-c15b592b9090",
"eventSubmissionTimestamp": "2026-07-02T18:38:31.7179525Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afhostgroups",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/images/write
#Description
Creates a new Image or updates an existing one
References #
Microsoft.Compute/interconnectBlocks/deploy/action
#Description
Deploy a new VM/VMSS using Interconnect Block
References #
Microsoft.Compute/interconnectBlocks/write
#Description
Creates a new interconnect block or updates an existing interconnect block
References #
Microsoft.Compute/locations/diagnostics/generate/action
#Description
Create a request for generating recommendations
References #
Microsoft.Compute/locations/diagnostics/run/action
#Description
Create a request for running Diagnostics
References #
Microsoft.Compute/locations/logAnalytics/getRequestRateByInterval/action
#Description
Create logs to show total requests by time interval to aid throttling diagnostics.
References #
Microsoft.Compute/locations/logAnalytics/getThrottledRequests/action
#Description
Create logs to show aggregates of throttled requests grouped by ResourceName, OperationName, or the applied Throttle Policy.
References #
Microsoft.Compute/locations/placementScores/generate/action
#Description
Create a request for generating Placement Scores
References #
Microsoft.Compute/locations/vmSizeRecommendations/generate/action
#Description
Create a request for generating VMSize Recommendations
References #
Microsoft.Compute/proximityPlacementGroups/delete
#Description
Deletes the Proximity Placement Group
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"action": "Microsoft.Compute/proximityPlacementGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"action": "Microsoft.Compute/proximityPlacementGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "d8692a11-d74a-45dd-84ea-ce8e9b57d182",
"EventDataId": "43846790-a3dd-39e4-d409-cfc14133458c",
"EventSubmissionTimestamp": "2026-07-02T17:14:23.4972934Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/PROXIMITYPLACEMENTGROUPS/DELETE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"message": "Microsoft.Compute/proximityPlacementGroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "43846790-a3dd-39e4-d409-cfc14133458c",
"eventSubmissionTimestamp": "2026-07-02T17:14:23.4972934Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0ppg",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"message": "Microsoft.Compute/proximityPlacementGroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "43846790-a3dd-39e4-d409-cfc14133458c",
"eventSubmissionTimestamp": "2026-07-02T17:14:23.4972934Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0ppg",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/proximityPlacementGroups/write
#Description
Creates a new Proximity Placement Group or updates an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"action": "Microsoft.Compute/proximityPlacementGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"action": "Microsoft.Compute/proximityPlacementGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "4c9eb9aa-4d96-47eb-8861-e33e357cf0b9",
"EventDataId": "50a1e27d-5d47-2e04-57ee-2b9f8150aded",
"EventSubmissionTimestamp": "2026-07-02T17:14:21.9472157Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/PROXIMITYPLACEMENTGROUPS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"responseBody": {
"name": "dwh92eef0ppg",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"type": "Microsoft.Compute/proximityPlacementGroups",
"location": "westus2",
"properties": {
"proximityPlacementGroupType": "Standard"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"message": "Microsoft.Compute/proximityPlacementGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "50a1e27d-5d47-2e04-57ee-2b9f8150aded",
"eventSubmissionTimestamp": "2026-07-02T17:14:21.9472157Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0ppg",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"message": "Microsoft.Compute/proximityPlacementGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "50a1e27d-5d47-2e04-57ee-2b9f8150aded",
"eventSubmissionTimestamp": "2026-07-02T17:14:21.9472157Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0ppg",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created",
"responseBody": {
"name": "dwh92eef0ppg",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/proximityPlacementGroups/dwh92eef0ppg",
"type": "Microsoft.Compute/proximityPlacementGroups",
"location": "westus2",
"properties": {
"proximityPlacementGroupType": "Standard"
}
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/register/action
#Description
Registers Subscription with Microsoft.Compute resource provider
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.Compute/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.Compute/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "56cd70e1-88f7-4ab2-a48a-1e2223f3a719",
"EventDataId": "8bbf885c-6367-c09e-14c0-d0cb1588bd9c",
"EventSubmissionTimestamp": "2026-07-28T04:08:58.2002834Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/REGISTER/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Compute",
"message": "Microsoft.Compute/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "8bbf885c-6367-c09e-14c0-d0cb1588bd9c",
"eventSubmissionTimestamp": "2026-07-28T04:08:58.2002834Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Compute",
"message": "Microsoft.Compute/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "8bbf885c-6367-c09e-14c0-d0cb1588bd9c",
"eventSubmissionTimestamp": "2026-07-28T04:08:58.2002834Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/restorePointCollections/delete
#Description
Deletes the restore point collection and contained restore points
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType (elastic rule field) | eq | microsoft.compute/restorepointcollections/delete | 2 rules | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1490T1490Panther #
T1485, T1490
References #
Microsoft.Compute/restorePointCollections/restorePoints/delete
#Description
Deletes the restore point
References #
Microsoft.Compute/restorePointCollections/restorePoints/diskRestorePoints/beginGetAccess/action
#Description
Get the SAS URI of the incremental DiskRestorePoint
References #
Microsoft.Compute/restorePointCollections/restorePoints/diskRestorePoints/endGetAccess/action
#Description
Revoke the SAS URI of the incremental DiskRestorePoint
References #
Microsoft.Compute/restorePointCollections/restorePoints/retrieveSasUris/action
#Description
Get the properties of a restore point along with blob SAS URIs
References #
Microsoft.Compute/restorePointCollections/restorePoints/write
#Description
Creates a new restore point
References #
Microsoft.Compute/restorePointCollections/write
#Description
Creates a new restore point collection or updates an existing one
References #
Microsoft.Compute/snapshots/beginGetAccess/action
#Description
Get the SAS URI of the Snapshot for blob access
References #
