Azure Network Azure-Microsoft.Network

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Network rules that match the resource provider but no specific operation.NN
Microsoft.Network/adminNetworkSecurityGroups/deleteDeletes Admin Network Security GroupNN
Microsoft.Network/adminNetworkSecurityGroups/writeCreates or Updates Existing Admin Network Security GroupNN
Microsoft.Network/applicationGateways/applicationGatewayHealth/actionGets an application gateway resource healthNN
Microsoft.Network/applicationGateways/appProtectPolicy/attachAppProtectPolicy/actionAttaches AppProtect policy to application gateway at global, path and/or listener levelNN
Microsoft.Network/applicationGateways/appProtectPolicy/detachAppProtectPolicy/actionDetaches AppProtect policy from application gateway at global, path and/or listener levelNN
Microsoft.Network/applicationGateways/appProtectPolicy/getAppProtectPolicy/actionGet AppProtect policy attached to application gateway resourceNN
Microsoft.Network/applicationGateways/backendAddressPools/join/actionJoins an application gateway backend address pool. Not Alertable.NN
Microsoft.Network/applicationGateways/backendhealth/actionGets an application gateway backend healthNN
Microsoft.Network/applicationGateways/commitMigration/actionCommit application gateway migrationNN
Microsoft.Network/applicationGateways/deleteDeletes an application gatewayNY
Microsoft.Network/applicationGateways/effectiveNetworkSecurityGroups/actionGet Route Table configured On Application GatewayNN
Microsoft.Network/applicationGateways/effectiveRouteTable/actionGet Route Table configured On Application GatewayNN
Microsoft.Network/applicationGateways/executeMigration/actionExecute application gateway migrationNN
Microsoft.Network/applicationGateways/getBackendHealthOnDemand/actionGets an application gateway backend health on demand for given http setting and backend poolNN
Microsoft.Network/applicationGateways/getListenerCertificateMetadata/actionGets an application gateway listener certificate metadataNN
Microsoft.Network/applicationGateways/getMigrationStatus/actionGet Status Of Migrate Application Gateway From V1 sku To V2 skuNN
Microsoft.Network/applicationGateways/migrateV1ToV2/actionMigrate Application Gateway from v1 sku to v2 skuNN
Microsoft.Network/applicationGateways/prepareMigration/actionPrepare application gateway migrationNN
Microsoft.Network/applicationGateways/privateEndpointConnections/deleteDeletes Application Gateway PrivateEndpoint ConnectionNN
Microsoft.Network/applicationGateways/privateEndpointConnections/writeUpdates Application Gateway PrivateEndpoint ConnectionNN
Microsoft.Network/applicationGateways/resolvePrivateLinkServiceId/actionResolves privateLinkServiceId for application gateway private link resourceNN
Microsoft.Network/applicationGateways/restart/actionRestarts an application gatewayNN
Microsoft.Network/applicationGateways/setSecurityCenterConfiguration/actionSets Application Gateway Security Center ConfigurationNN
Microsoft.Network/applicationGateways/start/actionStarts an application gatewayNN
Microsoft.Network/applicationGateways/stop/actionStops an application gatewayNN
Microsoft.Network/applicationGateways/v1tov2Migration/actionApplication Gateway V1 to V2 Migration OperationNN
Microsoft.Network/applicationGateways/writeCreates an application gateway or updates an application gatewayNY
Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/attachWafPolicyToAgc/actionAttaches Web application firewall policy to application gateway for containersNN
Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/deleteDeletes an Application Gateway WAF policyYN
Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/detachWafPolicyFromAgc/actionDetaches Web application firewall policy from application gateway for containersNN
Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/join/actionJoin Application Gateway Web Application Firewall Policy. Not alertableNN
Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/writeCreates an Application Gateway WAF policy or updates an Application Gateway WAF policyYN
Microsoft.Network/applicationSecurityGroups/addressPrefixSets/deleteDeletes an Address Prefix SetNN
Microsoft.Network/applicationSecurityGroups/addressPrefixSets/writeCreates an address prefix set or updates an existing address prefix setNN
Microsoft.Network/applicationSecurityGroups/deleteDeletes an Application Security GroupYY
Microsoft.Network/applicationSecurityGroups/joinIpConfiguration/actionJoins an IP Configuration to Application Security Groups. Not alertable.NN
Microsoft.Network/applicationSecurityGroups/joinNetworkSecurityRule/actionJoins a Security Rule to Application Security Groups. Not alertable.NN
Microsoft.Network/applicationSecurityGroups/listAddressPrefixSets/actionLists address prefix sets in an application security groupNN
Microsoft.Network/applicationSecurityGroups/listIpConfigurations/actionLists IP Configurations in the ApplicationSecurityGroupNN
Microsoft.Network/applicationSecurityGroups/writeCreates an Application Security Group, or updates an existing Application Security Group.YY
Microsoft.Network/authenticationPolicies/deleteDelete Authentication PolicyNN
Microsoft.Network/authenticationPolicies/join/actionJoin Authentication PolicyNN
Microsoft.Network/authenticationPolicies/writeCreate or update Authentication PolicyNN
Microsoft.Network/authorizationPolicies/deleteDelete Authorization PolicyNN
Microsoft.Network/authorizationPolicies/join/actionJoin Authorization PolicyNN
Microsoft.Network/authorizationPolicies/writeCreate or update Authorization PolicyNN
Microsoft.Network/azureFirewalls/applicationRuleCollections/deleteDeletes Azure Firewall ApplicationRuleCollectionNY
Microsoft.Network/azureFirewalls/applicationRuleCollections/writeCreatesOrUpdates Azure Firewall ApplicationRuleCollectionNY
Microsoft.Network/azurefirewalls/deleteDelete Azure FirewallNY
Microsoft.Network/azurefirewalls/learnedIPPrefixes/actionGets IP prefixes learned by Azure Firewall to not perform SNATNN
Microsoft.Network/azureFirewalls/natRuleCollections/deleteDeletes Azure Firewall NatRuleCollectionNY
Microsoft.Network/azureFirewalls/natRuleCollections/writeCreatesOrUpdates Azure Firewall NatRuleCollectionNY
Microsoft.Network/azureFirewalls/networkRuleCollections/deleteDeletes Azure Firewall NetworkRuleCollectionNY
Microsoft.Network/azureFirewalls/networkRuleCollections/writeCreatesOrUpdates Azure Firewall NetworkRuleCollectionNY
Microsoft.Network/azurefirewalls/packetCapture/actionAzureFirewallPacketCaptureOperationNN
Microsoft.Network/azurefirewalls/packetCaptureOperation/actionAzureFirewallPacketCaptureOperationNN
Microsoft.Network/azureFirewalls/providers/Microsoft.Insights/DiagnosticSettings/WriteCreate or update the diagnostic settings of Azure FirewallsNN
Microsoft.Network/azurefirewalls/writeCreates or updates an Azure FirewallNY
Microsoft.Network/azureWebCategories/classifyUnknown/actionClassifies Unknown WebCategoryNN
Microsoft.Network/azureWebCategories/getMiscategorizationStatus/actionGets Miscategorization StatusNN
Microsoft.Network/azureWebCategories/getwebcategory/actionLooks up WebCategoryNN
Microsoft.Network/azureWebCategories/reclassify/actionReclassifies WebCategoryNN
Microsoft.Network/bastionHosts/createShareableLinks/actionCreates shareable urls for the VMs under a bastion and returns the urlsNN
Microsoft.Network/bastionHosts/deleteDeletes a Bastion HostNN
Microsoft.Network/bastionHosts/deleteShareableLinks/actionDeletes shareable urls for the provided VMs under a bastionNN
Microsoft.Network/bastionHosts/deleteShareableLinksByToken/actionDeletes shareable urls for the provided tokens under a bastionNN
Microsoft.Network/bastionHosts/disconnectactivesessions/actionDisconnect given Active Sessions in the Bastion HostNN
Microsoft.Network/bastionHosts/getactivesessions/actionGet Active Sessions in the Bastion HostNN
Microsoft.Network/bastionHosts/getsessionrecordingsasurl/actionGets SAS URL for BastionHost Session Recording FeatureNN
Microsoft.Network/bastionHosts/getShareableLinks/actionReturns the shareable urls for the specified VMs in a Bastion subnet provided their urls are createdNN
Microsoft.Network/bastionHosts/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resourceNN
Microsoft.Network/bastionHosts/setsessionrecordingsasurl/actionSets SAS URL for BastionHost Session Recording FeatureNN
Microsoft.Network/bastionHosts/writeCreate or Update a Bastion HostNN
Microsoft.Network/checkFrontDoorNameAvailability/actionChecks whether a Front Door name is availableNN
Microsoft.Network/checkTrafficManagerNameAvailability/actionChecks the availability of a Traffic Manager Relative DNS name.NN
Microsoft.Network/connections/deleteDeletes VirtualNetworkGatewayConnectionNN
Microsoft.Network/connections/getikesas/actionLists IKE Security Associations for the connectionNN
Microsoft.Network/connections/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates diagnostic settings for ConnectionsNN
Microsoft.Network/connections/resetconnection/actionResets connection for VNGNN
Microsoft.Network/connections/revoke/actionMarks an Express Route Connection status as RevokedNN
Microsoft.Network/connections/sharedkey/actionGet VirtualNetworkGatewayConnection SharedKeyNN
Microsoft.Network/connections/sharedKey/writeCreates or updates an existing VirtualNetworkGatewayConnection SharedKeyNN
Microsoft.Network/connections/startpacketcapture/actionStarts a Virtual Network Gateway Connection Packet Capture.NN
Microsoft.Network/connections/stoppacketcapture/actionStops a Virtual Network Gateway Connection Packet Capture.NN
Microsoft.Network/connections/vpndeviceconfigurationscript/actionGets Vpn Device Configuration of VirtualNetworkGatewayConnectionNN
Microsoft.Network/connections/writeCreates or updates an existing VirtualNetworkGatewayConnectionNN
Microsoft.Network/customIpPrefixes/deleteDeletes A Custom Ip PrefixNN
Microsoft.Network/customIpPrefixes/join/actionJoins a CustomIpPrefix. Not alertable.NN
Microsoft.Network/customIpPrefixes/writeCreates A Custom Ip Prefix Or Updates An Existing Custom Ip PrefixNN
Microsoft.Network/ddosCustomPolicies/deleteDeletes a DDoS customized policyNN
Microsoft.Network/ddosCustomPolicies/writeCreates a DDoS customized policy or updates an existing DDoS customized policyNN
Microsoft.Network/ddosProtectionPlans/ddosProtectionPlanProxies/deleteDeletes a DDoS Protection Plan ProxyNN
Microsoft.Network/ddosProtectionPlans/ddosProtectionPlanProxies/writeCreates a DDoS Protection Plan Proxy or updates and existing DDoS Protection Plan ProxyNN
Microsoft.Network/ddosProtectionPlans/deleteDeletes a DDoS Protection PlanNN
Microsoft.Network/ddosProtectionPlans/join/actionJoins a DDoS Protection Plan. Not alertable.NN
Microsoft.Network/ddosProtectionPlans/writeCreates a DDoS Protection Plan or updates a DDoS Protection PlanNN
Microsoft.Network/dnsForwardingRulesets/deleteDeletes a DNS Forwarding Ruleset, in JSON formatNN
Microsoft.Network/dnsForwardingRulesets/forwardingRules/deleteDeletes a DNS Forwarding Rule, in JSON formatNN
Microsoft.Network/dnsForwardingRulesets/forwardingRules/writeCreates Or Updates a DNS Forwarding Rule, in JSON formatNN
Microsoft.Network/dnsForwardingRulesets/join/actionJoin DNS Forwarding RulesetNN
Microsoft.Network/dnsForwardingRulesets/virtualNetworkLinks/deleteDeletes DNS Forwarding Ruleset Link to Virtual NetworkNN
Microsoft.Network/dnsForwardingRulesets/virtualNetworkLinks/writeCreates Or Updates DNS Forwarding Ruleset Link to virtual network properties, in JSON formatNN
Microsoft.Network/dnsForwardingRulesets/writeCreates Or Updates a DNS Forwarding RulesetNN
Microsoft.Network/dnsResolverDomainLists/bulk/actionBulk operations on the contents of the DNS Resolver Domain List.NN
Microsoft.Network/dnsResolverDomainLists/deleteDelete a DNS Resolver Domain List.NN
Microsoft.Network/dnsResolverDomainLists/join/actionJoin a DNS Resolver Domain List from another resource.NN
Microsoft.Network/dnsResolverDomainLists/writeCreate or update a DNS Resolver Domain List.NN
Microsoft.Network/dnsResolverPolicies/deleteDelete a DNS Resolver Policy.NN
Microsoft.Network/dnsResolverPolicies/dnsSecurityRules/deleteDelete a DNS Security Rule for a DNS Resolver Policy.NN
Microsoft.Network/dnsResolverPolicies/dnsSecurityRules/writeCreate or update a DNS Security Rule for a DNS Resolver Policy.NN
Microsoft.Network/dnsResolverPolicies/providers/Microsoft.Insights/diagnosticSettings/writeCreate or update diagnostic settings for a DNS Resolver Policy.NN
Microsoft.Network/dnsResolverPolicies/virtualNetworkLinks/deleteDelete a Virtual Network Link for a DNS Resolver Policy.NN
Microsoft.Network/dnsResolverPolicies/virtualNetworkLinks/writeCreate or update a Virtual Network Link for a DNS Resolver Policy.NN
Microsoft.Network/dnsResolverPolicies/writeCreate or update a DNS Resolver Policy.NN
Microsoft.Network/dnsResolvers/deleteDeletes a DNS ResolverNN
Microsoft.Network/dnsResolvers/inboundEndpoints/deleteDeletes a DNS Resolver Inbound Endpoint, in JSON formatNN
Microsoft.Network/dnsResolvers/inboundEndpoints/join/actionJoin DNS ResolverNN
Microsoft.Network/dnsResolvers/inboundEndpoints/writeCreates Or Updates a DNS Resolver Inbound Endpoint, in JSON formatNN
Microsoft.Network/dnsResolvers/join/actionJoin DNS ResolverNN
Microsoft.Network/dnsResolvers/outboundEndpoints/deleteDeletes a DNS Resolver Outbound Endpoint description.NN
Microsoft.Network/dnsResolvers/outboundEndpoints/join/actionJoin DNS ResolverNN
Microsoft.Network/dnsResolvers/outboundEndpoints/listDnsForwardingRulesets/actionGets the DNS Forwarding Rulesets Properties for DNS Resolver Outbound Endpoint, in JSON formatNN
Microsoft.Network/dnsResolvers/outboundEndpoints/writeCreates Or Updates a DNS Resolver Outbound Endpoint, in JSON formatNN
Microsoft.Network/dnsResolvers/writeCreates Or Updates a DNS Resolver, in JSON formatNN
Microsoft.Network/dnszones/A/deleteRemove the record set of a given name and type 'A' from a DNS zone.NN
Microsoft.Network/dnszones/A/writeCreate or update a record set of type 'A' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/AAAA/deleteRemove the record set of a given name and type 'AAAA' from a DNS zone.NN
Microsoft.Network/dnszones/AAAA/writeCreate or update a record set of type 'AAAA' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/CAA/deleteRemove the record set of a given name and type 'CAA' from a DNS zone.NN
Microsoft.Network/dnszones/CAA/writeCreate or update a record set of type 'CAA' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/CNAME/deleteRemove the record set of a given name and type 'CNAME' from a DNS zone.NN
Microsoft.Network/dnszones/CNAME/writeCreate or update a record set of type 'CNAME' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/deleteDelete the DNS zone, in JSON format. The zone properties include tags, etag, numberOfRecordSets, and maxNumberOfRecordSets.YN
Microsoft.Network/dnszones/dnssecConfigs/default/deleteDeletes the DNSSEC configuration for a DNS zoneNN
Microsoft.Network/dnszones/dnssecConfigs/default/writeCreates or updates the DNSSEC configuration for a DNS zoneNN
Microsoft.Network/dnszones/DS/deleteDeletes the DNS record set of type DSNN
Microsoft.Network/dnszones/DS/writeCreates or updates DNS record set of type DSNN
Microsoft.Network/dnszones/MX/deleteRemove the record set of a given name and type 'MX' from a DNS zone.NN
Microsoft.Network/dnszones/MX/writeCreate or update a record set of type 'MX' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/NS/deleteDeletes the DNS record set of type NSNN
Microsoft.Network/dnszones/NS/writeCreates or updates DNS record set of type NSNN
Microsoft.Network/dnszones/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the DNS zone diagnostic settingsNN
Microsoft.Network/dnszones/PTR/deleteRemove the record set of a given name and type 'PTR' from a DNS zone.NN
Microsoft.Network/dnszones/PTR/writeCreate or update a record set of type 'PTR' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/SOA/writeCreates or updates DNS record set of type SOANN
Microsoft.Network/dnszones/SRV/deleteRemove the record set of a given name and type 'SRV' from a DNS zone.NN
Microsoft.Network/dnszones/SRV/writeCreate or update record set of type SRVNN
Microsoft.Network/dnszones/TLSA/deleteDeletes the DNS record set of type TLSANN
Microsoft.Network/dnszones/TLSA/writeCreates or updates DNS record set of type TLSANN
Microsoft.Network/dnszones/TXT/deleteRemove the record set of a given name and type 'TXT' from a DNS zone.NN
