Azure Kubernetes Service (AKS) Azure-Microsoft.ContainerService

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.ContainerService rules that match the resource provider but no specific operation.NN
Microsoft.ContainerService/aiManagers/deleteDelete AI ManagerNN
Microsoft.ContainerService/aiManagers/listCredential/actionList AI Manager CredentialNN
Microsoft.ContainerService/aiManagers/namespaces/deleteDelete AI Manager NamespaceNN
Microsoft.ContainerService/aiManagers/namespaces/listCredential/actionList AI Manager Namespace CredentialNN
Microsoft.ContainerService/aiManagers/namespaces/writeCreate or Update AI Manager NamespaceNN
Microsoft.ContainerService/aiManagers/writeCreate or Update AI ManagerNN
Microsoft.ContainerService/containerServices/deleteDeletes a container serviceNN
Microsoft.ContainerService/containerServices/writeCreates a new container service or updates an existing oneNN
Microsoft.ContainerService/deploymentSafeguards/deleteDelete Deployment SafeguardsNN
Microsoft.ContainerService/deploymentSafeguards/writeCreate or Update Deployment SafeguardsNN
Microsoft.ContainerService/fleetMemberships/deleteDelete a fleet membership extensionNN
Microsoft.ContainerService/fleetMemberships/forward/actionForwards a call to the underlying clusterNN
Microsoft.ContainerService/fleetMemberships/writeCreate or Update a fleet membership extensionNN
Microsoft.ContainerService/fleets/autoUpgradeProfiles/deleteDelete a fleet auto upgrade profileNN
Microsoft.ContainerService/fleets/autoUpgradeProfiles/generateUpdateRun/actionGenerate a fleet update run based off the auto upgrade profileNN
Microsoft.ContainerService/fleets/autoUpgradeProfiles/writeCreate or Update a fleet auto upgrade profileNN
Microsoft.ContainerService/fleets/clusterMeshProfiles/apply/actionApplies a fleet cluster mesh profileNN
Microsoft.ContainerService/fleets/clusterMeshProfiles/deleteDelete a fleet cluster mesh profileNN
Microsoft.ContainerService/fleets/clusterMeshProfiles/writeCreate or Update a fleet cluster mesh profileNN
Microsoft.ContainerService/fleets/deleteDelete a fleetNN
Microsoft.ContainerService/fleets/gates/deleteDelete a fleet gateNN
Microsoft.ContainerService/fleets/gates/writeCreate or Update a fleet gateNN
Microsoft.ContainerService/fleets/listCredentials/actionList fleet credentialsNN
Microsoft.ContainerService/fleets/managedNamespaces/deleteDelete a fleet managed namespaceNN
Microsoft.ContainerService/fleets/managedNamespaces/writeCreate or Update a fleet managed namespaceNN
Microsoft.ContainerService/fleets/members/deleteDelete a fleet memberNN
Microsoft.ContainerService/fleets/members/writeCreate or Update a fleet memberNN
Microsoft.ContainerService/fleets/updateRuns/deleteDelete a fleet update runNN
Microsoft.ContainerService/fleets/updateRuns/start/actionStarts a fleet update runNN
Microsoft.ContainerService/fleets/updateRuns/stop/actionStops a fleet update runNN
Microsoft.ContainerService/fleets/updateRuns/writeCreate or Update a fleet update runNN
Microsoft.ContainerService/fleets/updateStrategies/deleteDelete a fleet update strategyNN
Microsoft.ContainerService/fleets/updateStrategies/writeCreate or Update a fleet update strategyNN
Microsoft.ContainerService/fleets/writeCreate or Update a fleetNN
Microsoft.ContainerService/managedClusters/abort/actionLatest ongoing operation on managed cluster gets abortedNN
Microsoft.ContainerService/managedClusters/accessProfiles/listCredential/actionGet a managed cluster access profile by role name using list credentialNN
Microsoft.ContainerService/managedClusters/agentPools/abort/actionLatest ongoing operation on agent pool gets abortedNN
Microsoft.ContainerService/managedClusters/agentPools/deleteDeletes an agent poolNN
Microsoft.ContainerService/managedClusters/agentPools/deleteMachines/actionDeletes machinesNN
Microsoft.ContainerService/managedClusters/agentPools/machines/writeCreates a new machine or updates an existing oneNN
Microsoft.ContainerService/managedClusters/agentPools/upgradeNodeImageVersion/actionUpgrade the node image version of agent poolNN
Microsoft.ContainerService/managedClusters/agentPools/upgradeNodeImageVersion/writeUpgrade the node image version of agent poolNN
Microsoft.ContainerService/managedClusters/agentPools/writeCreates a new agent pool or updates an existing oneNN
Microsoft.ContainerService/managedClusters/deleteDeletes a managed clusterNN
Microsoft.ContainerService/managedClusters/eventGridFilters/deleteDelete an eventgrid filterNN
Microsoft.ContainerService/managedClusters/eventGridFilters/writeCreate or Update eventgrid filterNN
Microsoft.ContainerService/managedClusters/extensionaddons/deleteDeletes an extension addonNN
Microsoft.ContainerService/managedClusters/extensionaddons/writeCreates a new extension addon or updates an existing oneNN
Microsoft.ContainerService/managedClusters/jwtAuthenticators/deleteDelete a JWT authenticator from a managed clusterNN
Microsoft.ContainerService/managedClusters/jwtAuthenticators/writeCreate or update a JWT authenticator of a managed clusterNN
Microsoft.ContainerService/managedClusters/listClusterAdminCredential/actionList the clusterAdmin credential of a managed clusterNN
Microsoft.ContainerService/managedClusters/listClusterMonitoringUserCredential/actionList the clusterMonitoringUser credential of a managed clusterNN
Microsoft.ContainerService/managedClusters/listClusterUserCredential/actionList the clusterUser credential of a managed clusterNN