Microsoft.Compute/snapshots/delete
#Description
Delete a Snapshot
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
"action": "Microsoft.Compute/snapshots/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
"action": "Microsoft.Compute/snapshots/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "9e9b38be-b4c1-4678-80cd-ffef49c8a318",
"EventDataId": "95db2ab3-8c63-ea2b-4ca9-01f28d5621b8",
"EventSubmissionTimestamp": "2026-07-28T04:12:23.442875Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/SNAPSHOTS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
"message": "Microsoft.Compute/snapshots/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "95db2ab3-8c63-ea2b-4ca9-01f28d5621b8",
"eventSubmissionTimestamp": "2026-07-28T04:12:23.442875Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665snap",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/dwh38d665snap",
"message": "Microsoft.Compute/snapshots/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "95db2ab3-8c63-ea2b-4ca9-01f28d5621b8",
"eventSubmissionTimestamp": "2026-07-28T04:12:23.4428750Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665snap",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.activitylogs.identity.claims_initiated_by_user.name (elastic rule field) | is_not_null | | 2 rules | elastic |
azure.activitylogs.properties.status_code (elastic rule field) | eq | accepted | 2 rules | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1490T1485, T1490Panther #
T1485, T1490
References #
Microsoft.Compute/snapshots/endGetAccess/action
#Description
Revoke the SAS URI of the Snapshot
References #
Microsoft.Compute/snapshots/write
#Description
Create a new Snapshot or update an existing one
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
"action": "Microsoft.Compute/snapshots/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
"action": "Microsoft.Compute/snapshots/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "0969a0c7-44b8-4252-837c-e21b42e5d586",
"EventDataId": "4aed47ad-3481-6455-71af-7e2a0fa15c87",
"EventSubmissionTimestamp": "2026-06-29T19:03:14.6313372Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.COMPUTE/SNAPSHOTS/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
"message": "Microsoft.Compute/snapshots/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "4aed47ad-3481-6455-71af-7e2a0fa15c87",
"eventSubmissionTimestamp": "2026-06-29T19:03:14.6313372Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcsnap3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/snapshots/zcsnap3",
"message": "Microsoft.Compute/snapshots/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "4aed47ad-3481-6455-71af-7e2a0fa15c87",
"eventSubmissionTimestamp": "2026-06-29T19:03:14.6313372Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcsnap3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:03:14.6313372Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/snapshots/zcsnap3"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ActivityStatusValue (kusto rule field) | eq | success | 1 rule | kusto |
count_ (kusto rule field) | ge | 5 | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1003
References #
Microsoft.Compute/sshPublicKeys/delete
#Description
Deletes the SSH public key
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
"action": "Microsoft.Compute/sshPublicKeys/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
"action": "Microsoft.Compute/sshPublicKeys/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "18f1dffc-51f2-46df-b203-158f5a735f76",
"EventDataId": "82fdf158-43ac-8fed-e2f0-5c79180a72b2",
"EventSubmissionTimestamp": "2026-07-03T02:29:00.2040497Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/SSHPUBLICKEYS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
"message": "Microsoft.Compute/sshPublicKeys/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "82fdf158-43ac-8fed-e2f0-5c79180a72b2",
"eventSubmissionTimestamp": "2026-07-03T02:29:00.2040497Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dsshpublickeys",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwhc6a93dsshpublickeys",
"message": "Microsoft.Compute/sshPublicKeys/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "82fdf158-43ac-8fed-e2f0-5c79180a72b2",
"eventSubmissionTimestamp": "2026-07-03T02:29:00.2040497Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dsshpublickeys",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/sshPublicKeys/generateKeyPair/action
#Description
Generates a new SSH public/private key pair
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"action": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"action": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "da1e1936-e633-4437-b268-5de2beff681b",
"EventDataId": "283d0f94-a8bb-cb10-a70f-2a4c18193709",
"EventSubmissionTimestamp": "2026-07-02T18:28:34.1562356Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/SSHPUBLICKEYS/GENERATEKEYPAIR/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"message": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "283d0f94-a8bb-cb10-a70f-2a4c18193709",
"eventSubmissionTimestamp": "2026-07-02T18:28:34.1562356Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afsshpublickeys",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"message": "Microsoft.Compute/sshPublicKeys/generateKeyPair/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "283d0f94-a8bb-cb10-a70f-2a4c18193709",
"eventSubmissionTimestamp": "2026-07-02T18:28:34.1562356Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afsshpublickeys",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/sshPublicKeys/write
#Description
Creates a new SSH public key or updates an existing SSH public key
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"action": "Microsoft.Compute/sshPublicKeys/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"action": "Microsoft.Compute/sshPublicKeys/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "aae59fcf-d2b4-46e2-a5a0-96513ba1f1bf",
"EventDataId": "439d9215-d076-6fb8-7410-d07f00aaccf3",
"EventSubmissionTimestamp": "2026-07-02T18:38:34.2965052Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/SSHPUBLICKEYS/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"message": "Microsoft.Compute/sshPublicKeys/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "439d9215-d076-6fb8-7410-d07f00aaccf3",
"eventSubmissionTimestamp": "2026-07-02T18:38:34.2965052Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afsshpublickeys",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/sshPublicKeys/dwh2220afsshpublickeys",
"message": "Microsoft.Compute/sshPublicKeys/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "439d9215-d076-6fb8-7410-d07f00aaccf3",
"eventSubmissionTimestamp": "2026-07-02T18:38:34.2965052Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afsshpublickeys",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/virtualMachines/assessPatches/action
#Description
Assesses the virtual machine and finds list of available OS update patches for it.