Microsoft.Network/dnszones/TXT/writeCreate or update a record set of type 'TXT' within a DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/dnszones/writeCreate or update a DNS zone within a resource group. Used to update the tags on a DNS zone resource. Note that this command can not be used to create or update record sets within the zone.YN
Microsoft.Network/dscpConfiguration/join/actionJoins DSCP ConfigurationNN
Microsoft.Network/dscpConfiguration/writeOperation to put the DSCP configurationNN
Microsoft.Network/expressRouteCircuits/authorizations/addAuthorization/actionCreate an ExpressRouteCircuit AuthorizationNN
Microsoft.Network/expressRouteCircuits/authorizations/authorizationKey/actionGet an Authorization Key for ExpressRouteCircuit AuthorizationNN
Microsoft.Network/expressRouteCircuits/authorizations/deleteDeletes an ExpressRouteCircuit AuthorizationNN
Microsoft.Network/expressRouteCircuits/authorizations/getAuthorization/actionGets an ExpressRouteCircuit Authorization with Authorization KeyNN
Microsoft.Network/expressRouteCircuits/authorizations/listkeys/actionGet an Authorization Key for ExpressRouteCircuit AuthorizationNN
Microsoft.Network/expressRouteCircuits/authorizations/writeCreates or updates an existing ExpressRouteCircuit AuthorizationNN
Microsoft.Network/expressRouteCircuits/deleteDeletes an ExpressRouteCircuitNN
Microsoft.Network/expressRouteCircuits/join/actionJoins an Express Route Circuit. Not alertable.NN
Microsoft.Network/expressRouteCircuits/listAuthorizations/actionList All ExpressRouteCircuit Authorization with Authorization KeyNN
Microsoft.Network/expressRouteCircuits/nrpinternalupdate/actionCreate or Update ExpressRouteCircuitNN
Microsoft.Network/expressRouteCircuits/peerings/connections/deleteDeletes an ExpressRouteCircuit ConnectionNN
Microsoft.Network/expressRouteCircuits/peerings/connections/writeCreates or updates an existing ExpressRouteCircuit Connection ResourceNN
Microsoft.Network/expressRouteCircuits/peerings/deleteDeletes an ExpressRouteCircuit PeeringNN
Microsoft.Network/expressRouteCircuits/peerings/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates diagnostic settings for ExpressRoute Circuit PeeringsNN
Microsoft.Network/expressRouteCircuits/peerings/writeCreates or updates an existing ExpressRouteCircuit PeeringNN
Microsoft.Network/expressRouteCircuits/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates diagnostic settings for ExpressRoute CircuitsNN
Microsoft.Network/expressRouteCircuits/writeCreates or updates an existing ExpressRouteCircuitNN
Microsoft.Network/expressRouteCrossConnections/confirmActivationKey/actionExpress Route Cross Connection Confirm Activation KeyNN
Microsoft.Network/expressRouteCrossConnections/deleteDelete Express Route Cross ConnectionNN
Microsoft.Network/expressRouteCrossConnections/deprovisionConnection/actionExpress Route Deprovision Multi Cloud ConnectionNN
Microsoft.Network/expressRouteCrossConnections/features/deleteDeletes an Express Route Cross Connection FeatureNN
Microsoft.Network/expressRouteCrossConnections/features/writeCreates or Updates an Express Route Cross Connection FeatureNN
Microsoft.Network/expressRouteCrossConnections/join/actionJoins an Express Route Cross Connection. Not alertable.NN
Microsoft.Network/expressRouteCrossConnections/notifyConnectionStatus/actionExpress Route Notify Multi Cloud Connection StatusNN
Microsoft.Network/expressRouteCrossConnections/peerings/deleteDeletes an Express Route Cross Connection PeeringNN
Microsoft.Network/expressRouteCrossConnections/peerings/writeCreates an Express Route Cross Connection Peering or Updates an existing Express Route Cross Connection PeeringNN
Microsoft.Network/expressRouteCrossConnections/proposeInterconnect/actionExpress Route Cross Connection operation to propose InterconnectNN
Microsoft.Network/expressRouteCrossConnections/serviceProviders/actionBackfill Express Route Cross ConnectionNN
Microsoft.Network/expressRouteCrossConnections/writeCreate or Update Express Route Cross ConnectionNN
Microsoft.Network/expressRouteGateways/deleteDelete Express Route GatewayNN
Microsoft.Network/expressRouteGateways/expressRouteConnections/deleteDeletes an Express Route ConnectionNN
Microsoft.Network/expressRouteGateways/expressRouteConnections/writeCreates an Express Route Connection or Updates an existing Express Route ConnectionNN
Microsoft.Network/expressRouteGateways/join/actionJoins an Express Route Gateway. Not alertable.NN
Microsoft.Network/expressRouteGateways/writeCreate or Update Express Route GatewayNN
Microsoft.Network/expressRouteLags/authorizations/deleteDeletes an ExpressRouteLagAuthorizationNN
Microsoft.Network/expressRouteLags/authorizations/listkeys/actionGet an AuthorizationKey for ExpressRouteLagAuthorizationNN
Microsoft.Network/expressRouteLags/authorizations/writeCreate or Update ExpressRouteLagAuthorizationNN
Microsoft.Network/expressRouteLags/deleteDeletes ExpressRouteLagNN
Microsoft.Network/expressRouteLags/generateloa/actionGenerates LOA for ExpressRouteLagNN
Microsoft.Network/expressRouteLags/join/actionJoins ExpressRouteLagNN
Microsoft.Network/expressRouteLags/writeCreates or updates ExpressRouteLagNN
Microsoft.Network/expressRoutePorts/authorizations/addAuthorization/actionCreate ExpressRoutePorts AuthorizationNN
Microsoft.Network/expressRoutePorts/authorizations/authorizationKey/actionGet an Authorization Key for Express Route Ports AuthorizationNN
Microsoft.Network/expressRoutePorts/authorizations/deleteDeletes an ExpressRoutePorts AuthorizationNN
Microsoft.Network/expressRoutePorts/authorizations/getAuthorization/actionGet Express Route Ports Authorization with Authorization KeyNN
Microsoft.Network/expressRoutePorts/authorizations/listkeys/actionGet an Authorization Key for Express Route Ports AuthorizationNN
Microsoft.Network/expressRoutePorts/authorizations/writeCreates or updates an existing ExpressRoutePorts AuthorizationNN
Microsoft.Network/expressRoutePorts/deleteDeletes ExpressRoutePortsNN
Microsoft.Network/expressRoutePorts/generateloa/actionGenerates LOA for ExpressRoutePortsNN
Microsoft.Network/expressRoutePorts/join/actionJoins Express Route ports. Not alertable.NN
Microsoft.Network/expressRoutePorts/listAuthorizations/actionList All Express Route Ports Authorizations with Authorization KeyNN
Microsoft.Network/expressRoutePorts/writeCreates or updates ExpressRoutePortsNN
Microsoft.Network/firewallPolicies/certificates/actionGenerate Firewall Policy CertificatesNY
Microsoft.Network/firewallPolicies/deleteDeletes a Firewall PolicyYY
Microsoft.Network/firewallPolicies/deploy/actionDeploy Firewall Policy DraftNN
Microsoft.Network/firewallPolicies/firewallPolicyDrafts/deleteDeletes a Firewall Policy DraftNN
Microsoft.Network/firewallPolicies/firewallPolicyDrafts/writeCreates a Firewall Policy Draft or Updates an existing Firewall Policy DraftNN
Microsoft.Network/firewallPolicies/join/actionJoins a Firewall Policy. Not alertable.NY
Microsoft.Network/firewallPolicies/pacFile/actionGet Firewall Policy PacFileNN
Microsoft.Network/firewallPolicies/ruleCollectionGroups/deleteDeletes a Firewall Policy Rule Collection GroupNY
Microsoft.Network/firewallPolicies/ruleCollectionGroups/ruleCollectionGroupDrafts/deleteDeletes a Firewall Policy Rule Collection Group DraftNN
Microsoft.Network/firewallPolicies/ruleCollectionGroups/ruleCollectionGroupDrafts/writeCreates a Firewall Policy Rule Collection Group Draft or Updates an existing Firewall Policy Rule Collection Group DraftNN
Microsoft.Network/firewallPolicies/ruleCollectionGroups/writeCreates a Firewall Policy Rule Collection Group or Updates an existing Firewall Policy Rule Collection GroupNY
Microsoft.Network/firewallPolicies/ruleGroups/deleteDeletes a Firewall Policy Rule GroupNY
Microsoft.Network/firewallPolicies/ruleGroups/writeCreates a Firewall Policy Rule Group or Updates an existing Firewall Policy Rule GroupNY
Microsoft.Network/firewallPolicies/writeCreates a Firewall Policy or Updates an existing Firewall PolicyYY
Microsoft.Network/firstPartyServiceTags/deleteDelete First Party Service TagNN
Microsoft.Network/firstPartyServiceTags/writeCreate or Update First Party Service TagNN
Microsoft.Network/frontDoors/backendPools/deleteDeletes a backend poolNN
Microsoft.Network/frontDoors/backendPools/writeCreates or updates a backend poolNN
Microsoft.Network/frontDoors/deleteDeletes a Front DoorNN
Microsoft.Network/frontDoors/frontendEndpoints/deleteDeletes a frontend endpointNN
Microsoft.Network/frontDoors/frontendEndpoints/disableHttps/actionDisables HTTPS on a Frontend EndpointNN
Microsoft.Network/frontDoors/frontendEndpoints/enableHttps/actionEnables HTTPS on a Frontend EndpointNN
Microsoft.Network/frontDoors/frontendEndpoints/writeCreates or updates a frontend endpointNN
Microsoft.Network/frontDoors/healthProbeSettings/deleteDeletes health probe settingsNN
Microsoft.Network/frontDoors/healthProbeSettings/writeCreates or updates health probe settingsNN
Microsoft.Network/frontDoors/loadBalancingSettings/deleteCreates or updates load balancing settingsNN
Microsoft.Network/frontDoors/loadBalancingSettings/writeCreates or updates load balancing settingsNN
Microsoft.Network/frontdoors/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the Frontdoor resourceNN
Microsoft.Network/frontDoors/purge/actionPurge cached content from a Front DoorNN
Microsoft.Network/frontDoors/routingRules/deleteDeletes a routing ruleNN
Microsoft.Network/frontDoors/routingRules/writeCreates or updates a routing ruleNN
Microsoft.Network/frontDoors/rulesEngines/deleteDeletes a Rules EngineNN
Microsoft.Network/frontDoors/rulesEngines/writeCreates or updates a Rules EngineNN
Microsoft.Network/frontDoors/validateCustomDomain/actionValidates a frontend endpoint for a Front DoorNN
Microsoft.Network/frontDoors/writeCreates or updates a Front DoorNN
Microsoft.Network/frontDoorWebApplicationFirewallPolicies/deleteDeletes a Web Application Firewall PolicyNY
Microsoft.Network/frontDoorWebApplicationFirewallPolicies/join/actionJoins a Web Application Firewall Policy. Not Alertable.NN
Microsoft.Network/frontDoorWebApplicationFirewallPolicies/writeCreates or updates a Web Application Firewall PolicyNN
Microsoft.Network/gatewayLoadBalancerAliases/deleteDelete Gateway LoadBalancer AliasNN
Microsoft.Network/gatewayLoadBalancerAliases/writeCreates or Updates a Gateway LaodBalancer AliasNN
Microsoft.Network/getDnsResourceReference/actionDNS alias resource dependency requestNN
Microsoft.Network/interconnectGroups/deleteDelete Interconnect GroupNN
Microsoft.Network/interconnectGroups/writeCreate or update Interconnect GroupNN
Microsoft.Network/internalNotify/actionDNS alias resource notificationNN
Microsoft.Network/ipAllocations/deleteDeletes A IpAllocationNN
Microsoft.Network/ipAllocations/writeCreates A IpAllocation Or Updates An Existing IpAllocationNN
Microsoft.Network/ipGroups/deleteDeletes an IpGroupYN
Microsoft.Network/ipGroups/join/actionJoins an IpGroup. Not alertable.NN
Microsoft.Network/ipGroups/updateReferences/actionUpdate references in an IpGroupNN
Microsoft.Network/ipGroups/validate/actionValidates an IpGroupNN
Microsoft.Network/ipGroups/writeCreates an IpGroup or Updates an Existing IpGroupYN
Microsoft.Network/loadBalancers/backendAddressPools/deleteDeletes a load balancer backend address poolNN
Microsoft.Network/loadBalancers/backendAddressPools/health/actionGet Health Details of Backend InstanceNN
Microsoft.Network/loadBalancers/backendAddressPools/join/actionJoins a load balancer backend address pool. Not Alertable.NN
Microsoft.Network/loadBalancers/backendAddressPools/queryInboundNatRulePortMapping/actionQuery inbound Nat rule port mapping.NN
Microsoft.Network/loadBalancers/backendAddressPools/updateAdminState/actionUpdate AdminStates of backend addresses of a poolNN
Microsoft.Network/loadBalancers/backendAddressPools/writeCreates a load balancer backend address pool or updates an existing load balancer backend address poolNN
Microsoft.Network/loadBalancers/deleteDeletes a load balancerYN
Microsoft.Network/loadBalancers/frontendIPConfigurations/join/actionJoins a Load Balancer Frontend IP Configuration. Not alertable.NN
Microsoft.Network/loadBalancers/frontendIPConfigurations/loadBalancerPools/deleteDeletes a load balancer frontend IP address backend poolNN
Microsoft.Network/loadBalancers/frontendIPConfigurations/loadBalancerPools/join/actionJoins a load balancer frontend IP address backend pool. Not alertable.NN
Microsoft.Network/loadBalancers/frontendIPConfigurations/loadBalancerPools/writeCreates a load balancer frontend IP address backend pool or updates an existing public IP Address load balancer backend poolNN
Microsoft.Network/loadBalancers/health/actionGet Health Summary of Load BalancerNN
Microsoft.Network/loadBalancers/inboundNatPools/join/actionJoins a load balancer inbound NAT pool. Not alertable.NN
Microsoft.Network/loadBalancers/inboundNatRules/deleteDeletes a load balancer inbound nat ruleNN
Microsoft.Network/loadBalancers/inboundNatRules/join/actionJoins a load balancer inbound nat rule. Not Alertable.NN
Microsoft.Network/loadBalancers/inboundNatRules/writeCreates a load balancer inbound nat rule or updates an existing load balancer inbound nat ruleNN
Microsoft.Network/loadBalancers/loadBalancingRules/health/actionGet Health Details of Load Balancing RuleNN
Microsoft.Network/loadBalancers/migrateToIpBased/actionMigrate from NIC based to IP based Load BalancerNN
Microsoft.Network/loadBalancers/probes/join/actionAllows using probes of a load balancer. For example, with this permission healthProbe property of VM scale set can reference the probe. Not alertable.NN
Microsoft.Network/loadBalancers/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the Load Balancer Diagnostic SettingsNN
Microsoft.Network/loadBalancers/writeCreates a load balancer or updates an existing load balancerYN
Microsoft.Network/localnetworkgateways/deleteDeletes LocalNetworkGatewayYN
Microsoft.Network/localnetworkgateways/writeCreates or updates an existing LocalNetworkGatewayYN
Microsoft.Network/locations/bareMetalTenants/actionAllocates or validates a Bare Metal TenantNN
Microsoft.Network/locations/batchNotifyPrivateEndpointsForResourceMove/actionNotifies to private endpoint in batches for resource move.NN
Microsoft.Network/locations/batchValidatePrivateEndpointsForResourceMove/actionValidates private endpoints in batches for resource move.NN
Microsoft.Network/locations/checkAcceleratedNetworkingSupport/actionChecks Accelerated Networking supportNN
Microsoft.Network/locations/checkPrivateLinkServiceVisibility/actionChecks Private Link Service VisibilityNN
Microsoft.Network/locations/commitInternalAzureNetworkManagerConfiguration/actionCommits Internal AzureNetworkManager Configuration In ANMNN
Microsoft.Network/locations/dataTasks/run/actionRuns Data TaskNN
Microsoft.Network/locations/deletePacketTagging/actionDeletes Packet TaggingNN
Microsoft.Network/locations/effectiveResourceOwnership/actionGets Effective Resource OwnershipNN
Microsoft.Network/locations/getAzureNetworkManagerConfiguration/actionGets Azure Network Manager ConfigurationNN
Microsoft.Network/locations/getPacketTagging/actionGets Packet TaggingNN
Microsoft.Network/locations/internalAzureVirtualNetworkManagerOperation/actionInternal AzureVirtualNetworkManager Operation In ANMNN
Microsoft.Network/locations/privateLinkServices/privateEndpointConnectionProxies/deleteDeletes an private endpoint connection proxy resource.NN
Microsoft.Network/locations/privateLinkServices/privateEndpointConnectionProxies/writeCreates a new private endpoint connection proxy, or updates an existing private endpoint connection proxy.NN
Microsoft.Network/locations/publicIPAddresses/cleanupDdppReference/actionCleanup DDPP reference on linked PublicIP upon DDPP subscription deleteNN
Microsoft.Network/locations/publishResources/actionPublish Subscrioption ResourcesNN
Microsoft.Network/locations/PutResourcePubsubData/actionPut Resource PubSub DataNN
Microsoft.Network/locations/queryNetworkSecurityPerimeter/actionQueries Network Security Perimeter by the perimeter GUIDNN
Microsoft.Network/locations/rnmEffectiveNetworkSecurityGroups/actionGets Effective Security Groups Configured In Rnm FormatNN
Microsoft.Network/locations/rnmEffectiveRouteTable/actionGets Effective Routes Configured In Rnm FormatNN
Microsoft.Network/locations/setAzureNetworkManagerConfiguration/actionSets Azure Network Manager ConfigurationNN
Microsoft.Network/locations/setLbBackendAdminState/actionSets admin state for load balancer backend addresses associated with the specified virtual machines or VM scale set instancesNN
Microsoft.Network/locations/setLoadBalancerFrontendPublicIpAddresses/actionSetLoadBalancerFrontendPublicIpAddresses targets frontend IP configurations of 2 load balancers. Azure Resource Manager IDs of the IP configurations are provided in the body of the request.NN
