Azure Kubernetes Service (AKS) Azure-Microsoft.ContainerService
any: Azure Kubernetes Service (AKS) (catch-all)
#Description
Catch-all for Azure-Microsoft.ContainerService rules that match the resource provider but no specific operation.
Microsoft.ContainerService/aiManagers/delete
#Description
Delete AI Manager
Microsoft.ContainerService/aiManagers/listCredential/action
#Description
List AI Manager Credential
Microsoft.ContainerService/aiManagers/namespaces/delete
#Description
Delete AI Manager Namespace
Microsoft.ContainerService/aiManagers/namespaces/listCredential/action
#Description
List AI Manager Namespace Credential
Microsoft.ContainerService/aiManagers/namespaces/write
#Description
Create or Update AI Manager Namespace
Microsoft.ContainerService/aiManagers/write
#Description
Create or Update AI Manager
Microsoft.ContainerService/containerServices/delete
#Description
Deletes a container service
Microsoft.ContainerService/containerServices/write
#Description
Creates a new container service or updates an existing one
Microsoft.ContainerService/deploymentSafeguards/delete
#Description
Delete Deployment Safeguards
Microsoft.ContainerService/deploymentSafeguards/write
#Description
Create or Update Deployment Safeguards
Microsoft.ContainerService/fleetMemberships/delete
#Description
Delete a fleet membership extension
Microsoft.ContainerService/fleetMemberships/forward/action
#Description
Forwards a call to the underlying cluster
Microsoft.ContainerService/fleetMemberships/write
#Description
Create or Update a fleet membership extension
Microsoft.ContainerService/fleets/autoUpgradeProfiles/delete
#Description
Delete a fleet auto upgrade profile
Microsoft.ContainerService/fleets/autoUpgradeProfiles/generateUpdateRun/action
#Description
Generate a fleet update run based off the auto upgrade profile
Microsoft.ContainerService/fleets/autoUpgradeProfiles/write
#Description
Create or Update a fleet auto upgrade profile
Microsoft.ContainerService/fleets/clusterMeshProfiles/apply/action
#Description
Applies a fleet cluster mesh profile
Microsoft.ContainerService/fleets/clusterMeshProfiles/delete
#Description
Delete a fleet cluster mesh profile
Microsoft.ContainerService/fleets/clusterMeshProfiles/write
#Description
Create or Update a fleet cluster mesh profile
Microsoft.ContainerService/fleets/delete
#Description
Delete a fleet
Microsoft.ContainerService/fleets/gates/delete
#Description
Delete a fleet gate
Microsoft.ContainerService/fleets/gates/write
#Description
Create or Update a fleet gate
Microsoft.ContainerService/fleets/listCredentials/action
#Description
List fleet credentials
Microsoft.ContainerService/fleets/managedNamespaces/delete
#Description
Delete a fleet managed namespace
Microsoft.ContainerService/fleets/managedNamespaces/write
#Description
Create or Update a fleet managed namespace
Microsoft.ContainerService/fleets/members/delete
#Description
Delete a fleet member
Microsoft.ContainerService/fleets/members/write
#Description
Create or Update a fleet member
Microsoft.ContainerService/fleets/updateRuns/delete
#Description
Delete a fleet update run
Microsoft.ContainerService/fleets/updateRuns/start/action
#Description
Starts a fleet update run
Microsoft.ContainerService/fleets/updateRuns/stop/action
#Description
Stops a fleet update run
Microsoft.ContainerService/fleets/updateRuns/write
#Description
Create or Update a fleet update run
Microsoft.ContainerService/fleets/updateStrategies/delete
#Description
Delete a fleet update strategy
Microsoft.ContainerService/fleets/updateStrategies/write
#Description
Create or Update a fleet update strategy
Microsoft.ContainerService/fleets/write
#Description
Create or Update a fleet
Microsoft.ContainerService/managedClusters/abort/action
#Description
Latest ongoing operation on managed cluster gets aborted
Microsoft.ContainerService/managedClusters/accessProfiles/listCredential/action
#Description
Get a managed cluster access profile by role name using list credential
Microsoft.ContainerService/managedClusters/agentPools/abort/action
#Description
Latest ongoing operation on agent pool gets aborted
Microsoft.ContainerService/managedClusters/agentPools/delete
#Description
Deletes an agent pool
Microsoft.ContainerService/managedClusters/agentPools/deleteMachines/action
#Description
Deletes machines
Microsoft.ContainerService/managedClusters/agentPools/machines/write
#Description
Creates a new machine or updates an existing one
Microsoft.ContainerService/managedClusters/agentPools/upgradeNodeImageVersion/action
#Description
Upgrade the node image version of agent pool
Microsoft.ContainerService/managedClusters/agentPools/upgradeNodeImageVersion/write
#Description
Upgrade the node image version of agent pool
Microsoft.ContainerService/managedClusters/agentPools/write
#Description
Creates a new agent pool or updates an existing one
Microsoft.ContainerService/managedClusters/delete
#Description
Deletes a managed cluster
Microsoft.ContainerService/managedClusters/eventGridFilters/delete
#Description
Delete an eventgrid filter
Microsoft.ContainerService/managedClusters/eventGridFilters/write
#Description
Create or Update eventgrid filter
Microsoft.ContainerService/managedClusters/extensionaddons/delete
#Description
Deletes an extension addon
Microsoft.ContainerService/managedClusters/extensionaddons/write