References #
Microsoft.Compute/virtualMachines/attachDetachDataDisks/action
#Description
Attaches Detaches existing data disks to a virtual machine
References #
Microsoft.Compute/virtualMachines/cancelPatchInstallation/action
#Description
Cancels the ongoing install OS update patch operation on the virtual machine.
References #
Microsoft.Compute/virtualMachines/capture/action
#Description
Captures the virtual machine by copying virtual hard disks and generates a template that can be used to create similar virtual machines
References #
Microsoft.Compute/virtualMachines/convertToManagedDisks/action
#Description
Converts the blob based disks of the virtual machine to managed disks
References #
Microsoft.Compute/virtualMachines/deallocate/action
#Description
Powers off the virtual machine and releases the compute resources
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"action": "Microsoft.Compute/virtualMachines/deallocate/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"action": "Microsoft.Compute/virtualMachines/deallocate/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "f9124087-f7d7-4101-aa0b-9925397fe95a",
"EventDataId": "dde5c871-73d7-1e33-3648-156b72abe63b",
"EventSubmissionTimestamp": "2026-07-28T04:12:33.6376326Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/DEALLOCATE/ACTION",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"message": "Microsoft.Compute/virtualMachines/deallocate/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "dde5c871-73d7-1e33-3648-156b72abe63b",
"eventSubmissionTimestamp": "2026-07-28T04:12:33.6376326Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh7075e5vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"message": "Microsoft.Compute/virtualMachines/deallocate/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "dde5c871-73d7-1e33-3648-156b72abe63b",
"eventSubmissionTimestamp": "2026-07-28T04:12:33.6376326Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh7075e5vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/virtualMachines/delete
#Description
Deletes the virtual machine
Example Resource Log Record #
{
"TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
"SourceSystem": "Azure",
"CallerIpAddress": "37.142.150.162",
"CategoryValue": "Administrative",
"CorrelationId": "3387cf7f-24b2-482f-9f4e-1ef7ceb08c14",
"Authorization": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
"action": "Microsoft.Compute/virtualMachines/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
"action": "Microsoft.Compute/virtualMachines/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE",
"Properties": {
"statusCode": "Accepted",
"serviceRequestId": "4b895e78-45c6-421a-a904-adb1f810bf99",
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
"message": "Microsoft.Compute/virtualMachines/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "9a0ebf0f-aa1f-4a59-b0d6-cb0f10e134ec",
"eventSubmissionTimestamp": "2021-04-28T14:36:53.2672695Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "linux01",
"resourceGroup": "VM-RG01",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Properties_d": {
"statusCode": "Accepted",
"serviceRequestId": "4b895e78-45c6-421a-a904-adb1f810bf99",
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/VM-RG01/providers/Microsoft.Compute/virtualMachines/Linux01",
"message": "Microsoft.Compute/virtualMachines/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "9a0ebf0f-aa1f-4a59-b0d6-cb0f10e134ec",
"eventSubmissionTimestamp": "2021-04-28T14:36:53.2672695Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "linux01",
"resourceGroup": "VM-RG01",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Caller": "AdeleV@M365x816222.OnMicrosoft.com",
"EventDataId": "9a0ebf0f-aa1f-4a59-b0d6-cb0f10e134ec",
"EventSubmissionTimestamp": "4/28/2021, 2:36:53.267 PM",
"HTTPRequest": {
"clientIpAddress": "37.142.150.162"
},
"ResourceGroup": "VM-RG01",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"ActivityStatusValue": "Accept",
"ActivitySubstatusValue": "Accepted",
"Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"TimeGenerated": "4/28/2021, 2:36:53.267 PM",
"SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"Type": "AzureActivity"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1489
References #
Microsoft.Compute/virtualMachines/deletePreservedOSDisk/action
#Description
Deletes PreservedOSDisk on the Virtual Machine which belongs to Virtual Machine Scale Set with Flexible Orchestration Mode.