Microsoft.ContainerService/managedClusters/loadBalancers/deleteDeletes a load balancer configurationNN
Microsoft.ContainerService/managedClusters/loadBalancers/writeCreates a new LoadBalancerConfiguration or updates an existing oneNN
Microsoft.ContainerService/managedClusters/maintenanceConfigurations/deleteDeletes a maintenance configurationNN
Microsoft.ContainerService/managedClusters/maintenanceConfigurations/writeCreates a new MaintenanceConfiguration or updates an existing oneNN
Microsoft.ContainerService/managedClusters/managedNamespaces/deleteDelete a managed namespace of a managed clusterNN
Microsoft.ContainerService/managedClusters/managedNamespaces/listCredential/actionList cluster credentials of a managed namespaceNN
Microsoft.ContainerService/managedClusters/managedNamespaces/writeCreate a managed namespace of a managed clusterNN
Microsoft.ContainerService/managedClusters/meshMemberships/deleteDelete a mesh membership from a managed clusterNN
Microsoft.ContainerService/managedClusters/meshMemberships/writeCreate a mesh membership of a managed clusterNN
Microsoft.ContainerService/managedClusters/networkSecurityPerimeterAssociationProxies/deleteDelete ManagedCluster NetworkSecurityPerimeter AssociationNN
Microsoft.ContainerService/managedClusters/networkSecurityPerimeterAssociationProxies/writeCreate or update ManagedCluster NetworkSecurityPerimeter AssociationNN
Microsoft.ContainerService/managedClusters/privateEndpointConnections/deleteDelete private endpoint connectionNN
Microsoft.ContainerService/managedClusters/privateEndpointConnections/writeApprove or Reject a private endpoint connectionNN
Microsoft.ContainerService/managedClusters/privateEndpointConnectionsApproval/actionDetermines if user is allowed to approve a private endpoint connectionNN
Microsoft.ContainerService/managedClusters/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for a managed cluster resourceNN
Microsoft.ContainerService/managedClusters/resetAADProfile/actionReset the AAD profile of a managed clusterNN
Microsoft.ContainerService/managedClusters/resetServicePrincipalProfile/actionReset the service principal profile of a managed clusterNN
Microsoft.ContainerService/managedClusters/resolvePrivateLinkServiceId/actionResolve the private link service id of a managed clusterNN
Microsoft.ContainerService/managedClusters/rotateClusterCertificates/actionRotate certificates of a managed clusterNN
Microsoft.ContainerService/managedClusters/runCommand/actionRun user issued command against managed kubernetes server.NY
Microsoft.ContainerService/managedClusters/start/actionStarts a managed clusterNN
Microsoft.ContainerService/managedClusters/stop/actionStops a managed clusterNN
Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/deleteDelete trusted access role bindings for managed clusterNN
Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/writeCreate or update trusted access role bindings for managed clusterNN
Microsoft.ContainerService/managedClusters/unpinManagedCluster/actionUnpin a managed clusterNN
Microsoft.ContainerService/managedClusters/writeCreates a new managed cluster or updates an existing oneYN
Microsoft.ContainerService/managedclustersnapshots/deleteDeletes a managed cluster snapshotNN
Microsoft.ContainerService/managedclustersnapshots/writeCreates a new managed cluster snapshotNN
Microsoft.ContainerService/nodeCustomizations/deleteDelete Node CustomizationNN
Microsoft.ContainerService/nodeCustomizations/versions/deleteDelete Node Customization VersionNN
Microsoft.ContainerService/nodeCustomizations/versions/writeCreate or Update Node Customization VersionNN
Microsoft.ContainerService/nodeCustomizations/writeCreate or Update Node CustomizationNN
Microsoft.ContainerService/openShiftClusters/deleteDelete an Open Shift ClusterNN
Microsoft.ContainerService/openShiftClusters/writeCreates a new Open Shift Cluster or updates an existing oneNN
Microsoft.ContainerService/openShiftManagedClusters/deleteDelete an Open Shift Managed ClusterNN
Microsoft.ContainerService/openShiftManagedClusters/writeCreates a new Open Shift Managed Cluster or updates an existing oneNN
Microsoft.ContainerService/preparedImageSpecifications/deleteDelete Prepared Image SpecificationNN
Microsoft.ContainerService/preparedImageSpecifications/deploy/actionDeploy Prepared Image SpecificationNN
Microsoft.ContainerService/preparedImageSpecifications/versions/deleteDelete Prepared Image Specification VersionNN
Microsoft.ContainerService/preparedImageSpecifications/versions/deploy/actionDeploy Prepared Image Specification VersionNN
Microsoft.ContainerService/preparedImageSpecifications/versions/writeCreate or Update Prepared Image Specification VersionNN
Microsoft.ContainerService/preparedImageSpecifications/writeCreate or Update Prepared Image SpecificationNN
Microsoft.ContainerService/register/actionRegisters Subscription with Microsoft.ContainerService resource providerNN
Microsoft.ContainerService/snapshots/deleteDeletes a snapshotNN
Microsoft.ContainerService/snapshots/writeCreates a new snapshotNN
Microsoft.ContainerService/unregister/actionUnregisters Subscription with Microsoft.ContainerService resource providerNN
Microsoft.ContainerService/fleets/notify/actionSend a notification event to a fleetNN
Microsoft.ContainerService/managedClusters/agentPools/listBootstrapData/actionList Agent Pool Bootstrap DataNN