Microsoft.Network/locations/setResourceOwnership/actionSets Resource OwnershipNN
Microsoft.Network/locations/startPacketTagging/actionStarts Packet TaggingNN
Microsoft.Network/locations/validateResourceOwnership/actionValidates Resource OwnershipNN
Microsoft.Network/locations/virtualNetworks/cleanupDdppReference/actionCleanup DDPP reference on linked VNET upon DDPP subscription deleteNN
Microsoft.Network/masterCustomIpPrefixes/deleteDeletes A Master Custom Ip PrefixNN
Microsoft.Network/masterCustomIpPrefixes/writeCreates A Master Custom Ip Prefix Or Updates An Existing Master Custom Ip PrefixNN
Microsoft.Network/natGateways/deleteDelete Nat GatewayYN
Microsoft.Network/natGateways/join/actionJoins a NAT GatewayNN
Microsoft.Network/natGateways/writeCreates or Updates a Nat GatewayYN
Microsoft.Network/networkExperimentProfiles/deleteDelete an Internet Analyzer profileNN
Microsoft.Network/networkExperimentProfiles/experiments/deleteDelete an Internet Analyzer testNN
Microsoft.Network/networkExperimentProfiles/experiments/latencyScorecard/actionGet an Internet Analyzer test's latency scorecardNN
Microsoft.Network/networkExperimentProfiles/experiments/timeseries/actionGet an Internet Analyzer test's time seriesNN
Microsoft.Network/networkExperimentProfiles/experiments/writeCreate or update an Internet Analyzer testNN
Microsoft.Network/networkExperimentProfiles/writeCreate or update an Internet Analyzer profileNN
Microsoft.Network/networkIntentPolicies/deleteDeletes an Network Intent PolicyNN
Microsoft.Network/networkIntentPolicies/join/actionJoins a Network Intent Policy. Not alertable.NN
Microsoft.Network/networkIntentPolicies/writeCreates an Network Intent Policy or updates an existing Network Intent PolicyNN
Microsoft.Network/networkInterfaces/deleteDeletes a network interfaceYY
Microsoft.Network/networkInterfaces/effectiveNetworkSecurityGroups/actionGet Network Security Groups configured On Network Interface Of The VmNN
Microsoft.Network/networkInterfaces/effectiveRouteTable/actionGet Route Table configured On Network Interface Of The VmNN
Microsoft.Network/networkInterfaces/ipconfigurations/join/actionJoins a Network Interface IP Configuration. Not alertable.NN
Microsoft.Network/networkInterfaces/join/actionJoins a Virtual Machine to a network interface. Not Alertable.NY
Microsoft.Network/networkInterfaces/tapConfigurations/deleteDeletes a Network Interface Tap Configuration.NY
Microsoft.Network/networkInterfaces/tapConfigurations/writeCreates a Network Interface Tap Configuration or updates an existing Network Interface Tap Configuration.NY
Microsoft.Network/networkInterfaces/UpdateParentNicAttachmentOnElasticNic/actionUpdates the parent NIC associated to the elastic NICNN
Microsoft.Network/networkInterfaces/writeCreates a network interface or updates an existing network interface.YY
Microsoft.Network/networkManagerConnections/deleteDelete Network Manager ConnectionNN
Microsoft.Network/networkManagerConnections/writeCreate Or Update Network Manager ConnectionNN
Microsoft.Network/networkManagers/commit/actionNetwork Manager CommitNN
Microsoft.Network/networkManagers/connectivityConfigurations/deleteDelete Connectivity ConfigurationNN
Microsoft.Network/networkManagers/connectivityConfigurations/writeCreate Or Update Connectivity ConfigurationNN
Microsoft.Network/networkManagers/deleteDelete Network ManagerNN
Microsoft.Network/networkManagers/ipamPools/allocateAzureResource/actionAllocate CIDR range for Azure resource from Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/allocateNonAzureResource/actionAllocate CIDR range for non Azure resource from Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/allocateResourcePrefixes/actionAllocate CIDR Range for Resource from Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/associatedResources/actionAction permission for list Associated Resource To Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/associateResourcesToPool/actionAction permission for associate resources to Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/deleteDeletes a Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/disassociateResourcesFromPool/actionDisassociate Azure resources (i.e. VNet) from Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/getPoolUsage/actionGet pool usage for a Ipam PoolNN
microsoft.network/networkmanagers/ipampools/listassociatedresources/actionAction permission for list Associated Resource To Ipam PoolNN
microsoft.network/networkmanagers/ipampools/staticcidrs/deleteDeletes a static CIDR from an Ipam PoolNN
microsoft.network/networkmanagers/ipampools/staticcidrs/writeCreates or updates a static CIDR in an Ipam PoolNN
Microsoft.Network/networkManagers/ipamPools/writeCreates or Updates a Ipam PoolNN
Microsoft.Network/networkManagers/listActiveConnectivityConfigurations/actionLists Active Connectivity ConfigurationsNN
Microsoft.Network/networkManagers/listActiveSecurityAdminRules/actionLists Active Security Admin RulesNN
Microsoft.Network/networkManagers/listActiveSecurityUserRules/actionLists Active Security User RulesNN
Microsoft.Network/networkManagers/listDeploymentStatus/actionList Deployment StatusNN
Microsoft.Network/networkManagers/networkGroups/deleteDelete Network GroupNN
Microsoft.Network/networkManagers/networkGroups/join/actionJoin Network GroupNN
Microsoft.Network/networkManagers/networkGroups/staticMembers/deleteDelete Network Group Static MemberNN
Microsoft.Network/networkManagers/networkGroups/staticMembers/writeCreate Or Update Network Group Static MemberNN
Microsoft.Network/networkManagers/networkGroups/writeCreate Or Update Network GroupNN
Microsoft.Network/networkManagers/routingConfigurations/deleteDelete Routing ConfigurationNN
Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/deleteDelete Routing Rule CollectionNN
Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/rules/deleteDelete Routing RuleNN
Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/rules/writeCreate Or Update Routing RuleNN
Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/writeCreate Or Update Routing Rule CollectionNN
Microsoft.Network/networkManagers/routingConfigurations/writeCreate Or Update Routing ConfigurationNN
Microsoft.Network/networkManagers/scopeConnections/deleteDelete Network Manager Scope ConnectionNN
Microsoft.Network/networkManagers/scopeConnections/writeCreate Or Update Network Manager Scope ConnectionNN
Microsoft.Network/networkManagers/securityAdminConfigurations/deleteDelete Security Admin ConfigurationNN
Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/deleteDelete Security Admin Rule CollectionNN
Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/rules/deleteDelete Security Admin RuleNN
Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/rules/writeCreate Or Update Security Admin RuleNN
Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/writeCreate Or Update Security Admin Rule CollectionNN
Microsoft.Network/networkManagers/securityAdminConfigurations/writeCreate Or Update Security Admin ConfigurationNN
Microsoft.Network/networkManagers/securityUserConfigurations/deleteDelete Security User ConfigurationNN
Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/deleteDelete Security User Rule CollectionNN
Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/rules/deleteDelete Security User RuleNN
Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/rules/writeCreate Or Update Security User RuleNN
Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/writeCreate Or Update Security User Rule CollectionNN
Microsoft.Network/networkManagers/securityUserConfigurations/writeCreate Or Update Security User ConfigurationNN
Microsoft.Network/networkManagers/verifierWorkspaces/deleteDeletes a Verifier WorkspaceNN
Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisIntents/deleteDeletes a Reachability Analysis IntentNN
Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisIntents/writeCreates or Updates a Reachability Analysis IntentNN
Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisRuns/deleteDeletes a Reachability Analysis RunNN
Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisRuns/writeCreates or Updates a Reachability Analysis RunNN
Microsoft.Network/networkManagers/verifierWorkspaces/writeCreates or Updates a Verifier WorkspaceNN
Microsoft.Network/networkManagers/writeCreate Or Update Network ManagerNN
Microsoft.Network/networkProfiles/deleteDeletes a Network ProfileNN
Microsoft.Network/networkProfiles/removeContainers/actionRemoves ContainersNN
Microsoft.Network/networkProfiles/setContainers/actionSets ContainersNN
Microsoft.Network/networkProfiles/setNetworkInterfaces/actionSets Container Network InterfacesNN
Microsoft.Network/networkProfiles/writeCreates or updates a Network ProfileNN
Microsoft.Network/networkSecurityGroups/deleteDeletes a network security groupYY
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable.NY
Microsoft.Network/networksecuritygroups/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the Network Security Groups diagnostic settings, this operation is supplemented by insights resource provider.NY
Microsoft.Network/networkSecurityGroups/securityRules/deleteDeletes a security ruleYY
Microsoft.Network/networkSecurityGroups/securityRules/writeCreates a security rule or updates an existing security ruleYY
Microsoft.Network/networkSecurityGroups/writeCreates a network security group or updates an existing network security groupYY
Microsoft.Network/networkSecurityPerimeters/backingResourceAssociations/deleteDeletes a Network Security Perimeter Backing Resource AssociationNN
Microsoft.Network/networkSecurityPerimeters/backingResourceAssociations/writeCreates or Updates a Network Security Perimeter Backing Resource AssociationNN
Microsoft.Network/networkSecurityPerimeters/deleteDeletes a Network Security PerimeterNN
Microsoft.Network/networkSecurityPerimeters/joinPerimeterRule/actionJoins an NSP Access RuleNN
Microsoft.Network/networkSecurityPerimeters/linkPerimeter/actionLink Perimeter in Auto-Approval modeNN
Microsoft.Network/networkSecurityPerimeters/linkProxies/writeUpdates a Network Security Perimeter Link ProxyNN
Microsoft.Network/networkSecurityPerimeters/linkReferenceProxies/writeCreates or Updates a Network Security Perimeter LinkReference ProxyNN
Microsoft.Network/networkSecurityPerimeters/linkReferences/deleteDeletes a Network Security Perimeter LinkReferenceNN
Microsoft.Network/networkSecurityPerimeters/linkReferences/reconcile/actionReconciles a Network Security Perimeter LinkReferenceNN
Microsoft.Network/networkSecurityPerimeters/linkReferences/writeCreates or Updates a Network Security Perimeter LinkReferenceNN
Microsoft.Network/networkSecurityPerimeters/links/deleteDeletes a Network Security Perimeter LinkNN
Microsoft.Network/networkSecurityPerimeters/links/writeCreates or Updates a Network Security Perimeter LinkNN
Microsoft.Network/networkSecurityPerimeters/loggingConfigurations/deleteDeletes a Network Security Perimeter Logging ConfigurationNN
Microsoft.Network/networkSecurityPerimeters/loggingConfigurations/writeCreates or Updates a Network Security Perimeter Logging ConfigurationNN
Microsoft.Network/networkSecurityPerimeters/profiles/accessRules/deleteDeletes a Network Security Perimeter Access RuleNN
Microsoft.Network/networkSecurityPerimeters/profiles/accessRules/writeCreates or Updates a Network Security Perimeter Access RuleNN
Microsoft.Network/networkSecurityPerimeters/profiles/checkMembers/actionChecks if members can be accessed or notNN
Microsoft.Network/networkSecurityPerimeters/profiles/deleteDeletes a Network Security Perimeter ProfileNN
Microsoft.Network/networkSecurityPerimeters/profiles/join/actionJoins a Network Security Perimeter ProfileNN
Microsoft.Network/networkSecurityPerimeters/profiles/writeCreates or Updates a Network Security Perimeter ProfileNN
Microsoft.Network/networkSecurityPerimeters/resourceAssociationProxies/deleteDeletes a Network Security Perimeter Resource Association ProxyNN
Microsoft.Network/networkSecurityPerimeters/resourceAssociationProxies/writeCreates or Updates a Network Security Perimeter Resource Association ProxyNN
Microsoft.Network/networkSecurityPerimeters/resourceAssociations/deleteDeletes a Network Security Perimeter Resource AssociationNN
Microsoft.Network/networkSecurityPerimeters/resourceAssociations/writeCreates or Updates a Network Security Perimeter Resource AssociationNN
Microsoft.Network/networkSecurityPerimeters/writeCreates or Updates a Network Security PerimeterNN
Microsoft.Network/networkVerifiers/analysisIntents/analysisRuns/deleteDeletes a Analysis RunNN
Microsoft.Network/networkVerifiers/analysisIntents/analysisRuns/writeCreates or Updates a Analysis RunNN
Microsoft.Network/networkVerifiers/analysisIntents/deleteDeletes a Analysis IntentNN
Microsoft.Network/networkVerifiers/analysisIntents/writeCreates or Updates a Analysis IntentNN
Microsoft.Network/networkVerifiers/configurationSnapshots/deleteDeletes a Configuration SnapshotNN
Microsoft.Network/networkVerifiers/configurationSnapshots/writeCreates or Updates a Configuration SnapshotNN
Microsoft.Network/networkVerifiers/deleteDeletes a Network VerifierNN
Microsoft.Network/networkVerifiers/writeCreates or Updates a Network VerifierNN
Microsoft.Network/networkVirtualAppliances/deleteDelete a Network Virtual ApplianceNY
Microsoft.Network/networkVirtualAppliances/getBootDiagnosticLogs/actionGet Network Virtual Appliance Boot Diagnostic LogsNN
Microsoft.Network/networkVirtualAppliances/getDelegatedSubnets/actionGet Network Virtual Appliance delegated subnetsNN
Microsoft.Network/networkVirtualAppliances/getVmssResourceId/actionGet VMSS Resource IDNN
Microsoft.Network/networkVirtualAppliances/inboundSecurityRules/deleteDelete a InboundSecurityRuleNN
Microsoft.Network/networkVirtualAppliances/inboundSecurityRules/writeCreate or update a InboundSecurityRuleNN
Microsoft.Network/networkVirtualAppliances/networkVirtualApplianceConnections/deleteDelete a Network Virtual Appliance ConnectionNN
Microsoft.Network/networkVirtualAppliances/networkVirtualApplianceConnections/writeUpdate a Network Virtual Appliance ConnectionNN
Microsoft.Network/networkVirtualAppliances/reimage/actionReimage Network Virtual ApplianceNN
Microsoft.Network/networkVirtualAppliances/restart/actionRestart Network Virtual ApplianceNN
Microsoft.Network/networkVirtualAppliances/writeCreate or update a Network Virtual ApplianceNY
Microsoft.Network/networkWatchers/agents/deleteDeletes a Network Watcher AgentNN
Microsoft.Network/networkWatchers/agents/register/actionRegisters a network watcher agentNN
Microsoft.Network/networkWatchers/agents/writeCreates a Network Watcher AgentNN
Microsoft.Network/networkWatchers/availableProvidersList/actionReturns all available internet service providers for a specified Azure region.NN
Microsoft.Network/networkWatchers/azureReachabilityReport/actionReturns the relative latency score for internet service providers from a specified location to Azure regions.NN
Microsoft.Network/networkWatchers/configureFlowLog/actionConfigures flow logging for a target resource.NN
Microsoft.Network/networkWatchers/connectionAnalyzers/deleteDeletes a Connection AnalyzerNN
Microsoft.Network/networkWatchers/connectionAnalyzers/queryStatus/actionQuery status and details of Connection AnalyzerNN
Microsoft.Network/networkWatchers/connectionAnalyzers/writeCreates a Connection AnalyzerNN
Microsoft.Network/networkWatchers/connectionMonitors/deleteDeletes a Connection MonitorNN
Microsoft.Network/networkWatchers/connectionMonitors/query/actionQuery monitoring connectivity between specified endpointsNN
Microsoft.Network/networkWatchers/connectionMonitors/start/actionStart monitoring connectivity between specified endpointsNN
Microsoft.Network/networkWatchers/connectionMonitors/stop/actionStop/pause monitoring connectivity between specified endpointsNN
Microsoft.Network/networkWatchers/connectionMonitors/writeCreates a Connection MonitorNN
Microsoft.Network/networkWatchers/connectivityCheck/actionVerifies the possibility of establishing a direct TCP connection from a virtual machine to a given endpoint including another VM or an arbitrary remote server.NN
Microsoft.Network/networkWatchers/deleteDeletes a network watcherNY
Microsoft.Network/networkWatchers/flowLogs/deleteDeletes a Flow LogNN
Microsoft.Network/networkWatchers/flowLogs/writeCreates a Flow LogNN
Microsoft.Network/networkWatchers/ipFlowVerify/actionReturns whether the packet is allowed or denied to or from a particular destination.NN
Microsoft.Network/networkWatchers/lenses/deleteDeletes a LensNN
Microsoft.Network/networkWatchers/lenses/query/actionQuery monitoring network traffic on a specified endpointNN