References #
Microsoft.Compute/virtualMachines/diagnosticRunCommand/action
#Description
Executes a diagnostic script on the virtual machine
References #
Microsoft.Compute/virtualMachines/diagnosticRunCommands/delete
#Description
Deletes the virtual machine diagnostic run command
References #
Microsoft.Compute/virtualMachines/diagnosticRunCommands/write
#Description
Creates a new virtual machine diagnostic run command or updates an existing one
References #
Microsoft.Compute/virtualMachines/extensions/delete
#Description
Deletes the virtual machine extension
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"action": "Microsoft.Compute/virtualMachines/extensions/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"action": "Microsoft.Compute/virtualMachines/extensions/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "c33a76f7-d376-4511-9268-9cf10eaa4c16",
"EventDataId": "2112148f-fec0-7c47-d0e2-79f0f4e87fb3",
"EventSubmissionTimestamp": "2026-07-28T04:13:22.2789062Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"message": "Microsoft.Compute/virtualMachines/extensions/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "2112148f-fec0-7c47-d0e2-79f0f4e87fb3",
"eventSubmissionTimestamp": "2026-07-28T04:13:22.2789062Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm/dwharn-custom-script",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"message": "Microsoft.Compute/virtualMachines/extensions/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "2112148f-fec0-7c47-d0e2-79f0f4e87fb3",
"eventSubmissionTimestamp": "2026-07-28T04:13:22.2789062Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm/dwharn-custom-script",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType (elastic rule field) | in | microsoft.compute/virtualmachines/extensions/write | 1 rule | elastic |
EventType (elastic rule field) | in | microsoft.compute/virtualmachinescalesets/extensions/write | 1 rule | elastic |
azure.resource.name (elastic rule field) | is_not_null | | 1 rule | elastic |
source.as.number (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachineScaleSets/extensions/delete, Microsoft.Compute/virtualMachineScaleSets/extensions/write
References #
Microsoft.Compute/virtualMachines/extensions/write
#Description
Creates a new virtual machine extension or updates an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Accept",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"action": "Microsoft.Compute/virtualMachines/extensions/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"action": "Microsoft.Compute/virtualMachines/extensions/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "09fbcf5c-8980-4973-a79a-4b75b6dd8ffe",
"EventDataId": "e527e5ca-060d-cee6-1d83-b67dd38195e8",
"EventSubmissionTimestamp": "2026-07-28T04:11:14.8174458Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"responseBody": {
"name": "dwharn-custom-script",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"type": "Microsoft.Compute/virtualMachines/extensions",
"location": "westus2",
"properties": {
"autoUpgradeMinorVersion": true,
"provisioningState": "Creating",
"publisher": "Microsoft.Azure.Extensions",
"type": "CustomScript",
"typeHandlerVersion": "2.1",
"settings": "******"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"message": "Microsoft.Compute/virtualMachines/extensions/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e527e5ca-060d-cee6-1d83-b67dd38195e8",
"eventSubmissionTimestamp": "2026-07-28T04:11:14.8174458Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm/dwharn-custom-script",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"statusCode": "Created",
"serviceRequestId": "",
"responseBody": {
"name": "dwharn-custom-script",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"type": "Microsoft.Compute/virtualMachines/extensions",
"location": "westus2",
"properties": {
"autoUpgradeMinorVersion": true,
"provisioningState": "Creating",
"publisher": "Microsoft.Azure.Extensions",
"type": "CustomScript",
"typeHandlerVersion": "2.1",
"settings": "******"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm/extensions/dwharn-custom-script",
"message": "Microsoft.Compute/virtualMachines/extensions/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e527e5ca-060d-cee6-1d83-b67dd38195e8",
"eventSubmissionTimestamp": "2026-07-28T04:11:14.8174458Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm/dwharn-custom-script",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Created"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType (elastic rule field) | in | microsoft.compute/virtualmachines/extensions/write | 2 rules | elastic |
EventType (elastic rule field) | in | microsoft.compute/virtualmachinescalesets/extensions/write | 2 rules | elastic |
azure.activitylogs.identity.authorization.evidence.principal_type (elastic rule field) | eq | user | 1 rule | elastic |
azure.resource.name (elastic rule field) | is_not_null | | 1 rule | elastic |
azure_ad::operation_name_value (kusto rule field) | eq | microsoft.compute/virtualmachines/runcommand/action | 1 rule | kusto |
source.as.number (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
azure.resource.name and alerts the first time a given (host, extension name) pair is observed in the window, surfacing novel extension deployments while suppressing names a host routinely uses.T1037, T1651↳ also matches Microsoft.Compute/virtualMachineScaleSets/extensions/write T1098, T1578, T1578.002, T1651T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/delete, Microsoft.Compute/virtualMachineScaleSets/extensions/delete, Microsoft.Compute/virtualMachineScaleSets/extensions/write Kusto #
T1021, T1021.008, T1651↳ also matches Microsoft.Compute/virtualMachines/runCommand/action Panther #
T1651↳ also matches Microsoft.Compute/galleries/applications/versions/write, Microsoft.Compute/virtualMachines/runCommand/action, Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action
References #
Microsoft.Compute/virtualMachines/generalize/action
#Description
Sets the virtual machine state to Generalized and prepares the virtual machine for capture
References #
Microsoft.Compute/virtualMachines/installPatches/action
#Description
Installs available OS update patches on the virtual machine based on parameters provided by user. Assessment results containing list of available patches will also get refreshed as part of this.
References #
Microsoft.Compute/virtualMachines/osUpgradeInternal/action
#Description
Perform OS Upgrade on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode.
References #
Microsoft.Compute/virtualMachines/performMaintenance/action
#Description
Performs Maintenance Operation on the VM.
References #
Microsoft.Compute/virtualMachines/powerOff/action
#Description
Powers off the virtual machine. Note that the virtual machine will continue to be billed.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"action": "Microsoft.Compute/virtualMachines/powerOff/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"action": "Microsoft.Compute/virtualMachines/powerOff/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "fd29bd3d-2a1a-41b9-85e6-d0eb81a7d776",
"EventDataId": "6df95355-6b97-2aa6-398c-4c860669ad00",
"EventSubmissionTimestamp": "2026-07-28T04:11:39.2147507Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/POWEROFF/ACTION",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"message": "Microsoft.Compute/virtualMachines/powerOff/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6df95355-6b97-2aa6-398c-4c860669ad00",
"eventSubmissionTimestamp": "2026-07-28T04:11:39.2147507Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"message": "Microsoft.Compute/virtualMachines/powerOff/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6df95355-6b97-2aa6-398c-4c860669ad00",
"eventSubmissionTimestamp": "2026-07-28T04:11:39.2147507Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/virtualMachines/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the Virtual Machine.