any: Azure Kubernetes Service (AKS) (catch-all)

#
Namespace
Microsoft.ContainerService

Description

Catch-all for Azure-Microsoft.ContainerService rules that match the resource provider but no specific operation.

Microsoft.ContainerService/aiManagers/delete

#
Namespace
Microsoft.ContainerService

Description

Delete AI Manager

Microsoft.ContainerService/aiManagers/listCredential/action

#
Namespace
Microsoft.ContainerService

Description

List AI Manager Credential

Microsoft.ContainerService/aiManagers/namespaces/delete

#
Namespace
Microsoft.ContainerService

Description

Delete AI Manager Namespace

Microsoft.ContainerService/aiManagers/namespaces/listCredential/action

#
Namespace
Microsoft.ContainerService

Description

List AI Manager Namespace Credential

Microsoft.ContainerService/aiManagers/namespaces/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update AI Manager Namespace

Microsoft.ContainerService/aiManagers/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update AI Manager

Microsoft.ContainerService/containerServices/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes a container service

Microsoft.ContainerService/containerServices/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new container service or updates an existing one

Microsoft.ContainerService/deploymentSafeguards/delete

#
Namespace
Microsoft.ContainerService

Description

Delete Deployment Safeguards

Microsoft.ContainerService/deploymentSafeguards/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update Deployment Safeguards

Microsoft.ContainerService/fleetMemberships/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet membership extension

Microsoft.ContainerService/fleetMemberships/forward/action

#
Namespace
Microsoft.ContainerService

Description

Forwards a call to the underlying cluster

Microsoft.ContainerService/fleetMemberships/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet membership extension

Microsoft.ContainerService/fleets/autoUpgradeProfiles/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet auto upgrade profile