Microsoft.Network/networkWatchers/lenses/start/actionStart monitoring network traffic on a specified endpointNN
Microsoft.Network/networkWatchers/lenses/stop/actionStop/pause monitoring network traffic on a specified endpointNN
Microsoft.Network/networkWatchers/lenses/writeCreates a LensNN
Microsoft.Network/networkWatchers/networkConfigurationDiagnostic/actionDiagnostic of network configuration.NN
Microsoft.Network/networkWatchers/nextHop/actionFor a specified target and destination IP address, return the next hop type and next hope IP address.NN
Microsoft.Network/networkWatchers/packetCaptures/deleteDeletes a packet captureNN
Microsoft.Network/networkWatchers/packetCaptures/queryStatus/actionGets information about properties and status of a packet capture resource.NN
Microsoft.Network/networkWatchers/packetCaptures/stop/actionStop the running packet capture session.NN
Microsoft.Network/networkWatchers/packetCaptures/writeCreates a packet captureNN
Microsoft.Network/networkWatchers/pingMeshes/deleteDeletes a PingMeshNN
Microsoft.Network/networkWatchers/pingMeshes/start/actionStart PingMesh between specified VMsNN
Microsoft.Network/networkWatchers/pingMeshes/stop/actionStop PingMesh between specified VMsNN
Microsoft.Network/networkWatchers/pingMeshes/writeCreates a PingMeshNN
Microsoft.Network/networkWatchers/queryConnectionMonitors/actionBatch query monitoring connectivity between specified endpointsNN
Microsoft.Network/networkWatchers/queryFlowLogStatus/actionGets the status of flow logging on a resource.NN
Microsoft.Network/networkWatchers/queryTroubleshootResult/actionGets the troubleshooting result from the previously run or currently running troubleshooting operation.NN
Microsoft.Network/networkWatchers/securityGroupView/actionView the configured and effective network security group rules applied on a VM.NN
Microsoft.Network/networkWatchers/topology/actionGets a network level view of resources and their relationships in a resource group.NN
Microsoft.Network/networkWatchers/troubleshoot/actionStarts troubleshooting on a Networking resource in Azure.NN
Microsoft.Network/networkWatchers/writeCreates a network watcher or updates an existing network watcherYN
microsoft.network/p2sVpnGateways/attach/actionAttaches a P2SVpnGateway Hub from WAN Traffic managerNN
Microsoft.Network/p2sVpnGateways/deleteDeletes a P2SVpnGateway.NY
microsoft.network/p2sVpnGateways/detach/actionDetaches a P2SVpnGateway Hub from WAN Traffic managerNN
Microsoft.Network/p2sVpnGateways/disconnectp2svpnconnections/actionDisconnect p2s vpn connectionsNY
Microsoft.Network/p2sVpnGateways/generatevpnprofile/actionGenerate Vpn Profile for P2SVpnGatewayNY
Microsoft.Network/p2sVpnGateways/getp2svpnconnectionhealth/actionGets a P2S Vpn Connection health for P2SVpnGatewayNN
Microsoft.Network/p2sVpnGateways/getp2svpnconnectionhealthdetailed/actionGets a P2S Vpn Connection health detailed for P2SVpnGatewayNN
Microsoft.Network/p2sVpnGateways/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the P2S Vpn Gateway diagnostic settings, this operation is supplemented by insights resource provider.NY
microsoft.network/p2sVpnGateways/reset/actionResets a P2SVpnGatewayNY
Microsoft.Network/p2sVpnGateways/writePuts a P2SVpnGateway.NY
Microsoft.Network/privateDnsZones/A/deleteRemove the record set of a given name and type 'A' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/A/writeCreate or update a record set of type 'A' within a Private DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/privateDnsZones/AAAA/deleteRemove the record set of a given name and type 'AAAA' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/AAAA/writeCreate or update a record set of type 'AAAA' within a Private DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/privateDnsZones/CNAME/deleteRemove the record set of a given name and type 'CNAME' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/CNAME/writeCreate or update a record set of type 'CNAME' within a Private DNS zone.NN
Microsoft.Network/privateDnsZones/deleteDelete a Private DNS zone.YN
Microsoft.Network/privateDnsZones/join/actionJoins a Private DNS ZoneNN
Microsoft.Network/privateDnsZones/MX/deleteRemove the record set of a given name and type 'MX' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/MX/writeCreate or update a record set of type 'MX' within a Private DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/privateDnsZones/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the Private DNS zone diagnostic settingsNN
Microsoft.Network/privateDnsZones/PTR/deleteRemove the record set of a given name and type 'PTR' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/PTR/writeCreate or update a record set of type 'PTR' within a Private DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/privateDnsZones/SOA/writeUpdate a record set of type 'SOA' within a Private DNS zone.NN
Microsoft.Network/privateDnsZones/SRV/deleteRemove the record set of a given name and type 'SRV' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/SRV/writeCreate or update a record set of type 'SRV' within a Private DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/privateDnsZones/TXT/deleteRemove the record set of a given name and type 'TXT' from a Private DNS zone.NN
Microsoft.Network/privateDnsZones/TXT/writeCreate or update a record set of type 'TXT' within a Private DNS zone. The records specified will replace the current records in the record set.NN
Microsoft.Network/privateDnsZones/virtualNetworkLinks/deleteDelete a Private DNS zone link to virtual network.YN
Microsoft.Network/privateDnsZones/virtualNetworkLinks/writeCreate or update a Private DNS zone link to virtual network.YN
Microsoft.Network/privateDnsZones/writeCreate or update a Private DNS zone within a resource group. Note that this command cannot be used to create or update virtual network links or record sets within the zone.YN
Microsoft.Network/privateDnsZonesInternal/actionExecutes Private DNS Zones Internal APIsNN
Microsoft.Network/privateEndpointRedirectMaps/writeCreates Private Endpoint RedirectMap Or Updates An Existing Private Endpoint RedirectMapNN
Microsoft.Network/privateEndpoints/deleteDeletes an private endpoint resource.NN
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/deleteDeletes a Private DNS Zone GroupNN
Microsoft.Network/privateEndpoints/privateDnsZoneGroups/writePuts a Private DNS Zone GroupNN
Microsoft.Network/privateEndpoints/privateLinkServiceProxies/deleteDeletes an private link service proxy resource.NN
Microsoft.Network/privateEndpoints/privateLinkServiceProxies/writeCreates a new private link service proxy, or updates an existing private link service proxy.NN
Microsoft.Network/privateEndpoints/pushPropertiesToResource/actionOperation to push private endpoint property updates from NRP clientNN
Microsoft.Network/privateEndpoints/writeCreates a new private endpoint, or updates an existing private endpoint.NN
Microsoft.Network/privateLinkServices/deleteDeletes an private link service resource.NN
Microsoft.Network/privateLinkServices/notifyPrivateEndpointMove/actionNotifies a connected Private Link Service of Private Endpoint moveNN
Microsoft.Network/privateLinkServices/privateEndpointConnectionProxies/deleteDeletes an private endpoint connection proxy resource.NN
Microsoft.Network/privateLinkServices/privateEndpointConnectionProxies/writeCreates a new private endpoint connection proxy, or updates an existing private endpoint connection proxy.NN
Microsoft.Network/privateLinkServices/privateEndpointConnections/deleteDeletes an private endpoint connection.NN
Microsoft.Network/privateLinkServices/privateEndpointConnections/writeCreates a new private endpoint connection, or updates an existing private endpoint connection.NN
Microsoft.Network/privateLinkServices/PrivateEndpointConnectionsApproval/actionApprove or reject PrivateEndpoint connection on PrivateLinkServiceNN
Microsoft.Network/privateLinkServices/writeCreates a new private link service, or updates an existing private link service.NN
Microsoft.Network/publicIPAddresses/ddosProtectionStatus/actionGets the effective Ddos protection status for a Public IP Address resource.NN
Microsoft.Network/publicIPAddresses/deleteDeletes a public IP address.YN
Microsoft.Network/publicIPAddresses/dnsAliases/deleteDeletes a Public IP Address Dns Alias resourceNN
Microsoft.Network/publicIPAddresses/dnsAliases/writeCreates a Public IP Address Dns Alias resourceNN
Microsoft.Network/publicIPAddresses/join/actionJoins a public IP address. Not Alertable.NN
Microsoft.Network/publicIPAddresses/joinServiceEndpointNetworkIdentifier/actionJoins a Public Ip Address Service Endpoint Network IdentifierNN
Microsoft.Network/publicIPAddresses/providers/Microsoft.Insights/diagnosticSettings/writeCreate or update the diagnostic settings of Public IP AddressNN
Microsoft.Network/publicIPAddresses/writeCreates a public IP address or updates an existing public IP address.YY
Microsoft.Network/publicIPPrefixes/deleteDeletes A Public Ip PrefixYN
Microsoft.Network/publicIPPrefixes/join/actionJoins a PublicIPPrefix. Not alertable.NN
Microsoft.Network/publicIPPrefixes/writeCreates A Public Ip Prefix Or Updates An Existing Public Ip PrefixYN
Microsoft.Network/queryExpressRoutePortsBandwidth/actionQuery ExpressRoute Ports BandwidthNN
Microsoft.Network/register/actionRegisters the subscriptionYN
Microsoft.Network/routeFilters/deleteDeletes a route filter definitionYN
Microsoft.Network/routeFilters/join/actionJoins a route filter. Not Alertable.NN
Microsoft.Network/routeFilters/routeFilterRules/deleteDeletes a route filter rule definitionNN
Microsoft.Network/routeFilters/routeFilterRules/writeCreates a route filter rule or Updates an existing route filter ruleNN
Microsoft.Network/routeFilters/writeCreates a route filter or Updates an existing route filterYN
Microsoft.Network/routeTables/deleteDeletes a route table definitionYN
Microsoft.Network/routeTables/join/actionJoins a route table. Not Alertable.NN
Microsoft.Network/routeTables/routes/deleteDeletes a route definitionNN
Microsoft.Network/routeTables/routes/writeCreates a route or Updates an existing routeNN
Microsoft.Network/routeTables/writeCreates a route table or Updates an existing route tableYN
Microsoft.Network/securityPartnerProviders/deleteDeletes a SecurityPartnerProviderNN
Microsoft.Network/securityPartnerProviders/join/actionJoins a SecurityPartnerProvider. Not alertable.NN
Microsoft.Network/securityPartnerProviders/updateReferences/actionUpdate references in a SecurityPartnerProviderNN
Microsoft.Network/securityPartnerProviders/validate/actionValidates a SecurityPartnerProviderNN
Microsoft.Network/securityPartnerProviders/writeCreates a SecurityPartnerProvider or Updates An Existing SecurityPartnerProviderNN
Microsoft.Network/serviceEndpointPolicies/deleteDeletes a Service Endpoint PolicyYN
Microsoft.Network/serviceEndpointPolicies/join/actionJoins a Service Endpoint Policy. Not alertable.NN
Microsoft.Network/serviceEndpointPolicies/joinSubnet/actionJoins a Subnet To Service Endpoint Policies. Not alertable.NN
Microsoft.Network/serviceEndpointPolicies/serviceEndpointPolicyDefinitions/deleteDeletes a Service Endpoint Policy DefinitionNN
Microsoft.Network/serviceEndpointPolicies/serviceEndpointPolicyDefinitions/writeCreates a Service Endpoint Policy Definition or updates an existing Service Endpoint Policy DefinitionNN
Microsoft.Network/serviceEndpointPolicies/writeCreates a Service Endpoint Policy or updates an existing Service Endpoint PolicyYN
Microsoft.Network/trafficManagerProfiles/azureEndpoints/deleteDeletes an Azure Endpoint from an existing Traffic Manager Profile. Traffic Manager will stop routing traffic to the deleted Azure Endpoint.NN
Microsoft.Network/trafficManagerProfiles/azureEndpoints/writeAdd a new Azure Endpoint in an existing Traffic Manager Profile or update the properties of an existing Azure Endpoint in that Traffic Manager Profile.NN
Microsoft.Network/trafficManagerProfiles/deleteDelete the Traffic Manager profile. All settings associated with the Traffic Manager profile will be lost, and the profile can no longer be used to route traffic.YN
Microsoft.Network/trafficManagerProfiles/externalEndpoints/deleteDeletes an External Endpoint from an existing Traffic Manager Profile. Traffic Manager will stop routing traffic to the deleted External Endpoint.NN
Microsoft.Network/trafficManagerProfiles/externalEndpoints/writeAdd a new External Endpoint in an existing Traffic Manager Profile or update the properties of an existing External Endpoint in that Traffic Manager Profile.NN
Microsoft.Network/trafficManagerProfiles/nestedEndpoints/deleteDeletes an Nested Endpoint from an existing Traffic Manager Profile. Traffic Manager will stop routing traffic to the deleted Nested Endpoint.NN
Microsoft.Network/trafficManagerProfiles/nestedEndpoints/writeAdd a new Nested Endpoint in an existing Traffic Manager Profile or update the properties of an existing Nested Endpoint in that Traffic Manager Profile.NN
Microsoft.Network/trafficManagerProfiles/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the Traffic Manager diagnostic settings, this operation is supplemented by insights resource provider.NN
Microsoft.Network/trafficManagerProfiles/validateLink/actionEstablishes a link between a DNS record and a Traffic Manager Profile so that the traffic manager profile can't be removed while it is being referenced by the dns recordNN
Microsoft.Network/trafficManagerProfiles/writeCreate a Traffic Manager profile, or modify the configuration of an existing Traffic Manager profile.<br>This includes enabling or disabling a profile and modifying DNS settings, traffic routing settings, or endpoint monitoring settings.<br>Endpoints routed by the Traffic Manager profile can be added, removed, enabled or disabled.YN
Microsoft.Network/trafficManagerUserMetricsKeys/deleteDeletes the subscription-level key used for Realtime User Metrics collection.NN
Microsoft.Network/trafficManagerUserMetricsKeys/writeCreates a new subscription-level key to be used for Realtime User Metrics collection.NN
Microsoft.Network/unregister/actionUnregisters the subscriptionNN
Microsoft.Network/virtualHubs/bgpConnections/advertisedRoutes/actionGets virtualrouter advertised routesNN
Microsoft.Network/virtualHubs/bgpConnections/deleteDeletes a Hub Bgp Connection child resource of Virtual HubNN
Microsoft.Network/virtualHubs/bgpConnections/learnedRoutes/actionGets virtualrouter learned routesNN
Microsoft.Network/virtualHubs/bgpConnections/writeCreates or Updates a Hub Bgp Connection child resource of Virtual HubNN
Microsoft.Network/virtualHubs/connectionPolicies/deleteDeletes Connection Policy child resource of Virtual HubNN
Microsoft.Network/virtualHubs/connectionPolicies/writeCreates or Updates Connection Policy child resource of Virtual HubNN
Microsoft.Network/virtualHubs/deleteDeletes a Virtual HubNY
Microsoft.Network/virtualHubs/effectiveRoutes/actionGets effective route configured on Virtual HubNN
Microsoft.Network/virtualHubs/hubRouteTables/deleteDeletes a Route Table child resource of Virtual HubNN
Microsoft.Network/virtualHubs/hubRouteTables/writeCreates or Updates a Route Table child resource of Virtual HubNN
Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/deleteDeletes a HubVirtualNetworkConnectionNN
Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/writeCreate or update a HubVirtualNetworkConnectionNN
Microsoft.Network/virtualHubs/inboundRoutes/actionGets routes learnt from a virtual wan connectionNN
Microsoft.Network/virtualHubs/ipConfigurations/deleteDeletes a Hub IpConfiguration child resource of Virtual HubNN
Microsoft.Network/virtualHubs/ipConfigurations/writeCreates or Updates a Hub IpConfiguration child resource of Virtual HubNN
Microsoft.Network/virtualHubs/migrateRouteService/actionValidate or execute the hub router migrationNN
Microsoft.Network/virtualHubs/outboundRoutes/actionGet Routes advertised by a virtual wan connectionNN
Microsoft.Network/virtualHubs/routeMaps/deleteDeletes a Route Map child resource of Virtual HubNN
Microsoft.Network/virtualHubs/routeMaps/writeCreates or Updates a Route Map child resource of Virtual HubNN
Microsoft.Network/virtualHubs/routeTables/deleteDelete a VirtualHubRouteTableV2NN
Microsoft.Network/virtualHubs/routeTables/writeCreate or Update a VirtualHubRouteTableV2NN
Microsoft.Network/virtualHubs/routingIntent/deleteDeletes a Routing Intent child resource of Virtual HubNN
Microsoft.Network/virtualHubs/routingIntent/writeCreates or Updates a Routing Intent child resource of Virtual HubNN
Microsoft.Network/virtualHubs/writeCreate or update a Virtual HubNY