References #
Microsoft.Compute/virtualMachines/reapply/action
#Description
Reapplies a virtual machine's current model
References #
Microsoft.Compute/virtualMachines/redeploy/action
#Description
Redeploys virtual machine
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/redeploy/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/redeploy/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "5dc589b9-807b-400a-b947-5fe3bde9c350",
"EventDataId": "3e537189-3402-dacb-f9e7-60a666d61a64",
"EventSubmissionTimestamp": "2026-06-29T18:06:01.4781071Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/REDEPLOY/ACTION",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Compute/virtualMachines/redeploy/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3e537189-3402-dacb-f9e7-60a666d61a64",
"eventSubmissionTimestamp": "2026-06-29T18:06:01.4781071Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Compute/virtualMachines/redeploy/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3e537189-3402-dacb-f9e7-60a666d61a64",
"eventSubmissionTimestamp": "2026-06-29T18:06:01.4781071Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:06:01.4781071Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/virtualmachines/zcvm"
}
References #
Microsoft.Compute/virtualMachines/reimage/action
#Description
Reimages virtual machine which is using differencing disk.
References #
Microsoft.Compute/virtualMachines/restart/action
#Description
Restarts the virtual machine
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"action": "Microsoft.Compute/virtualMachines/restart/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"action": "Microsoft.Compute/virtualMachines/restart/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "4b7dc080-afa6-482a-aa4e-a5ce11b59e2c",
"EventDataId": "f9d30760-fc4c-f524-59d3-5f36195f8f72",
"EventSubmissionTimestamp": "2026-07-28T04:13:19.849199Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/RESTART/ACTION",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"message": "Microsoft.Compute/virtualMachines/restart/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "f9d30760-fc4c-f524-59d3-5f36195f8f72",
"eventSubmissionTimestamp": "2026-07-28T04:13:19.849199Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"message": "Microsoft.Compute/virtualMachines/restart/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "f9d30760-fc4c-f524-59d3-5f36195f8f72",
"eventSubmissionTimestamp": "2026-07-28T04:13:19.8491990Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/virtualMachines/retrieveBootDiagnosticsData/action
#Description
Retrieves boot diagnostic logs blob URIs
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1552
References #
Microsoft.Compute/virtualMachines/rollbackOSDisk/action
#Description
Rollback OSDisk on Virtual Machine after failed OS Upgrade invoked by Virtual Machine Scale Set with Flexible Orchestration Mode.
References #
Microsoft.Compute/virtualMachines/runCommand/action
#Description
Executes a predefined script on the virtual machine
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"action": "Microsoft.Compute/virtualMachines/runCommand/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"action": "Microsoft.Compute/virtualMachines/runCommand/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "fbf9e650-38a1-4cc1-9be1-d46eee1e7943",
"EventDataId": "a129a816-7505-0425-f064-472eddd81b75",
"EventSubmissionTimestamp": "2026-07-28T04:10:33.4448075Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"message": "Microsoft.Compute/virtualMachines/runCommand/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "a129a816-7505-0425-f064-472eddd81b75",
"eventSubmissionTimestamp": "2026-07-28T04:10:33.4448075Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh38d665vm",
"message": "Microsoft.Compute/virtualMachines/runCommand/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "a129a816-7505-0425-f064-472eddd81b75",
"eventSubmissionTimestamp": "2026-07-28T04:10:33.4448075Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh38d665vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure_ad::operation_name_value (kusto rule field) | eq | microsoft.compute/virtualmachines/runcommand/action | 4 rules | kusto |
Authorization (kusto rule field) | contains | virtualmachines | 3 rules | kusto |
list_ActivityStatusValue (kusto rule field) | contains | succeeded | 3 rules | kusto |
list_ActivityStatusValue (kusto rule field) | contains | success | 3 rules | kusto |
ActionUncommonlyPerformedByUser (kusto rule field) | eq | True | 2 rules | kusto |
StartTime (kusto rule field) | ge | UEBAWindowStart | 2 rules | kusto |
StartTime (kusto rule field) | le | UEBAWindowEnd | 2 rules | kusto |
UEBASourceIPLocation (kusto rule field) | is_not_null | | 2 rules | kusto |
aws::eventSource (kusto rule field) | eq | Azure AD | 2 rules | kusto |
user (kusto rule field) | is_not_null | | 2 rules | kusto |
ParentCommandLine (elastic rule field) | eq | powershell -executionpolicy unrestricted -file script?.ps1 | 1 rule | elastic |
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field) | is_not_null | | 1 rule | elastic |
azure.resource.name (elastic rule field) | is_not_null | | 1 rule | elastic |
event.module (elastic rule field) | eq | azure | 1 rule | elastic |
parent_process_name (elastic rule field) | eq | powershell.exe | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1059, T1059.001, T1651T1651↳ also matches Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action Kusto #
T1212, T1570T1212, T1570T1059, T1059.001, T1570Panther #
T1651↳ also matches Microsoft.Compute/galleries/applications/versions/write, Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action
References #
Microsoft.Compute/virtualMachines/runCommands/delete
#Description
Deletes the virtual machine run command
References #
Microsoft.Compute/virtualMachines/runCommands/write
#Description
Creates a new virtual machine run command or updates an existing one
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1651↳ also matches Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/write
References #
Microsoft.Compute/virtualMachines/setVMHealth/action
#Description
Sets health status on Virtual Machine belonging to Virtual Machine Scale Set with Flexible Orchestration Mode.