Microsoft.ContainerService/fleets/autoUpgradeProfiles/generateUpdateRun/action

#
Namespace
Microsoft.ContainerService

Description

Generate a fleet update run based off the auto upgrade profile

Microsoft.ContainerService/fleets/autoUpgradeProfiles/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet auto upgrade profile

Microsoft.ContainerService/fleets/clusterMeshProfiles/apply/action

#
Namespace
Microsoft.ContainerService

Description

Applies a fleet cluster mesh profile

Microsoft.ContainerService/fleets/clusterMeshProfiles/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet cluster mesh profile

Microsoft.ContainerService/fleets/clusterMeshProfiles/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet cluster mesh profile

Microsoft.ContainerService/fleets/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet

Microsoft.ContainerService/fleets/gates/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet gate

Microsoft.ContainerService/fleets/gates/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet gate

Microsoft.ContainerService/fleets/listCredentials/action

#
Namespace
Microsoft.ContainerService

Description

List fleet credentials

Microsoft.ContainerService/fleets/managedNamespaces/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet managed namespace

Microsoft.ContainerService/fleets/managedNamespaces/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet managed namespace

Microsoft.ContainerService/fleets/members/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet member

Microsoft.ContainerService/fleets/members/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet member

Microsoft.ContainerService/fleets/updateRuns/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet update run

Microsoft.ContainerService/fleets/updateRuns/start/action

#
Namespace
Microsoft.ContainerService

Description

Starts a fleet update run

Microsoft.ContainerService/fleets/updateRuns/stop/action

#
Namespace
Microsoft.ContainerService

Description

Stops a fleet update run

Microsoft.ContainerService/fleets/updateRuns/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet update run

Microsoft.ContainerService/fleets/updateStrategies/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a fleet update strategy

Microsoft.ContainerService/fleets/updateStrategies/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet update strategy

Microsoft.ContainerService/fleets/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update a fleet

Microsoft.ContainerService/managedClusters/abort/action

#
Namespace
Microsoft.ContainerService

Description

Latest ongoing operation on managed cluster gets aborted

Microsoft.ContainerService/managedClusters/accessProfiles/listCredential/action

#
Namespace
Microsoft.ContainerService

Description

Get a managed cluster access profile by role name using list credential

Microsoft.ContainerService/managedClusters/agentPools/abort/action

#
Namespace
Microsoft.ContainerService

Description

Latest ongoing operation on agent pool gets aborted

Microsoft.ContainerService/managedClusters/agentPools/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes an agent pool

Microsoft.ContainerService/managedClusters/agentPools/deleteMachines/action

#
Namespace
Microsoft.ContainerService

Description

Deletes machines

Microsoft.ContainerService/managedClusters/agentPools/machines/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new machine or updates an existing one

Microsoft.ContainerService/managedClusters/agentPools/upgradeNodeImageVersion/action

#
Namespace
Microsoft.ContainerService

Description

Upgrade the node image version of agent pool

Microsoft.ContainerService/managedClusters/agentPools/upgradeNodeImageVersion/write

#
Namespace
Microsoft.ContainerService

Description

Upgrade the node image version of agent pool

Microsoft.ContainerService/managedClusters/agentPools/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new agent pool or updates an existing one

Microsoft.ContainerService/managedClusters/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes a managed cluster

Microsoft.ContainerService/managedClusters/eventGridFilters/delete

#
Namespace
Microsoft.ContainerService

Description

Delete an eventgrid filter

Microsoft.ContainerService/managedClusters/eventGridFilters/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update eventgrid filter

Microsoft.ContainerService/managedClusters/extensionaddons/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes an extension addon

Microsoft.ContainerService/managedClusters/extensionaddons/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new extension addon or updates an existing one

Microsoft.ContainerService/managedClusters/jwtAuthenticators/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a JWT authenticator from a managed cluster

Microsoft.ContainerService/managedClusters/jwtAuthenticators/write

#
Namespace
Microsoft.ContainerService

Description

Create or update a JWT authenticator of a managed cluster

Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action

#
Namespace
Microsoft.ContainerService

Description

List the clusterAdmin credential of a managed cluster

Microsoft.ContainerService/managedClusters/listClusterMonitoringUserCredential/action

#
Namespace
Microsoft.ContainerService

Description

List the clusterMonitoringUser credential of a managed cluster

Microsoft.ContainerService/managedClusters/listClusterUserCredential/action

#
Namespace
Microsoft.ContainerService

Description

List the clusterUser credential of a managed cluster

Microsoft.ContainerService/managedClusters/loadBalancers/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes a load balancer configuration