Microsoft.Network/virtualNetworkAppliances/deleteDelete Virtual Network ApplianceNN
Microsoft.Network/virtualNetworkAppliances/writeCreate or update Virtual Network ApplianceNN
microsoft.network/virtualnetworkgateways/abortMigration/actionAbort Migrate Virtual Network Gateway OperationNN
microsoft.network/virtualnetworkgateways/commitMigration/actionCommit Migrate Virtual Network Gateway OperationNN
Microsoft.Network/virtualNetworkGateways/deleteDeletes a virtualNetworkGatewayNN
microsoft.network/virtualnetworkgateways/disconnectvirtualnetworkgatewayvpnconnections/actionDisconnect virtual network gateway vpn connectionsNN
microsoft.network/virtualnetworkgateways/executeMigration/actionExecute Migrate Virtual Network Gateway OperationNN
microsoft.network/virtualnetworkgateways/generatevpnclientpackage/actionGenerate VpnClient package for virtualNetworkGatewayNN
microsoft.network/virtualnetworkgateways/generatevpnprofile/actionGenerate VpnProfile package for VirtualNetworkGatewayNN
microsoft.network/virtualnetworkgateways/getadvertisedroutes/actionGets virtualNetworkGateway advertised routesNN
microsoft.network/virtualnetworkgateways/getbgppeerstatus/actionGets virtualNetworkGateway bgp peer statusNN
microsoft.network/virtualnetworkgateways/geteffectiveroutes/actionGets virtualnetworkgateway effective routesNN
microsoft.network/virtualnetworkgateways/getlearnedroutes/actionGets virtualnetworkgateway learned routesNN
microsoft.network/virtualnetworkgateways/getvpnclientconnectionhealth/actionGet Per Vpn Client Connection Health for VirtualNetworkGatewayNN
microsoft.network/virtualnetworkgateways/getvpnclientipsecparameters/actionGet Vpnclient Ipsec parameters for VirtualNetworkGateway P2S client.NN
microsoft.network/virtualnetworkgateways/getvpnprofilepackageurl/actionGets the URL of a pre-generated vpn client profile packageNN
microsoft.network/virtualnetworkgateways/listAllRadiusServersSecrets/actionList all VirtualNetworkGateway RadiusServer secretsNN
microsoft.network/virtualNetworkGateways/natRules/deleteDeletes a NAT rule resourceNN
microsoft.network/virtualNetworkGateways/natRules/writePuts a NAT rule resourceNN
microsoft.network/virtualnetworkgateways/prepareMigration/actionPrepare Migrate Virtual Network Gateway OperationNN
Microsoft.Network/virtualNetworkGateways/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the Virtual Network Gateway diagnostic settings, this operation is supplemented by insights resource provider.NN
microsoft.network/virtualnetworkgateways/reset/actionResets a virtualNetworkGatewayNN
microsoft.network/virtualnetworkgateways/resetvpnclientsharedkey/actionReset Vpnclient shared key for VirtualNetworkGateway P2S client.NN
microsoft.network/virtualnetworkgateways/setvpnclientipsecparameters/actionSet Vpnclient Ipsec parameters for VirtualNetworkGateway P2S client.NN
microsoft.network/virtualnetworkgateways/startpacketcapture/actionStarts a Virtual Network Gateway Packet Capture.NN
microsoft.network/virtualnetworkgateways/stoppacketcapture/actionStops a Virtual Network Gateway Packet Capture.NN
Microsoft.Network/virtualnetworkgateways/supportedvpndevices/actionLists Supported Vpn DevicesNN
Microsoft.Network/virtualNetworkGateways/writeCreates or updates a VirtualNetworkGatewayNN
Microsoft.Network/virtualNetworks/BastionHosts/actionGets Bastion Host references in a Virtual Network.NN
Microsoft.Network/virtualNetworks/bastionHosts/default/actionGets Bastion Host references in a Virtual Network.NN
Microsoft.Network/virtualNetworks/customViews/get/actionGet a Virtual Network custom view contentNN
Microsoft.Network/virtualNetworks/ddosProtectionStatus/actionGets the effective Ddos protection status for a Virtual Network resource.NN
Microsoft.Network/virtualNetworks/deleteDeletes a virtual networkYY
Microsoft.Network/virtualNetworks/join/actionJoins a virtual network. Not Alertable.NN
Microsoft.Network/virtualNetworks/joinLoadBalancer/actionJoins a load balancer to virtual networksNN
Microsoft.Network/virtualNetworks/listDnsForwardingRulesets/actionGets the DNS Forwarding Ruleset for Virtual Network, in JSON formatNN
Microsoft.Network/virtualNetworks/listDnsResolverPolicies/actionGets the DNS Resolver Policy associated with a Virtual Network, in JSON format.NN
Microsoft.Network/virtualNetworks/listDnsResolvers/actionGets the DNS Resolver for Virtual Network, in JSON formatNN
Microsoft.Network/virtualNetworks/listNetworkManagerEffectiveConnectivityConfigurations/actionLists Network Manager Effective Connectivity ConfigurationsNN
Microsoft.Network/virtualNetworks/listNetworkManagerEffectiveSecurityAdminRules/actionLists Network Manager Effective Security Admin RulesNN
Microsoft.Network/virtualNetworks/manageIpFromPool/actionManage Private Ip Inventory Pool Operation DescriptionNN
Microsoft.Network/virtualNetworks/moveIpConfigurations/actionMoves secondary IP configurations between resourcesNN
Microsoft.Network/virtualNetworks/peer/actionPeers a virtual network with another virtual networkNN
Microsoft.Network/virtualNetworks/providers/Microsoft.Insights/diagnosticSettings/writeCreate or update the diagnostic settings of the Virtual NetworkNN
Microsoft.Network/virtualNetworks/remoteVirtualNetworkPeeringProxies/deleteDeletes a virtual network peering proxyNN
Microsoft.Network/virtualNetworks/remoteVirtualNetworkPeeringProxies/writeCreates a virtual network peering proxy or updates an existing virtual network peering proxyNN
Microsoft.Network/virtualNetworks/removeAdminNetworkSecurityGroup/actionRemoves Admin Network Security Group Reference From Virtual NetworkNN
Microsoft.Network/virtualNetworks/rnmEffectiveNetworkSecurityGroups/actionGets Security Groups Configured On CA Of The Vnet In Rnm FormatNN
Microsoft.Network/virtualNetworks/rnmEffectiveRouteTable/actionGets RouteTables Configured On CA Of The Vnet In Rnm FormatNN
Microsoft.Network/virtualNetworks/setAdminNetworkSecurityGroup/actionSets Admin Network Security Group Reference On Virtual NetworkNN
Microsoft.Network/virtualNetworks/subnets/contextualServiceEndpointPolicies/deleteDeletes A Contextual Service Endpoint PolicyNN
Microsoft.Network/virtualNetworks/subnets/contextualServiceEndpointPolicies/writeCreates a Contextual Service Endpoint Policy or updates an existing Contextual Service Endpoint PolicyNN
Microsoft.Network/virtualNetworks/subnets/deleteDeletes a virtual network subnetNN
Microsoft.Network/virtualNetworks/subnets/join/actionJoins a virtual network. Not Alertable.NN
Microsoft.Network/virtualNetworks/subnets/joinLoadBalancer/actionJoins a load balancer to virtual network subnetsNN
Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/actionJoins resource such as storage account or SQL database to a subnet. Not alertable.NN
Microsoft.Network/virtualNetworks/subnets/prepareNetworkPolicies/actionPrepares a subnet by applying necessary Network PoliciesNN
Microsoft.Network/virtualNetworks/subnets/resourceNavigationLinks/deleteDeletes a Resource Navigation LinkNN
Microsoft.Network/virtualNetworks/subnets/resourceNavigationLinks/writeCreates a Resource Navigation Link or updates an existing Resource Navigation LinkNN
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/deleteDeletes a Service Association LinkNN
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/validate/actionValidates a Service Association LinkNN
Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/writeCreates a Service Association Link or updates an existing Service Association LinkNN
Microsoft.Network/virtualNetworks/subnets/unprepareNetworkPolicies/actionUnprepare a subnet by removing the applied Network PoliciesNN
Microsoft.Network/virtualNetworks/subnets/writeCreates a virtual network subnet or updates an existing virtual network subnetNN
Microsoft.Network/virtualNetworks/taggedTrafficConsumers/deleteDeletes a Tagged Traffic ConsumerNN
Microsoft.Network/virtualNetworks/taggedTrafficConsumers/validate/actionValidates a Tagged Traffic ConsumerNN
Microsoft.Network/virtualNetworks/taggedTrafficConsumers/writeCreates a Tagged Traffic Consumer or updates an existing Tagged Traffic ConsumerNN
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/deleteDeletes a virtual network peeringNN
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/writeCreates a virtual network peering or updates an existing virtual network peeringNN
Microsoft.Network/virtualNetworks/writeCreates a virtual network or updates an existing virtual networkYN
Microsoft.Network/virtualNetworkTaps/deleteDelete Virtual Network TapNN
Microsoft.Network/virtualNetworkTaps/join/actionJoins a virtual network tap. Not Alertable.NN
Microsoft.Network/virtualNetworkTaps/networkInterfaceTapConfigurationProxies/deleteDeletes a Network Interface Tap Configuration Proxy.NN
Microsoft.Network/virtualNetworkTaps/networkInterfaceTapConfigurationProxies/writeCreates a Network Interface Tap Configuration Proxy Or updates an existing Network Interface Tap Configuration Proxy.NN
Microsoft.Network/virtualNetworkTaps/writeCreate or Update Virtual Network TapNN
Microsoft.Network/virtualRouters/deleteDeletes A VirtualRouterNY
Microsoft.Network/virtualRouters/join/actionJoins A VirtualRouter. Not alertable.NN
Microsoft.Network/virtualRouters/peerings/deleteDeletes A VirtualRouterPeeringNN
Microsoft.Network/virtualRouters/peerings/writeCreates A VirtualRouterPeering or Updates An Existing VirtualRouterPeeringNN
Microsoft.Network/virtualRouters/writeCreates A VirtualRouter or Updates An Existing VirtualRouterNY
Microsoft.Network/virtualWans/deleteDeletes a Virtual WanYN
Microsoft.Network/virtualwans/generateVpnProfile/actionGenerate VirtualWanVpnServerConfiguration VpnProfileNN
Microsoft.Network/virtualWans/join/actionJoins a Virtual WAN. Not alertable.NN
Microsoft.network/virtualWans/p2sVpnServerConfigurations/deleteDeletes a virtual Wan P2SVpnServerConfigurationNN
Microsoft.network/virtualWans/p2sVpnServerConfigurations/writeCreates a virtual Wan P2SVpnServerConfiguration or updates an existing virtual Wan P2SVpnServerConfigurationNN
Microsoft.Network/virtualWans/updateVhubReferences/actionUpdate VirtualHub reference in VirtualWanNN
Microsoft.Network/virtualWans/updateVpnReferences/actionUpdate VPN reference in VirtualWanNN
Microsoft.Network/virtualWans/virtualHubProxies/deleteDeletes a Virtual Hub proxyNN
Microsoft.Network/virtualWans/virtualHubProxies/writeCreates a Virtual Hub proxy or updates a Virtual Hub proxyNN
Microsoft.Network/virtualwans/vpnconfiguration/actionGets a Vpn ConfigurationNN
Microsoft.Network/virtualwans/vpnServerConfigurations/actionGet VirtualWanVpnServerConfigurationsNN
Microsoft.Network/virtualWans/vpnSiteProxies/deleteDeletes a Vpn Site proxyNN
Microsoft.Network/virtualWans/vpnSiteProxies/writeCreates a Vpn Site proxy or updates a Vpn Site proxyNN
Microsoft.Network/virtualWans/writeCreate or update a Virtual WanYN
Microsoft.Network/vpnGateways/deleteDeletes a VpnGateway.NN
microsoft.network/vpngateways/getadvertisedroutes/actionGets advertised routes of a VpnGatewayNN
microsoft.network/vpngateways/getbgppeerstatus/actionGets bgp peer status of a VpnGatewayNN
microsoft.network/vpngateways/getlearnedroutes/actionGets learned routes of a VpnGatewayNN
microsoft.network/vpngateways/listvpnconnectionshealth/actionGets connection health for all or a subset of connections on a VpnGatewayNN
microsoft.network/vpnGateways/natRules/deleteDeletes a NAT rule resourceNN
microsoft.network/vpnGateways/natRules/writePuts a NAT rule resourceNN
Microsoft.Network/vpnGateways/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the Vpn Gateway diagnostic settings, this operation is supplemented by insights resource provider.NN
microsoft.network/vpngateways/reset/actionResets a VpnGatewayNN
microsoft.network/vpngateways/startpacketcapture/actionStart Vpn gateway Packet Capture with according resourceNN
microsoft.network/vpngateways/stoppacketcapture/actionStop Vpn gateway Packet Capture with sasURLNN
microsoft.network/vpnGateways/vpnConnections/deleteDeletes a VpnConnection.NY
microsoft.network/vpnGateways/vpnConnections/startpacketcapture/actionStart packet capture for selected linked in vpn connectionNN
microsoft.network/vpnGateways/vpnConnections/stoppacketcapture/actionStop packet capture for selected linked in vpn connectionNN
microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/getikesas/actionLists Vpn Link Connection IKE Security AssociationsNN
microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/resetconnection/actionResets connection for vWANNN
microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/sharedKeys/default/listSharedKey/actionGets Vpn Link Connection Shared KeyNN
microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/sharedKeys/default/writePuts Vpn Link Connection Shared KeyNN
microsoft.network/vpnGateways/vpnConnections/writePuts a VpnConnection.NY
Microsoft.Network/vpnGateways/writePuts a VpnGateway.NN
microsoft.network/vpnServerConfigurations/configurationPolicyGroups/deleteDeletes a Configuration Policy GroupNN
Microsoft.Network/vpnServerConfigurations/configurationPolicyGroups/p2sConnectionConfigurationProxies/deleteDeletes A P2S Connection Configuration ProxyNN
Microsoft.Network/vpnServerConfigurations/configurationPolicyGroups/p2sConnectionConfigurationProxies/writeCreates A P2S Connection Configuration Proxy Or Updates An Existing P2S Connection Configuration ProxyNN
microsoft.network/vpnServerConfigurations/configurationPolicyGroups/writePuts a Configuration Policy GroupNN
Microsoft.Network/vpnServerConfigurations/deleteDelete VpnServerConfigurationNN
microsoft.network/vpnServerConfigurations/listAllRadiusServersSecrets/actionList all VpnServerConfiguration RadiusServer secretsNN
Microsoft.Network/vpnServerConfigurations/p2sVpnGatewayProxies/deleteDeletes a P2SVpnGateway ProxyNN
Microsoft.Network/vpnServerConfigurations/p2sVpnGatewayProxies/writeCreates a P2SVpnGateway Proxy or updates a P2SVpnGateway ProxyNN
Microsoft.Network/vpnServerConfigurations/writeCreate or Update VpnServerConfigurationNN
Microsoft.Network/vpnsites/deleteDeletes a Vpn Site resource.NN
Microsoft.Network/vpnsites/writeCreates or updates a Vpn Site resource.NN
Microsoft.Network/azureserviceconnectioncontrollers/deleteDelete Azure Service Connection ControllerNN
Microsoft.Network/azureserviceconnectioncontrollers/writeCreate Or Update Azure Service Connection ControllerNN
Microsoft.Network/expressRouteCircuits/routeTable/actionGet MultiCloud Circuit Route TableNN
Microsoft.Network/firewallPolicies/kubeSelectorGroups/deleteDelete Firewall Policy Kube Selector GroupNN
Microsoft.Network/firewallPolicies/kubeSelectorGroups/writeCreate or Update Firewall Policy Kube Selector GroupNN
Microsoft.Network/firstPartyServiceTags/join/actionJoin First Party Service TagNN
Microsoft.Network/interconnectGroups/nodeAvailability/actionGet InterconnectGroup Node AvailabilityNN
Microsoft.Network/networkWatchers/packetCaptures/queryInsight/actionQuery Packet Capture InsightNN
Microsoft.Network/networkWatchers/packetCaptures/startInsight/actionStart Packet Capture InsightNN
Microsoft.Network/networkWatchers/trafficAnalytics/deleteDelete Traffic AnalyticsNN
Microsoft.Network/networkWatchers/trafficAnalytics/writeCreate Traffic AnalyticsNN
Microsoft.Network/privateEndpoints/copy/actionCopy an private endpoint.NN
Microsoft.Network/privatetrafficmanagerprofiles/deleteDelete a Private Traffic Manager ProfileNN
Microsoft.Network/privatetrafficmanagerprofiles/endpoints/deleteDelete a Private Traffic Manager Profile EndpointNN
Microsoft.Network/privatetrafficmanagerprofiles/endpoints/writeCreate Or Update a Private Traffic Manager Profile EndpointNN
Microsoft.Network/privatetrafficmanagerprofiles/healthPolicies/deleteDelete a Private Traffic Manager Profile Health PolicyNN
Microsoft.Network/privatetrafficmanagerprofiles/healthPolicies/writeCreate Or Update a Private Traffic Manager Profile Health PolicyNN
Microsoft.Network/privatetrafficmanagerprofiles/validateLink/actionEstablishes a link between a Private DNS record and a Private Traffic Manager ProfileNN
Microsoft.Network/privatetrafficmanagerprofiles/writeCreate Or Update a Private Traffic Manager ProfileNN
Microsoft.Network/probinggateways/deleteDelete a Probing GatewayNN
Microsoft.Network/probinggateways/writeCreate Or Update a Probing GatewayNN
Microsoft.Network/topologymaps/deleteDelete a Topology MapNN
Microsoft.Network/topologymaps/sites/deleteDelete a Topology Map SiteNN
Microsoft.Network/topologymaps/sites/writeCreate Or Update a Topology Map SiteNN
Microsoft.Network/topologymaps/writeCreate Or Update a Topology MapNN
Microsoft.Network/virtualNetworks/subnets/getNetworkPolicies/actionGet Subnet Network Intent PoliciesNN