References #
Microsoft.Compute/virtualMachines/simulateEviction/action
#Description
Simulates the eviction of spot Virtual Machine
References #
Microsoft.Compute/virtualMachines/start/action
#Description
Starts the virtual machine
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"action": "Microsoft.Compute/virtualMachines/start/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"action": "Microsoft.Compute/virtualMachines/start/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1785209876",
"nbf": "1785209876",
"exp": "1785215473",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "C7K3Vvx9ykO4R4sH5a0vAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
"xms_idrel": "26 1",
"xms_sub_fct": "3 16",
"xms_tcdt": "1768616282"
},
"CorrelationId": "b66f156b-f58c-4f6d-9228-9bdc2e287840",
"EventDataId": "c9664ee1-485c-9e29-6be8-f13a77c7f902",
"EventSubmissionTimestamp": "2026-07-28T04:11:30.2954394Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/START/ACTION",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"message": "Microsoft.Compute/virtualMachines/start/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "c9664ee1-485c-9e29-6be8-f13a77c7f902",
"eventSubmissionTimestamp": "2026-07-28T04:11:30.2954394Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh7075e5vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/dwh7075e5vm",
"message": "Microsoft.Compute/virtualMachines/start/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "c9664ee1-485c-9e29-6be8-f13a77c7f902",
"eventSubmissionTimestamp": "2026-07-28T04:11:30.2954394Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh7075e5vm",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Compute/virtualMachines/upgradeVMAgent/action
#Description
Upgrade version of VM Agent on Virtual Machine
References #
Microsoft.Compute/virtualMachines/write
#Description
Creates a new virtual machine or updates an existing virtual machine
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Accept",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"action": "Microsoft.Compute/virtualMachines/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
"EventDataId": "48040b10-7e19-6001-932a-01ad7012e6d2",
"EventSubmissionTimestamp": "2026-06-29T18:02:44.4196985Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"responseBody": {
"name": "zcvm",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"type": "Microsoft.Compute/virtualMachines",
"location": "westus2",
"tags": {},
"properties": {
"hardwareProfile": {
"vmSize": "Standard_D2s_v3"
},
"provisioningState": "Creating",
"vmId": "67e9390f-4bb1-40ad-8753-f2b24bb00b00",
"storageProfile": {
"imageReference": {
"publisher": "Canonical",
"offer": "0001-com-ubuntu-server-jammy",
"sku": "22_04-lts-gen2",
"version": "latest",
"exactVersion": "22.04.202606110"
},
"osDisk": {
"osType": "Linux",
"createOption": "FromImage",
"caching": "ReadWrite",
"managedDisk": {
"storageAccountType": "Premium_LRS"
},
"deleteOption": "Detach",
"diskSizeGB": 30
},
"dataDisks": [],
"diskControllerType": "SCSI"
},
"osProfile": {
"computerName": "zcvm",
"linuxConfiguration": {
"disablePasswordAuthentication": true,
"ssh": {
"publicKeys": [
{
"path": "/home/zcadmin/.ssh/authorized_keys",
"keyData": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDeBZQWg6fCUl6IoZTp9kJVQLvhQRcJmmXpcZUXXyxfcH7WkuVs65rODvYVIrgr7i41XF7BBobWLdy+y5ib+c2t/E7sEXPe+CvaCLevc+rBIuD8UCZhWtp+Lp0QdL2UHDFE0mLRb1j+LTtkTkSVQfRT73JnVaDOLYuUiXx7UQ6iO97+PwE0BvVZceE9HTyXG5gfdwOvo+13ZbOssHFxSVczJ+XockGoljSrCwHMSVKcZhS/jKzgwJKeT+/Y3Rav9uUR0vBlyZFlbrANkirxPJDQ52NSraQFD0pRX4CYR5JQ59UsWmuMRV7b5gjN8fFw/AtVOs79s8TCRrL5fu2+J4LB"
}
]
},
"provisionVMAgent": true,
"patchSettings": {
"patchMode": "ImageDefault",
"assessmentMode": "ImageDefault"
}
},
"secrets": [],
"allowExtensionOperations": true,
"requireGuestProvisionSignal": true,
"adminUsername": "zcadmin"
},
"securityProfile": {
"uefiSettings": {
"secureBootEnabled": true,
"vTpmEnabled": true
},
"securityType": "TrustedLaunch"
},
"networkProfile": {
"networkInterfaces": [
{
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic"
}
]
},
"timeCreated": "2026-06-29T18:02:43.0495493+00:00"
},
"etag": "\"1\""
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Compute/virtualMachines/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "48040b10-7e19-6001-932a-01ad7012e6d2",
"eventSubmissionTimestamp": "2026-06-29T18:02:44.4196985Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"message": "Microsoft.Compute/virtualMachines/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "48040b10-7e19-6001-932a-01ad7012e6d2",
"eventSubmissionTimestamp": "2026-06-29T18:02:44.4196985Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcvm",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.COMPUTE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"statusCode": "Created",
"serviceRequestId": "",
"responseBody": {
"name": "zcvm",
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Compute/virtualMachines/zcvm",
"type": "Microsoft.Compute/virtualMachines",
"location": "westus2",
"tags": {},
"properties": {
"hardwareProfile": {
"vmSize": "Standard_D2s_v3"
},
"provisioningState": "Creating",
"vmId": "67e9390f-4bb1-40ad-8753-f2b24bb00b00",
"storageProfile": {
"imageReference": {
"publisher": "Canonical",
"offer": "0001-com-ubuntu-server-jammy",
"sku": "22_04-lts-gen2",
"version": "latest",
"exactVersion": "22.04.202606110"
},
"osDisk": {
"osType": "Linux",
"createOption": "FromImage",
"caching": "ReadWrite",
"managedDisk": {
"storageAccountType": "Premium_LRS"
},
"deleteOption": "Detach",
"diskSizeGB": 30