#Description
Creates a new extension addon or updates an existing one
Microsoft.ContainerService/managedClusters/jwtAuthenticators/delete
#Description
Delete a JWT authenticator from a managed cluster
Microsoft.ContainerService/managedClusters/jwtAuthenticators/write
#Description
Create or update a JWT authenticator of a managed cluster
Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action
#Description
List the clusterAdmin credential of a managed cluster
Microsoft.ContainerService/managedClusters/listClusterMonitoringUserCredential/action
#Description
List the clusterMonitoringUser credential of a managed cluster
Microsoft.ContainerService/managedClusters/listClusterUserCredential/action
#Description
List the clusterUser credential of a managed cluster
Microsoft.ContainerService/managedClusters/loadBalancers/delete
#Description
Deletes a load balancer configuration
Microsoft.ContainerService/managedClusters/loadBalancers/write
#Description
Creates a new LoadBalancerConfiguration or updates an existing one
Microsoft.ContainerService/managedClusters/maintenanceConfigurations/delete
#Description
Deletes a maintenance configuration
Microsoft.ContainerService/managedClusters/maintenanceConfigurations/write
#Description
Creates a new MaintenanceConfiguration or updates an existing one
Microsoft.ContainerService/managedClusters/managedNamespaces/delete
#Description
Delete a managed namespace of a managed cluster
Microsoft.ContainerService/managedClusters/managedNamespaces/listCredential/action
#Description
List cluster credentials of a managed namespace
Microsoft.ContainerService/managedClusters/managedNamespaces/write
#Description
Create a managed namespace of a managed cluster
Microsoft.ContainerService/managedClusters/meshMemberships/delete
#Description
Delete a mesh membership from a managed cluster
Microsoft.ContainerService/managedClusters/meshMemberships/write
#Description
Create a mesh membership of a managed cluster
Microsoft.ContainerService/managedClusters/networkSecurityPerimeterAssociationProxies/delete
#Description
Delete ManagedCluster NetworkSecurityPerimeter Association
Microsoft.ContainerService/managedClusters/networkSecurityPerimeterAssociationProxies/write
#Description
Create or update ManagedCluster NetworkSecurityPerimeter Association
Microsoft.ContainerService/managedClusters/privateEndpointConnections/delete
#Description
Delete private endpoint connection
Microsoft.ContainerService/managedClusters/privateEndpointConnections/write
#Description
Approve or Reject a private endpoint connection
Microsoft.ContainerService/managedClusters/privateEndpointConnectionsApproval/action
#Description
Determines if user is allowed to approve a private endpoint connection
Microsoft.ContainerService/managedClusters/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for a managed cluster resource
Microsoft.ContainerService/managedClusters/resetAADProfile/action
#Description
Reset the AAD profile of a managed cluster
Microsoft.ContainerService/managedClusters/resetServicePrincipalProfile/action
#Description
Reset the service principal profile of a managed cluster
Microsoft.ContainerService/managedClusters/resolvePrivateLinkServiceId/action
#Description
Resolve the private link service id of a managed cluster
Microsoft.ContainerService/managedClusters/rotateClusterCertificates/action
#Description
Rotate certificates of a managed cluster
Microsoft.ContainerService/managedClusters/runCommand/action
#Description
Run user issued command against managed kubernetes server.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1651
Microsoft.ContainerService/managedClusters/start/action
#Description
Starts a managed cluster
Microsoft.ContainerService/managedClusters/stop/action
#Description
Stops a managed cluster
Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/delete
#Description
Delete trusted access role bindings for managed cluster
Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/write
#Description
Create or update trusted access role bindings for managed cluster
Microsoft.ContainerService/managedClusters/unpinManagedCluster/action
#Description
Unpin a managed cluster
Microsoft.ContainerService/managedClusters/write
#Description
Creates a new managed cluster or updates an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Failure",
"ActivitySubstatusValue": "Conflict",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
"action": "Microsoft.ContainerService/managedClusters/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
"action": "Microsoft.ContainerService/managedClusters/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "fec75ec9-d389-47e7-b44c-608de92bf88b",
"EventDataId": "34d7029e-460b-0974-27c1-b1a47fc36192",
"EventSubmissionTimestamp": "2026-07-03T02:19:02.3107988Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Error",
"OperationNameValue": "MICROSOFT.CONTAINERSERVICE/MANAGEDCLUSTERS/WRITE",
"Properties": {
"statusCode": "Conflict",
"serviceRequestId": "",
"statusMessage": {
"error": {
"code": "MissingSubscriptionRegistration",
"message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions.",
"details": [
{
"code": "MissingSubscriptionRegistration",
"target": "Microsoft.ContainerService",
"message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions."