any: Azure Network (catch-all)

#
Namespace
Microsoft.Network

Description

Catch-all for Azure-Microsoft.Network rules that match the resource provider but no specific operation.

Microsoft.Network/adminNetworkSecurityGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes Admin Network Security Group

Microsoft.Network/adminNetworkSecurityGroups/write

#
Namespace
Microsoft.Network

Description

Creates or Updates Existing Admin Network Security Group

Microsoft.Network/applicationGateways/applicationGatewayHealth/action

#
Namespace
Microsoft.Network

Description

Gets an application gateway resource health

Microsoft.Network/applicationGateways/appProtectPolicy/attachAppProtectPolicy/action

#
Namespace
Microsoft.Network

Description

Attaches AppProtect policy to application gateway at global, path and/or listener level

Microsoft.Network/applicationGateways/appProtectPolicy/detachAppProtectPolicy/action

#
Namespace
Microsoft.Network

Description

Detaches AppProtect policy from application gateway at global, path and/or listener level

Microsoft.Network/applicationGateways/appProtectPolicy/getAppProtectPolicy/action

#
Namespace
Microsoft.Network

Description

Get AppProtect policy attached to application gateway resource

Microsoft.Network/applicationGateways/backendAddressPools/join/action

#
Namespace
Microsoft.Network

Description

Joins an application gateway backend address pool. Not Alertable.

Microsoft.Network/applicationGateways/backendhealth/action

#
Namespace
Microsoft.Network

Description

Gets an application gateway backend health

Microsoft.Network/applicationGateways/commitMigration/action

#
Namespace
Microsoft.Network

Description

Commit application gateway migration

Microsoft.Network/applicationGateways/delete

#
Namespace
Microsoft.Network

Description

Deletes an application gateway

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/applicationGateways/effectiveNetworkSecurityGroups/action

#
Namespace
Microsoft.Network

Description

Get Route Table configured On Application Gateway

Microsoft.Network/applicationGateways/effectiveRouteTable/action

#
Namespace
Microsoft.Network

Description

Get Route Table configured On Application Gateway

Microsoft.Network/applicationGateways/executeMigration/action

#
Namespace
Microsoft.Network

Description

Execute application gateway migration

Microsoft.Network/applicationGateways/getBackendHealthOnDemand/action

#
Namespace
Microsoft.Network

Description

Gets an application gateway backend health on demand for given http setting and backend pool

Microsoft.Network/applicationGateways/getListenerCertificateMetadata/action

#
Namespace
Microsoft.Network

Description

Gets an application gateway listener certificate metadata

Microsoft.Network/applicationGateways/getMigrationStatus/action

#
Namespace
Microsoft.Network

Description

Get Status Of Migrate Application Gateway From V1 sku To V2 sku

Microsoft.Network/applicationGateways/migrateV1ToV2/action

#
Namespace
Microsoft.Network

Description

Migrate Application Gateway from v1 sku to v2 sku

Microsoft.Network/applicationGateways/prepareMigration/action

#
Namespace
Microsoft.Network

Description

Prepare application gateway migration

Microsoft.Network/applicationGateways/privateEndpointConnections/delete

#
Namespace
Microsoft.Network

Description

Deletes Application Gateway PrivateEndpoint Connection

Microsoft.Network/applicationGateways/privateEndpointConnections/write

#
Namespace
Microsoft.Network

Description

Updates Application Gateway PrivateEndpoint Connection

Microsoft.Network/applicationGateways/resolvePrivateLinkServiceId/action

#
Namespace
Microsoft.Network

Description

Resolves privateLinkServiceId for application gateway private link resource

Microsoft.Network/applicationGateways/restart/action

#
Namespace
Microsoft.Network

Description

Restarts an application gateway

Microsoft.Network/applicationGateways/setSecurityCenterConfiguration/action

#
Namespace
Microsoft.Network

Description

Sets Application Gateway Security Center Configuration

Microsoft.Network/applicationGateways/start/action

#
Namespace
Microsoft.Network

Description

Starts an application gateway

Microsoft.Network/applicationGateways/stop/action

#
Namespace
Microsoft.Network

Description

Stops an application gateway

Microsoft.Network/applicationGateways/v1tov2Migration/action

#
Namespace
Microsoft.Network

Description

Application Gateway V1 to V2 Migration Operation

Microsoft.Network/applicationGateways/write

#
Namespace
Microsoft.Network

Description

Creates an application gateway or updates an application gateway

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/attachWafPolicyToAgc/action

#
Namespace
Microsoft.Network

Description

Attaches Web application firewall policy to application gateway for containers

Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes an Application Gateway WAF policy

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "action": "Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "action": "Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "a0e3c1d8-a394-4aa6-a136-ecb4b7eca5a0",
  "EventDataId": "1262f29d-57fd-0846-a943-dc39d97bc07d",
  "EventSubmissionTimestamp": "2026-07-02T18:25:16.1303936Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/APPLICATIONGATEWAYWEBAPPLICATIONFIREWALLPOLICIES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "message": "Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1262f29d-57fd-0846-a943-dc39d97bc07d",
    "eventSubmissionTimestamp": "2026-07-02T18:25:16.1303936Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afapplicationgat",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "message": "Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1262f29d-57fd-0846-a943-dc39d97bc07d",
    "eventSubmissionTimestamp": "2026-07-02T18:25:16.1303936Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afapplicationgat",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/detachWafPolicyFromAgc/action

#
Namespace
Microsoft.Network

Description

Detaches Web application firewall policy from application gateway for containers

Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/join/action

#
Namespace
Microsoft.Network

Description

Join Application Gateway Web Application Firewall Policy. Not alertable

Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/write

#
Namespace
Microsoft.Network

Description

Creates an Application Gateway WAF policy or updates an Application Gateway WAF policy

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "action": "Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "action": "Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "45495173-f6d9-4456-a9fa-dffda00c502f",
  "EventDataId": "7b5ab62c-bca6-82e6-db89-9d14a6fd8682",
  "EventSubmissionTimestamp": "2026-07-02T18:23:15.1524609Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/APPLICATIONGATEWAYWEBAPPLICATIONFIREWALLPOLICIES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "message": "Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7b5ab62c-bca6-82e6-db89-9d14a6fd8682",
    "eventSubmissionTimestamp": "2026-07-02T18:23:15.1524609Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afapplicationgat",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/dwh2220afapplicationgat",
    "message": "Microsoft.Network/applicationGatewayWebApplicationFirewallPolicies/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7b5ab62c-bca6-82e6-db89-9d14a6fd8682",
    "eventSubmissionTimestamp": "2026-07-02T18:23:15.1524609Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afapplicationgat",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/applicationSecurityGroups/addressPrefixSets/delete

#
Namespace
Microsoft.Network

Description

Deletes an Address Prefix Set

Microsoft.Network/applicationSecurityGroups/addressPrefixSets/write

#
Namespace
Microsoft.Network

Description

Creates an address prefix set or updates an existing address prefix set

Microsoft.Network/applicationSecurityGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes an Application Security Group

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/dwh92eef0asg",
    "action": "Microsoft.Network/applicationSecurityGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/dwh92eef0asg",
    "action": "Microsoft.Network/applicationSecurityGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "afc938e3-dbe2-4333-9fe3-7f95bd703877",
  "EventDataId": "95c98185-5696-c93e-e8d1-c56a3076a522",
  "EventSubmissionTimestamp": "2026-07-02T17:14:58.6910678Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/APPLICATIONSECURITYGROUPS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/dwh92eef0asg",
    "message": "Microsoft.Network/applicationSecurityGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "95c98185-5696-c93e-e8d1-c56a3076a522",
    "eventSubmissionTimestamp": "2026-07-02T17:14:58.6910678Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0asg",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/dwh92eef0asg",
    "message": "Microsoft.Network/applicationSecurityGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "95c98185-5696-c93e-e8d1-c56a3076a522",
    "eventSubmissionTimestamp": "2026-07-02T17:14:58.6910678Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0asg",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/applicationSecurityGroups/joinIpConfiguration/action

#
Namespace
Microsoft.Network

Description

Joins an IP Configuration to Application Security Groups. Not alertable.