},
"dataDisks": [],
"diskControllerType": "SCSI"
},
"osProfile": {
"computerName": "zcvm",
"linuxConfiguration": {
"disablePasswordAuthentication": true,
"ssh": {
"publicKeys": [
{
"path": "/home/zcadmin/.ssh/authorized_keys",
"keyData": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDeBZQWg6fCUl6IoZTp9kJVQLvhQRcJmmXpcZUXXyxfcH7WkuVs65rODvYVIrgr7i41XF7BBobWLdy+y5ib+c2t/E7sEXPe+CvaCLevc+rBIuD8UCZhWtp+Lp0QdL2UHDFE0mLRb1j+LTtkTkSVQfRT73JnVaDOLYuUiXx7UQ6iO97+PwE0BvVZceE9HTyXG5gfdwOvo+13ZbOssHFxSVczJ+XockGoljSrCwHMSVKcZhS/jKzgwJKeT+/Y3Rav9uUR0vBlyZFlbrANkirxPJDQ52NSraQFD0pRX4CYR5JQ59UsWmuMRV7b5gjN8fFw/AtVOs79s8TCRrL5fu2+J4LB"
}
]
},
"provisionVMAgent": true,
"patchSettings": {
"patchMode": "ImageDefault",
"assessmentMode": "ImageDefault"
}
},
"secrets": [],
"allowExtensionOperations": true,
"requireGuestProvisionSignal": true,
"adminUsername": "zcadmin"
},
"securityProfile": {
"uefiSettings": {
"secureBootEnabled": true,
"vTpmEnabled": true
},
"securityType": "TrustedLaunch"
},
"networkProfile": {
"networkInterfaces": [
{
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic"
}
]
},
"timeCreated": "2026-06-29T18:02:43.0495493+00:00"
},
"etag": "\"1\""
},
"activitySubstatusValue": "Created"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.COMPUTE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:02:44.4196985Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.compute/virtualmachines/zcvm"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure_ad::operation_name_value (kusto rule field) | in | microsoft.compute/virtualmachines/write | 4 rules | kusto |
azure_ad::operation_name_value (kusto rule field) | in | microsoft.resources/deployments/write | 4 rules | kusto |
ActivityStatusValue (kusto rule field) | starts_with | Accept | 2 rules | kusto |
Properties (kusto rule field) | contains | vmsize | 2 rules | kusto |
vmSize (kusto rule field) | cross_field_compare | token | 2 rules | kusto |
anomalies (kusto rule field) | gt | 0 | 1 rule | kusto |
baseline (kusto rule field) | gt | 0 | 1 rule | kusto |
properties.statusCode (sigma rule field) | eq | created | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098Elastic #
T1037, T1651Kusto #
T1496T1578T1578
References #
Microsoft.Compute/virtualMachineScaleSets/approveRollingUpgrade/action
#Description
Approves deferred rolling upgrades for the instances of a Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/deallocate/action
#Description
Powers off and releases the compute resources for the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/delete
#Description
Deletes the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/delete/action
#Description
Deletes the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/disks/beginGetAccess/action
#Description
Get the SAS URI of VirtualMachineScaleSets Disk
References #
Microsoft.Compute/virtualMachineScaleSets/eventGridFilters/delete
#Description
Deletes the Virtual Machine Scale Set Event Grid Filter
References #
Microsoft.Compute/virtualMachineScaleSets/eventGridFilters/write
#Description
Creates a new Virtual Machine Scale Set Event Grid Filter or updates an existing one
References #
Microsoft.Compute/virtualMachineScaleSets/extensions/delete
#Description
Deletes the Virtual Machine Scale Set Extension
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType (elastic rule field) | in | microsoft.compute/virtualmachines/extensions/write | 1 rule | elastic |
EventType (elastic rule field) | in | microsoft.compute/virtualmachinescalesets/extensions/write | 1 rule | elastic |
azure.resource.name (elastic rule field) | is_not_null | | 1 rule | elastic |
source.as.number (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/delete, Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachineScaleSets/extensions/write
References #
Microsoft.Compute/virtualMachineScaleSets/extensions/roles/write
#Description
Updates the properties of an existing Role in a Virtual Machine Scale Set with the Virtual Machine Runtime Service Extension
References #
Microsoft.Compute/virtualMachineScaleSets/extensions/write
#Description
Creates a new Virtual Machine Scale Set Extension or updates an existing one
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType (elastic rule field) | in | microsoft.compute/virtualmachines/extensions/write | 2 rules | elastic |
EventType (elastic rule field) | in | microsoft.compute/virtualmachinescalesets/extensions/write | 2 rules | elastic |
azure.resource.name (elastic rule field) | is_not_null | | 1 rule | elastic |
source.as.number (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/delete, Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachineScaleSets/extensions/delete azure.resource.name and alerts the first time a given (host, extension name) pair is observed in the window, surfacing novel extension deployments while suppressing names a host routinely uses.T1037, T1651↳ also matches Microsoft.Compute/virtualMachines/extensions/write
References #
Microsoft.Compute/virtualMachineScaleSets/forceRecoveryServiceFabricPlatformUpdateDomainWalk/action
#Description
Manually walk the platform update domains of a service fabric Virtual Machine Scale Set to finish a pending update that is stuck
References #
Microsoft.Compute/virtualMachineScaleSets/manualUpgrade/action
#Description
Manually updates instances to latest model of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/osRollingUpgrade/action
#Description
Starts a rolling upgrade to move all Virtual Machine Scale Set instances to the latest available Platform Image OS version.