Microsoft.ContainerService/managedClusters/loadBalancers/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new LoadBalancerConfiguration or updates an existing one

Microsoft.ContainerService/managedClusters/maintenanceConfigurations/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes a maintenance configuration

Microsoft.ContainerService/managedClusters/maintenanceConfigurations/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new MaintenanceConfiguration or updates an existing one

Microsoft.ContainerService/managedClusters/managedNamespaces/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a managed namespace of a managed cluster

Microsoft.ContainerService/managedClusters/managedNamespaces/listCredential/action

#
Namespace
Microsoft.ContainerService

Description

List cluster credentials of a managed namespace

Microsoft.ContainerService/managedClusters/managedNamespaces/write

#
Namespace
Microsoft.ContainerService

Description

Create a managed namespace of a managed cluster

Microsoft.ContainerService/managedClusters/meshMemberships/delete

#
Namespace
Microsoft.ContainerService

Description

Delete a mesh membership from a managed cluster

Microsoft.ContainerService/managedClusters/meshMemberships/write

#
Namespace
Microsoft.ContainerService

Description

Create a mesh membership of a managed cluster

Microsoft.ContainerService/managedClusters/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.ContainerService

Description

Delete ManagedCluster NetworkSecurityPerimeter Association

Microsoft.ContainerService/managedClusters/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.ContainerService

Description

Create or update ManagedCluster NetworkSecurityPerimeter Association

Microsoft.ContainerService/managedClusters/privateEndpointConnections/delete

#
Namespace
Microsoft.ContainerService

Description

Delete private endpoint connection

Microsoft.ContainerService/managedClusters/privateEndpointConnections/write

#
Namespace
Microsoft.ContainerService

Description

Approve or Reject a private endpoint connection

Microsoft.ContainerService/managedClusters/privateEndpointConnectionsApproval/action

#
Namespace
Microsoft.ContainerService

Description

Determines if user is allowed to approve a private endpoint connection

Microsoft.ContainerService/managedClusters/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.ContainerService

Description

Creates or updates the diagnostic setting for a managed cluster resource

Microsoft.ContainerService/managedClusters/resetAADProfile/action

#
Namespace
Microsoft.ContainerService

Description

Reset the AAD profile of a managed cluster

Microsoft.ContainerService/managedClusters/resetServicePrincipalProfile/action

#
Namespace
Microsoft.ContainerService

Description

Reset the service principal profile of a managed cluster

Microsoft.ContainerService/managedClusters/resolvePrivateLinkServiceId/action

#
Namespace
Microsoft.ContainerService

Description

Resolve the private link service id of a managed cluster

Microsoft.ContainerService/managedClusters/rotateClusterCertificates/action

#
Namespace
Microsoft.ContainerService

Description

Rotate certificates of a managed cluster

Microsoft.ContainerService/managedClusters/runCommand/action

#
Namespace
Microsoft.ContainerService

Description

Run user issued command against managed kubernetes server.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure VM Command Executed source informational: Detects when commands are executed on Azure virtual machines through multiple execution methods including RunCommand, VM extensions (CustomScriptExtension, DSC), gallery applications, AKS command invoke, VMSS run commands, and serial console access. Adversaries may abuse these capabilities to execute unauthorized commands, deploy malware, establish persistence, or move laterally within the environment.T1651