}
]
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
"message": "Microsoft.ContainerService/managedClusters/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "34d7029e-460b-0974-27c1-b1a47fc36192",
"eventSubmissionTimestamp": "2026-07-03T02:19:02.3107988Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh36bcb1aks",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.CONTAINERSERVICE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "Conflict"
},
"Properties_d": {
"statusCode": "Conflict",
"serviceRequestId": "",
"statusMessage": {
"error": {
"code": "MissingSubscriptionRegistration",
"message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions.",
"details": [
{
"code": "MissingSubscriptionRegistration",
"target": "Microsoft.ContainerService",
"message": "The subscription is not registered to use namespace 'Microsoft.ContainerService'. See https://aka.ms/rps-not-found for how to register subscriptions."
}
]
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.ContainerService/managedClusters/dwh36bcb1aks",
"message": "Microsoft.ContainerService/managedClusters/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "34d7029e-460b-0974-27c1-b1a47fc36192",
"eventSubmissionTimestamp": "2026-07-03T02:19:02.3107988Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh36bcb1aks",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.CONTAINERSERVICE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "Conflict"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.CONTAINERSERVICE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.ContainerService/managedclustersnapshots/delete
#Description
Deletes a managed cluster snapshot
Microsoft.ContainerService/managedclustersnapshots/write
#Description
Creates a new managed cluster snapshot
Microsoft.ContainerService/nodeCustomizations/delete
#Description
Delete Node Customization
Microsoft.ContainerService/nodeCustomizations/versions/delete
#Description
Delete Node Customization Version
Microsoft.ContainerService/nodeCustomizations/versions/write
#Description
Create or Update Node Customization Version
Microsoft.ContainerService/nodeCustomizations/write
#Description
Create or Update Node Customization
Microsoft.ContainerService/openShiftClusters/delete
#Description
Delete an Open Shift Cluster
Microsoft.ContainerService/openShiftClusters/write
#Description
Creates a new Open Shift Cluster or updates an existing one
Microsoft.ContainerService/openShiftManagedClusters/delete
#Description
Delete an Open Shift Managed Cluster
Microsoft.ContainerService/openShiftManagedClusters/write
#Description
Creates a new Open Shift Managed Cluster or updates an existing one
Microsoft.ContainerService/preparedImageSpecifications/delete
#Description
Delete Prepared Image Specification
Microsoft.ContainerService/preparedImageSpecifications/deploy/action
#Description
Deploy Prepared Image Specification
Microsoft.ContainerService/preparedImageSpecifications/versions/delete
#Description
Delete Prepared Image Specification Version
Microsoft.ContainerService/preparedImageSpecifications/versions/deploy/action
#Description
Deploy Prepared Image Specification Version
Microsoft.ContainerService/preparedImageSpecifications/versions/write
#Description
Create or Update Prepared Image Specification Version
Microsoft.ContainerService/preparedImageSpecifications/write
#Description
Create or Update Prepared Image Specification
Microsoft.ContainerService/register/action
#Description
Registers Subscription with Microsoft.ContainerService resource provider
Microsoft.ContainerService/snapshots/delete
#Description
Deletes a snapshot
Microsoft.ContainerService/snapshots/write
#Description
Creates a new snapshot
Microsoft.ContainerService/unregister/action
#Description
Unregisters Subscription with Microsoft.ContainerService resource provider
Microsoft.ContainerService/fleets/notify/action
#Description
Send a notification event to a fleet
Microsoft.ContainerService/managedClusters/agentPools/listBootstrapData/action
#Description
List Agent Pool Bootstrap Data