Microsoft.Network/applicationSecurityGroups/joinNetworkSecurityRule/action

#
Namespace
Microsoft.Network

Description

Joins a Security Rule to Application Security Groups. Not alertable.

Microsoft.Network/applicationSecurityGroups/listAddressPrefixSets/action

#
Namespace
Microsoft.Network

Description

Lists address prefix sets in an application security group

Microsoft.Network/applicationSecurityGroups/listIpConfigurations/action

#
Namespace
Microsoft.Network

Description

Lists IP Configurations in the ApplicationSecurityGroup

Microsoft.Network/applicationSecurityGroups/write

#
Namespace
Microsoft.Network

Description

Creates an Application Security Group, or updates an existing Application Security Group.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/zcasg3",
    "action": "Microsoft.Network/applicationSecurityGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/zcasg3",
    "action": "Microsoft.Network/applicationSecurityGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "ba66021d-6ed1-44fb-898d-69cfe9eed945",
  "EventDataId": "2f581fed-3d63-9319-8397-caa13aad9470",
  "EventSubmissionTimestamp": "2026-06-29T19:02:14.6592814Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/APPLICATIONSECURITYGROUPS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/zcasg3",
    "message": "Microsoft.Network/applicationSecurityGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2f581fed-3d63-9319-8397-caa13aad9470",
    "eventSubmissionTimestamp": "2026-06-29T19:02:14.6592814Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcasg3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/applicationSecurityGroups/zcasg3",
    "message": "Microsoft.Network/applicationSecurityGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2f581fed-3d63-9319-8397-caa13aad9470",
    "eventSubmissionTimestamp": "2026-06-29T19:02:14.6592814Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcasg3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:14.6592814Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/applicationsecuritygroups/zcasg3"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/authenticationPolicies/delete

#
Namespace
Microsoft.Network

Description

Delete Authentication Policy

Microsoft.Network/authenticationPolicies/join/action

#
Namespace
Microsoft.Network

Description

Join Authentication Policy

Microsoft.Network/authenticationPolicies/write

#
Namespace
Microsoft.Network

Description

Create or update Authentication Policy

Microsoft.Network/authorizationPolicies/delete

#
Namespace
Microsoft.Network

Description

Delete Authorization Policy

Microsoft.Network/authorizationPolicies/join/action

#
Namespace
Microsoft.Network

Description

Join Authorization Policy

Microsoft.Network/authorizationPolicies/write

#
Namespace
Microsoft.Network

Description

Create or update Authorization Policy

Microsoft.Network/azureFirewalls/applicationRuleCollections/delete

#

Microsoft.Network/azureFirewalls/applicationRuleCollections/write

#

Microsoft.Network/azurefirewalls/delete

#
Namespace
Microsoft.Network

Description

Delete Azure Firewall

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/azurefirewalls/learnedIPPrefixes/action

#
Namespace
Microsoft.Network

Description

Gets IP prefixes learned by Azure Firewall to not perform SNAT

Microsoft.Network/azureFirewalls/natRuleCollections/delete

#

Microsoft.Network/azureFirewalls/natRuleCollections/write

#

Microsoft.Network/azureFirewalls/networkRuleCollections/delete

#

Microsoft.Network/azureFirewalls/networkRuleCollections/write

#

Microsoft.Network/azurefirewalls/packetCapture/action

#
Namespace
Microsoft.Network

Description

AzureFirewallPacketCaptureOperation

Microsoft.Network/azurefirewalls/packetCaptureOperation/action

#
Namespace
Microsoft.Network

Description

AzureFirewallPacketCaptureOperation

Microsoft.Network/azureFirewalls/providers/Microsoft.Insights/DiagnosticSettings/Write

#
Namespace
Microsoft.Network

Description

Create or update the diagnostic settings of Azure Firewalls

Microsoft.Network/azurefirewalls/write

#
Namespace
Microsoft.Network

Description

Creates or updates an Azure Firewall

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/azureWebCategories/classifyUnknown/action

#
Namespace
Microsoft.Network

Description

Classifies Unknown WebCategory

Microsoft.Network/azureWebCategories/getMiscategorizationStatus/action

#
Namespace
Microsoft.Network

Description

Gets Miscategorization Status

Microsoft.Network/azureWebCategories/getwebcategory/action

#
Namespace
Microsoft.Network

Description

Looks up WebCategory

Microsoft.Network/azureWebCategories/reclassify/action

#
Namespace
Microsoft.Network

Description

Reclassifies WebCategory

Microsoft.Network/bastionHosts/createShareableLinks/action

#
Namespace
Microsoft.Network

Microsoft.Network/bastionHosts/delete

#
Namespace
Microsoft.Network

Description

Deletes a Bastion Host

Microsoft.Network/bastionHosts/deleteShareableLinks/action

#
Namespace
Microsoft.Network

Microsoft.Network/bastionHosts/deleteShareableLinksByToken/action

#
Namespace
Microsoft.Network

Description

Deletes shareable urls for the provided tokens under a bastion

Microsoft.Network/bastionHosts/disconnectactivesessions/action

#
Namespace
Microsoft.Network

Description

Disconnect given Active Sessions in the Bastion Host

Microsoft.Network/bastionHosts/getactivesessions/action

#
Namespace
Microsoft.Network

Description

Get Active Sessions in the Bastion Host

Microsoft.Network/bastionHosts/getsessionrecordingsasurl/action

#
Namespace
Microsoft.Network

Description

Gets SAS URL for BastionHost Session Recording Feature

Microsoft.Network/bastionHosts/getShareableLinks/action

#
Namespace
Microsoft.Network

Microsoft.Network/bastionHosts/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the diagnostic setting for the resource

Microsoft.Network/bastionHosts/setsessionrecordingsasurl/action

#
Namespace
Microsoft.Network

Description

Sets SAS URL for BastionHost Session Recording Feature

Microsoft.Network/bastionHosts/write

#
Namespace
Microsoft.Network

Description

Create or Update a Bastion Host

Microsoft.Network/checkFrontDoorNameAvailability/action

#
Namespace
Microsoft.Network

Description

Checks whether a Front Door name is available

Microsoft.Network/checkTrafficManagerNameAvailability/action

#
Namespace
Microsoft.Network

Description

Checks the availability of a Traffic Manager Relative DNS name.

Microsoft.Network/connections/delete

#
Namespace
Microsoft.Network

Description

Deletes VirtualNetworkGatewayConnection

Microsoft.Network/connections/getikesas/action

#
Namespace
Microsoft.Network

Description

Lists IKE Security Associations for the connection

Microsoft.Network/connections/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates diagnostic settings for Connections

Microsoft.Network/connections/resetconnection/action

#
Namespace
Microsoft.Network

Description

Resets connection for VNG

Microsoft.Network/connections/revoke/action

#
Namespace
Microsoft.Network

Description

Marks an Express Route Connection status as Revoked

Microsoft.Network/connections/sharedkey/action

#
Namespace
Microsoft.Network

Description

Get VirtualNetworkGatewayConnection SharedKey

Microsoft.Network/connections/sharedKey/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing VirtualNetworkGatewayConnection SharedKey

Microsoft.Network/connections/startpacketcapture/action

#
Namespace
Microsoft.Network

Description

Starts a Virtual Network Gateway Connection Packet Capture.

Microsoft.Network/connections/stoppacketcapture/action

#
Namespace
Microsoft.Network

Description

Stops a Virtual Network Gateway Connection Packet Capture.

Microsoft.Network/connections/vpndeviceconfigurationscript/action

#
Namespace
Microsoft.Network

Description

Gets Vpn Device Configuration of VirtualNetworkGatewayConnection

Microsoft.Network/connections/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing VirtualNetworkGatewayConnection

Microsoft.Network/customIpPrefixes/delete

#
Namespace
Microsoft.Network

Description

Deletes A Custom Ip Prefix

Microsoft.Network/customIpPrefixes/join/action

#
Namespace
Microsoft.Network

Description

Joins a CustomIpPrefix. Not alertable.

Microsoft.Network/customIpPrefixes/write

#
Namespace
Microsoft.Network

Description

Creates A Custom Ip Prefix Or Updates An Existing Custom Ip Prefix

Microsoft.Network/ddosCustomPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes a DDoS customized policy

Microsoft.Network/ddosCustomPolicies/write

#
Namespace
Microsoft.Network

Description

Creates a DDoS customized policy or updates an existing DDoS customized policy

Microsoft.Network/ddosProtectionPlans/ddosProtectionPlanProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a DDoS Protection Plan Proxy

Microsoft.Network/ddosProtectionPlans/ddosProtectionPlanProxies/write

#
Namespace
Microsoft.Network

Description

Creates a DDoS Protection Plan Proxy or updates and existing DDoS Protection Plan Proxy

Microsoft.Network/ddosProtectionPlans/delete

#
Namespace
Microsoft.Network

Description

Deletes a DDoS Protection Plan

Microsoft.Network/ddosProtectionPlans/join/action

#
Namespace
Microsoft.Network

Description

Joins a DDoS Protection Plan. Not alertable.

Microsoft.Network/ddosProtectionPlans/write

#
Namespace
Microsoft.Network

Description

Creates a DDoS Protection Plan or updates a DDoS Protection Plan

Microsoft.Network/dnsForwardingRulesets/delete

#
Namespace
Microsoft.Network

Description

Deletes a DNS Forwarding Ruleset, in JSON format

Microsoft.Network/dnsForwardingRulesets/forwardingRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a DNS Forwarding Rule, in JSON format

Microsoft.Network/dnsForwardingRulesets/forwardingRules/write

#
Namespace
Microsoft.Network

Description

Creates Or Updates a DNS Forwarding Rule, in JSON format

Microsoft.Network/dnsForwardingRulesets/join/action

#
Namespace
Microsoft.Network

Description

Join DNS Forwarding Ruleset

Microsoft.Network/dnsForwardingRulesets/virtualNetworkLinks/delete

#
Namespace
Microsoft.Network

Microsoft.Network/dnsForwardingRulesets/virtualNetworkLinks/write

#
Namespace
Microsoft.Network

Microsoft.Network/dnsForwardingRulesets/write

#
Namespace
Microsoft.Network

Description

Creates Or Updates a DNS Forwarding Ruleset

Microsoft.Network/dnsResolverDomainLists/bulk/action

#
Namespace
Microsoft.Network

Description

Bulk operations on the contents of the DNS Resolver Domain List.

Microsoft.Network/dnsResolverDomainLists/delete

#
Namespace
Microsoft.Network

Description

Delete a DNS Resolver Domain List.

Microsoft.Network/dnsResolverDomainLists/join/action

#
Namespace
Microsoft.Network

Description

Join a DNS Resolver Domain List from another resource.

Microsoft.Network/dnsResolverDomainLists/write

#
Namespace
Microsoft.Network

Description

Create or update a DNS Resolver Domain List.

Microsoft.Network/dnsResolverPolicies/delete

#
Namespace
Microsoft.Network

Description

Delete a DNS Resolver Policy.

Microsoft.Network/dnsResolverPolicies/dnsSecurityRules/delete

#
Namespace
Microsoft.Network

Description

Delete a DNS Security Rule for a DNS Resolver Policy.

Microsoft.Network/dnsResolverPolicies/dnsSecurityRules/write

#
Namespace
Microsoft.Network

Description

Create or update a DNS Security Rule for a DNS Resolver Policy.

Microsoft.Network/dnsResolverPolicies/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Create or update diagnostic settings for a DNS Resolver Policy.

Microsoft.Network/dnsResolverPolicies/virtualNetworkLinks/delete

#
Namespace
Microsoft.Network

Microsoft.Network/dnsResolverPolicies/virtualNetworkLinks/write

#
Namespace
Microsoft.Network

Microsoft.Network/dnsResolverPolicies/write

#
Namespace
Microsoft.Network

Description

Create or update a DNS Resolver Policy.

Microsoft.Network/dnsResolvers/delete

#
Namespace
Microsoft.Network

Description

Deletes a DNS Resolver

Microsoft.Network/dnsResolvers/inboundEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes a DNS Resolver Inbound Endpoint, in JSON format

Microsoft.Network/dnsResolvers/inboundEndpoints/join/action

#
Namespace
Microsoft.Network

Description

Join DNS Resolver

Microsoft.Network/dnsResolvers/inboundEndpoints/write

#
Namespace
Microsoft.Network

Description

Creates Or Updates a DNS Resolver Inbound Endpoint, in JSON format

Microsoft.Network/dnsResolvers/join/action

#
Namespace
Microsoft.Network

Description

Join DNS Resolver

Microsoft.Network/dnsResolvers/outboundEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes a DNS Resolver Outbound Endpoint description.

Microsoft.Network/dnsResolvers/outboundEndpoints/join/action

#
Namespace
Microsoft.Network

Description

Join DNS Resolver

Microsoft.Network/dnsResolvers/outboundEndpoints/listDnsForwardingRulesets/action

#
Namespace
Microsoft.Network

Description

Gets the DNS Forwarding Rulesets Properties for DNS Resolver Outbound Endpoint, in JSON format

Microsoft.Network/dnsResolvers/outboundEndpoints/write

#
Namespace
Microsoft.Network

Description

Creates Or Updates a DNS Resolver Outbound Endpoint, in JSON format

Microsoft.Network/dnsResolvers/write

#
Namespace
Microsoft.Network

Description

Creates Or Updates a DNS Resolver, in JSON format

Microsoft.Network/dnszones/A/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'A' from a DNS zone.

Microsoft.Network/dnszones/A/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'A' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/AAAA/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'AAAA' from a DNS zone.

Microsoft.Network/dnszones/AAAA/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'AAAA' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/CAA/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'CAA' from a DNS zone.

Microsoft.Network/dnszones/CAA/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'CAA' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/CNAME/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'CNAME' from a DNS zone.