Microsoft.ContainerService/managedClusters/start/action

#
Namespace
Microsoft.ContainerService

Description

Starts a managed cluster

Microsoft.ContainerService/managedClusters/stop/action

#
Namespace
Microsoft.ContainerService

Description

Stops a managed cluster

Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/delete

#
Namespace
Microsoft.ContainerService

Description

Delete trusted access role bindings for managed cluster

Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/write

#
Namespace
Microsoft.ContainerService

Description

Create or update trusted access role bindings for managed cluster

Microsoft.ContainerService/managedClusters/unpinManagedCluster/action

#
Namespace
Microsoft.ContainerService

Description

Unpin a managed cluster

Microsoft.ContainerService/managedClusters/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new managed cluster or updates an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "Conflict",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
    "action": "Microsoft.ContainerService/managedClusters/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
    "action": "Microsoft.ContainerService/managedClusters/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "fec75ec9-d389-47e7-b44c-608de92bf88b",
  "EventDataId": "34d7029e-460b-0974-27c1-b1a47fc36192",
  "EventSubmissionTimestamp": "2026-07-03T02:19:02.3107988Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.CONTAINERSERVICE/MANAGEDCLUSTERS/WRITE",
  "Properties": {
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "MissingSubscriptionRegistration",
        "message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions.",
        "details": [
          {
            "code": "MissingSubscriptionRegistration",
            "target": "Microsoft.ContainerService",
            "message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions."
          }
        ]
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
    "message": "Microsoft.ContainerService/managedClusters/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "34d7029e-460b-0974-27c1-b1a47fc36192",
    "eventSubmissionTimestamp": "2026-07-03T02:19:02.3107988Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh36bcb1aks",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.CONTAINERSERVICE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "Conflict"
  },
  "Properties_d": {
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "MissingSubscriptionRegistration",
        "message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions.",
        "details": [
          {
            "code": "MissingSubscriptionRegistration",
            "target": "Microsoft.ContainerService",
            "message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions."
          }
        ]
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
    "message": "Microsoft.ContainerService/managedClusters/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "34d7029e-460b-0974-27c1-b1a47fc36192",
    "eventSubmissionTimestamp": "2026-07-03T02:19:02.3107988Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh36bcb1aks",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.CONTAINERSERVICE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "Conflict"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.CONTAINERSERVICE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.ContainerService/managedclustersnapshots/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes a managed cluster snapshot

Microsoft.ContainerService/managedclustersnapshots/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new managed cluster snapshot

Microsoft.ContainerService/nodeCustomizations/delete

#
Namespace
Microsoft.ContainerService

Description

Delete Node Customization

Microsoft.ContainerService/nodeCustomizations/versions/delete

#
Namespace
Microsoft.ContainerService

Description

Delete Node Customization Version

Microsoft.ContainerService/nodeCustomizations/versions/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update Node Customization Version

Microsoft.ContainerService/nodeCustomizations/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update Node Customization

Microsoft.ContainerService/openShiftClusters/delete

#
Namespace
Microsoft.ContainerService

Description

Delete an Open Shift Cluster

Microsoft.ContainerService/openShiftClusters/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new Open Shift Cluster or updates an existing one

Microsoft.ContainerService/openShiftManagedClusters/delete

#
Namespace
Microsoft.ContainerService

Description

Delete an Open Shift Managed Cluster

Microsoft.ContainerService/openShiftManagedClusters/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new Open Shift Managed Cluster or updates an existing one

Microsoft.ContainerService/preparedImageSpecifications/delete

#
Namespace
Microsoft.ContainerService

Description

Delete Prepared Image Specification

Microsoft.ContainerService/preparedImageSpecifications/deploy/action

#
Namespace
Microsoft.ContainerService

Description

Deploy Prepared Image Specification

Microsoft.ContainerService/preparedImageSpecifications/versions/delete

#
Namespace
Microsoft.ContainerService

Description

Delete Prepared Image Specification Version

Microsoft.ContainerService/preparedImageSpecifications/versions/deploy/action

#
Namespace
Microsoft.ContainerService

Description

Deploy Prepared Image Specification Version

Microsoft.ContainerService/preparedImageSpecifications/versions/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update Prepared Image Specification Version

Microsoft.ContainerService/preparedImageSpecifications/write

#
Namespace
Microsoft.ContainerService

Description

Create or Update Prepared Image Specification

Microsoft.ContainerService/register/action

#
Namespace
Microsoft.ContainerService

Description

Registers Subscription with Microsoft.ContainerService resource provider

Microsoft.ContainerService/snapshots/delete

#
Namespace
Microsoft.ContainerService

Description

Deletes a snapshot

Microsoft.ContainerService/snapshots/write

#
Namespace
Microsoft.ContainerService

Description

Creates a new snapshot

Microsoft.ContainerService/unregister/action

#
Namespace
Microsoft.ContainerService

Description

Unregisters Subscription with Microsoft.ContainerService resource provider

Microsoft.ContainerService/fleets/notify/action

#
Namespace
Microsoft.ContainerService

Description

Send a notification event to a fleet

Microsoft.ContainerService/managedClusters/agentPools/listBootstrapData/action

#
Namespace
Microsoft.ContainerService

Description

List Agent Pool Bootstrap Data

References #