References #
Microsoft.Compute/virtualMachineScaleSets/performMaintenance/action
#Description
Performs planned maintenance on the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/powerOff/action
#Description
Powers off the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the Virtual Machine Scale set.
References #
Microsoft.Compute/virtualMachineScaleSets/redeploy/action
#Description
Redeploy the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/reimage/action
#Description
Reimages the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/reimageAll/action
#Description
Reimages all disks (OS Disk and Data Disks) for the instances of a Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/restart/action
#Description
Restarts the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/rollingUpgrades/action
#Description
Cancels the rolling upgrade of a Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/scale/action
#Description
Verify if an existing Virtual Machine Scale Set can Scale In/Scale Out to specified instance count
References #
Microsoft.Compute/virtualMachineScaleSets/setOrchestrationServiceState/action
#Description
Sets the state of an orchestration service based on the action provided in operation input.
References #
Microsoft.Compute/virtualMachineScaleSets/setVMHealth/action
#Description
Sets health status on Virtual Machines belonging to Virtual Machine Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/start/action
#Description
Starts the instances of the Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/approveRollingUpgrade/action
#Description
Approves deferred rolling upgrade for Virtual Machine instance in a Virtual Machine Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/attachDetachDataDisks/action
#Description
Attaches Detaches existing data disks to a Virtual Machine instance in a VM Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/deallocate/action
#Description
Powers off and releases the compute resources for a Virtual Machine in a VM Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/delete
#Description
Delete a specific Virtual Machine in a VM Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommand/action
#Description
Executes a diagnostic script on a Virtual Machine instance in a Virtual Machine Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommands/delete
#Description
Deletes the diagnostic run command for Virtual Machine in Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/diagnosticRunCommands/write
#Description
Creates a new diagnostic run command for Virtual Machine in Virtual Machine Scale Set or updates an existing one
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/extensions/delete
#Description
Deletes the extension for Virtual Machine in Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/extensions/write
#Description
Creates a new extension for Virtual Machine in Virtual Machine Scale Set or updates an existing one
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/getEffectiveRouteTable/action
#Description
Get properties of effective route table on network interface of a virtual machine created using Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/getEffectiveSecurityGroups/action
#Description
Get properties of effective security groups on network interface of a virtual machine created using Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/performMaintenance/action
#Description
Performs planned maintenance on a Virtual Machine instance in a Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/powerOff/action
#Description
Powers Off a Virtual Machine instance in a VM Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/redeploy/action
#Description
Redeploys a Virtual Machine instance in a Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/reimage/action
#Description
Reimages a Virtual Machine instance in a Virtual Machine Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/reimageAll/action
#Description
Reimages all disks (OS Disk and Data Disks) for Virtual Machine instance in a Virtual Machine Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/restart/action
#Description
Restarts a Virtual Machine instance in a VM Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/retrieveBootDiagnosticsData/action
#Description
Retrieves boot diagnostic logs blob URIs of Virtual Machine instance in a Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommand/action
#Description
Executes a predefined script on a Virtual Machine instance in a Virtual Machine Scale Set.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field) | is_not_null | | 1 rule | elastic |
azure.resource.name (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1651↳ also matches Microsoft.Compute/virtualMachines/runCommand/action Panther #
T1651↳ also matches Microsoft.Compute/galleries/applications/versions/write, Microsoft.Compute/virtualMachines/extensions/write, Microsoft.Compute/virtualMachines/runCommand/action
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/delete
#Description
Deletes the run command for Virtual Machine in Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/runCommands/write
#Description
Creates a new run command for Virtual Machine in Virtual Machine Scale Set or updates an existing one
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.activitylogs.identity.authorization.evidence.principal_id (elastic rule field) | is_not_null | | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1651↳ also matches Microsoft.Compute/virtualMachines/runCommands/write
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/simulateEviction/action
#Description
Simulates the eviction of spot Virtual Machine in Virtual Machine Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/start/action
#Description
Starts a Virtual Machine instance in a VM Scale Set.
References #
Microsoft.Compute/virtualMachineScaleSets/virtualMachines/write
#Description
Updates the properties of a Virtual Machine in a VM Scale Set
References #
Microsoft.Compute/virtualMachineScaleSets/write
#Description
Creates a new Virtual Machine Scale Set or updates an existing one