Microsoft.Network/dnszones/CNAME/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'CNAME' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/delete

#
Namespace
Microsoft.Network

Description

Delete the DNS zone, in JSON format. The zone properties include tags, etag, numberOfRecordSets, and maxNumberOfRecordSets.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "NoContent",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "action": "Microsoft.Network/dnsZones/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "action": "Microsoft.Network/dnsZones/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "95dc5735-fb83-49a5-a7d9-ec552a7cd1ae",
  "EventDataId": "e1a02799-2fff-434a-f505-c871bc4a7342",
  "EventSubmissionTimestamp": "2026-07-02T18:23:19.9687492Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/DNSZONES/DELETE",
  "Properties": {
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "message": "Microsoft.Network/dnsZones/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e1a02799-2fff-434a-f505-c871bc4a7342",
    "eventSubmissionTimestamp": "2026-07-02T18:23:19.9687492Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdnszones",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "NoContent"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "message": "Microsoft.Network/dnsZones/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e1a02799-2fff-434a-f505-c871bc4a7342",
    "eventSubmissionTimestamp": "2026-07-02T18:23:19.9687492Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdnszones",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "activitySubstatusValue": "NoContent"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/dnszones/dnssecConfigs/default/delete

#
Namespace
Microsoft.Network

Description

Deletes the DNSSEC configuration for a DNS zone

Microsoft.Network/dnszones/dnssecConfigs/default/write

#
Namespace
Microsoft.Network

Description

Creates or updates the DNSSEC configuration for a DNS zone

Microsoft.Network/dnszones/DS/delete

#
Namespace
Microsoft.Network

Description

Deletes the DNS record set of type DS

Microsoft.Network/dnszones/DS/write

#
Namespace
Microsoft.Network

Description

Creates or updates DNS record set of type DS

Microsoft.Network/dnszones/MX/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'MX' from a DNS zone.

Microsoft.Network/dnszones/MX/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'MX' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/NS/delete

#
Namespace
Microsoft.Network

Description

Deletes the DNS record set of type NS

Microsoft.Network/dnszones/NS/write

#
Namespace
Microsoft.Network

Description

Creates or updates DNS record set of type NS

Microsoft.Network/dnszones/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the DNS zone diagnostic settings

Microsoft.Network/dnszones/PTR/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'PTR' from a DNS zone.

Microsoft.Network/dnszones/PTR/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'PTR' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/SOA/write

#
Namespace
Microsoft.Network

Description

Creates or updates DNS record set of type SOA

Microsoft.Network/dnszones/SRV/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'SRV' from a DNS zone.

Microsoft.Network/dnszones/SRV/write

#
Namespace
Microsoft.Network

Description

Create or update record set of type SRV

Microsoft.Network/dnszones/TLSA/delete

#
Namespace
Microsoft.Network

Description

Deletes the DNS record set of type TLSA

Microsoft.Network/dnszones/TLSA/write

#
Namespace
Microsoft.Network

Description

Creates or updates DNS record set of type TLSA

Microsoft.Network/dnszones/TXT/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'TXT' from a DNS zone.

Microsoft.Network/dnszones/TXT/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'TXT' within a DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/dnszones/write

#
Namespace
Microsoft.Network

Description

Create or update a DNS zone within a resource group. Used to update the tags on a DNS zone resource. Note that this command can not be used to create or update record sets within the zone.

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "BadRequest",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "action": "Microsoft.Network/dnsZones/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "action": "Microsoft.Network/dnsZones/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "d1be501b-2f7b-4c59-8729-92ac0e3220db",
  "EventDataId": "b5dd0e8c-d52f-def7-baf0-1a38c4d6a708",
  "EventSubmissionTimestamp": "2026-07-02T18:23:18.3851724Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.NETWORK/DNSZONES/WRITE",
  "Properties": {
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "statusMessage": {
      "code": "BadRequest",
      "message": "The zone name 'dwh2220afdnszones' does not have enough labels. Zone names must have two or more labels."
    },
    "responseBody": {
      "code": "BadRequest",
      "message": "The zone name 'dwh2220afdnszones' does not have enough labels. Zone names must have two or more labels."
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "message": "Microsoft.Network/dnsZones/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b5dd0e8c-d52f-def7-baf0-1a38c4d6a708",
    "eventSubmissionTimestamp": "2026-07-02T18:23:18.3851724Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdnszones",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "BadRequest"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/dnsZones/dwh2220afdnszones",
    "message": "Microsoft.Network/dnsZones/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b5dd0e8c-d52f-def7-baf0-1a38c4d6a708",
    "eventSubmissionTimestamp": "2026-07-02T18:23:18.3851724Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afdnszones",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "activitySubstatusValue": "BadRequest",
    "responseBody": {
      "code": "BadRequest",
      "message": "The zone name 'dwh2220afdnszones' does not have enough labels. Zone names must have two or more labels."
    },
    "statusMessage": {
      "code": "BadRequest",
      "message": "The zone name 'dwh2220afdnszones' does not have enough labels. Zone names must have two or more labels."
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/dscpConfiguration/join/action

#
Namespace
Microsoft.Network

Description

Joins DSCP Configuration

Microsoft.Network/dscpConfiguration/write

#
Namespace
Microsoft.Network

Description

Operation to put the DSCP configuration

Microsoft.Network/expressRouteCircuits/authorizations/addAuthorization/action

#
Namespace
Microsoft.Network

Description

Create an ExpressRouteCircuit Authorization

Microsoft.Network/expressRouteCircuits/authorizations/authorizationKey/action

#
Namespace
Microsoft.Network

Description

Get an Authorization Key for ExpressRouteCircuit Authorization

Microsoft.Network/expressRouteCircuits/authorizations/delete

#
Namespace
Microsoft.Network

Description

Deletes an ExpressRouteCircuit Authorization

Microsoft.Network/expressRouteCircuits/authorizations/getAuthorization/action

#
Namespace
Microsoft.Network

Description

Gets an ExpressRouteCircuit Authorization with Authorization Key

Microsoft.Network/expressRouteCircuits/authorizations/listkeys/action

#
Namespace
Microsoft.Network

Description

Get an Authorization Key for ExpressRouteCircuit Authorization

Microsoft.Network/expressRouteCircuits/authorizations/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing ExpressRouteCircuit Authorization

Microsoft.Network/expressRouteCircuits/delete

#
Namespace
Microsoft.Network

Description

Deletes an ExpressRouteCircuit

Microsoft.Network/expressRouteCircuits/join/action

#
Namespace
Microsoft.Network

Description

Joins an Express Route Circuit. Not alertable.

Microsoft.Network/expressRouteCircuits/listAuthorizations/action

#
Namespace
Microsoft.Network

Description

List All ExpressRouteCircuit Authorization with Authorization Key

Microsoft.Network/expressRouteCircuits/nrpinternalupdate/action

#
Namespace
Microsoft.Network

Description

Create or Update ExpressRouteCircuit

Microsoft.Network/expressRouteCircuits/peerings/connections/delete

#
Namespace
Microsoft.Network

Description

Deletes an ExpressRouteCircuit Connection

Microsoft.Network/expressRouteCircuits/peerings/connections/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing ExpressRouteCircuit Connection Resource

Microsoft.Network/expressRouteCircuits/peerings/delete

#
Namespace
Microsoft.Network

Description

Deletes an ExpressRouteCircuit Peering

Microsoft.Network/expressRouteCircuits/peerings/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates diagnostic settings for ExpressRoute Circuit Peerings

Microsoft.Network/expressRouteCircuits/peerings/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing ExpressRouteCircuit Peering

Microsoft.Network/expressRouteCircuits/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates diagnostic settings for ExpressRoute Circuits

Microsoft.Network/expressRouteCircuits/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing ExpressRouteCircuit

Microsoft.Network/expressRouteCrossConnections/confirmActivationKey/action

#
Namespace
Microsoft.Network

Description

Express Route Cross Connection Confirm Activation Key

Microsoft.Network/expressRouteCrossConnections/delete

#
Namespace
Microsoft.Network

Description

Delete Express Route Cross Connection

Microsoft.Network/expressRouteCrossConnections/deprovisionConnection/action

#
Namespace
Microsoft.Network

Description

Express Route Deprovision Multi Cloud Connection

Microsoft.Network/expressRouteCrossConnections/features/delete

#
Namespace
Microsoft.Network

Description

Deletes an Express Route Cross Connection Feature

Microsoft.Network/expressRouteCrossConnections/features/write

#
Namespace
Microsoft.Network

Description

Creates or Updates an Express Route Cross Connection Feature

Microsoft.Network/expressRouteCrossConnections/join/action

#
Namespace
Microsoft.Network

Description

Joins an Express Route Cross Connection. Not alertable.

Microsoft.Network/expressRouteCrossConnections/notifyConnectionStatus/action

#
Namespace
Microsoft.Network

Description

Express Route Notify Multi Cloud Connection Status

Microsoft.Network/expressRouteCrossConnections/peerings/delete

#
Namespace
Microsoft.Network

Description

Deletes an Express Route Cross Connection Peering

Microsoft.Network/expressRouteCrossConnections/peerings/write

#
Namespace
Microsoft.Network

Description

Creates an Express Route Cross Connection Peering or Updates an existing Express Route Cross Connection Peering

Microsoft.Network/expressRouteCrossConnections/proposeInterconnect/action

#
Namespace
Microsoft.Network

Description

Express Route Cross Connection operation to propose Interconnect

Microsoft.Network/expressRouteCrossConnections/serviceProviders/action

#
Namespace
Microsoft.Network

Description

Backfill Express Route Cross Connection

Microsoft.Network/expressRouteCrossConnections/write

#
Namespace
Microsoft.Network

Description

Create or Update Express Route Cross Connection

Microsoft.Network/expressRouteGateways/delete

#
Namespace
Microsoft.Network

Description

Delete Express Route Gateway

Microsoft.Network/expressRouteGateways/expressRouteConnections/delete

#
Namespace
Microsoft.Network

Description

Deletes an Express Route Connection

Microsoft.Network/expressRouteGateways/expressRouteConnections/write

#
Namespace
Microsoft.Network

Description

Creates an Express Route Connection or Updates an existing Express Route Connection

Microsoft.Network/expressRouteGateways/join/action

#
Namespace
Microsoft.Network

Description

Joins an Express Route Gateway. Not alertable.

Microsoft.Network/expressRouteGateways/write

#
Namespace
Microsoft.Network

Description

Create or Update Express Route Gateway

Microsoft.Network/expressRouteLags/authorizations/delete

#
Namespace
Microsoft.Network

Description

Deletes an ExpressRouteLagAuthorization

Microsoft.Network/expressRouteLags/authorizations/listkeys/action

#
Namespace
Microsoft.Network

Description

Get an AuthorizationKey for ExpressRouteLagAuthorization

Microsoft.Network/expressRouteLags/authorizations/write

#
Namespace
Microsoft.Network

Description

Create or Update ExpressRouteLagAuthorization

Microsoft.Network/expressRouteLags/delete

#
Namespace
Microsoft.Network

Description

Deletes ExpressRouteLag

Microsoft.Network/expressRouteLags/generateloa/action

#
Namespace
Microsoft.Network

Description

Generates LOA for ExpressRouteLag

Microsoft.Network/expressRouteLags/join/action

#
Namespace
Microsoft.Network

Description

Joins ExpressRouteLag

Microsoft.Network/expressRouteLags/write

#
Namespace
Microsoft.Network

Description

Creates or updates ExpressRouteLag

Microsoft.Network/expressRoutePorts/authorizations/addAuthorization/action

#
Namespace
Microsoft.Network

Description

Create ExpressRoutePorts Authorization

Microsoft.Network/expressRoutePorts/authorizations/authorizationKey/action

#
Namespace
Microsoft.Network

Description

Get an Authorization Key for Express Route Ports Authorization

Microsoft.Network/expressRoutePorts/authorizations/delete

#
Namespace
Microsoft.Network

Description

Deletes an ExpressRoutePorts Authorization

Microsoft.Network/expressRoutePorts/authorizations/getAuthorization/action

#
Namespace
Microsoft.Network

Description

Get Express Route Ports Authorization with Authorization Key

Microsoft.Network/expressRoutePorts/authorizations/listkeys/action

#
Namespace
Microsoft.Network

Description

Get an Authorization Key for Express Route Ports Authorization

Microsoft.Network/expressRoutePorts/authorizations/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing ExpressRoutePorts Authorization

Microsoft.Network/expressRoutePorts/delete

#
Namespace
Microsoft.Network

Description

Deletes ExpressRoutePorts

Microsoft.Network/expressRoutePorts/generateloa/action

#
Namespace
Microsoft.Network

Description

Generates LOA for ExpressRoutePorts

Microsoft.Network/expressRoutePorts/join/action

#
Namespace
Microsoft.Network

Description

Joins Express Route ports. Not alertable.

Microsoft.Network/expressRoutePorts/listAuthorizations/action

#
Namespace
Microsoft.Network

Description

List All Express Route Ports Authorizations with Authorization Key

Microsoft.Network/expressRoutePorts/write

#
Namespace
Microsoft.Network

Description

Creates or updates ExpressRoutePorts

Microsoft.Network/firewallPolicies/certificates/action

#
Namespace
Microsoft.Network

Description

Generate Firewall Policy Certificates

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firewallPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Firewall Policy

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/dwh2220affirewallpolici",
    "action": "Microsoft.Network/firewallPolicies/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/dwh2220affirewallpolici",
    "action": "Microsoft.Network/firewallPolicies/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "f46e907e-014f-4d34-bd5b-457426f20dcb",
  "EventDataId": "42d7460e-8ab0-9283-5a2c-dc3e063ff2ca",
  "EventSubmissionTimestamp": "2026-07-02T18:33:35.0856657Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/FIREWALLPOLICIES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/dwh2220affirewallpolici",
    "message": "Microsoft.Network/firewallPolicies/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "42d7460e-8ab0-9283-5a2c-dc3e063ff2ca",
    "eventSubmissionTimestamp": "2026-07-02T18:33:35.0856657Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220affirewallpolici",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/dwh2220affirewallpolici",
    "message": "Microsoft.Network/firewallPolicies/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "42d7460e-8ab0-9283-5a2c-dc3e063ff2ca",
    "eventSubmissionTimestamp": "2026-07-02T18:33:35.0856657Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220affirewallpolici",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Panther #

  • Azure Firewall Policy Deleted source high: Detects when an Azure Firewall policy is deleted. Firewall policies define critical network security rules that control traffic flow and protect resources. Adversaries may delete firewall policies to disable network security controls, allow malicious traffic, or enable data exfiltration. This activity is a strong indicator of defense evasion or preparation for follow-on attacks.T1562.004

Microsoft.Network/firewallPolicies/deploy/action

#
Namespace
Microsoft.Network

Description

Deploy Firewall Policy Draft

Microsoft.Network/firewallPolicies/firewallPolicyDrafts/delete

#
Namespace
Microsoft.Network

Description

Deletes a Firewall Policy Draft

Microsoft.Network/firewallPolicies/firewallPolicyDrafts/write

#
Namespace
Microsoft.Network

Description

Creates a Firewall Policy Draft or Updates an existing Firewall Policy Draft

Microsoft.Network/firewallPolicies/join/action

#
Namespace
Microsoft.Network

Description

Joins a Firewall Policy. Not alertable.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firewallPolicies/pacFile/action

#
Namespace
Microsoft.Network

Description

Get Firewall Policy PacFile

Microsoft.Network/firewallPolicies/ruleCollectionGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes a Firewall Policy Rule Collection Group

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firewallPolicies/ruleCollectionGroups/ruleCollectionGroupDrafts/delete

#
Namespace
Microsoft.Network

Description

Deletes a Firewall Policy Rule Collection Group Draft

Microsoft.Network/firewallPolicies/ruleCollectionGroups/ruleCollectionGroupDrafts/write

#
Namespace
Microsoft.Network

Description

Creates a Firewall Policy Rule Collection Group Draft or Updates an existing Firewall Policy Rule Collection Group Draft

Microsoft.Network/firewallPolicies/ruleCollectionGroups/write

#
Namespace
Microsoft.Network

Description

Creates a Firewall Policy Rule Collection Group or Updates an existing Firewall Policy Rule Collection Group

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firewallPolicies/ruleGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes a Firewall Policy Rule Group

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firewallPolicies/ruleGroups/write

#
Namespace
Microsoft.Network

Description

Creates a Firewall Policy Rule Group or Updates an existing Firewall Policy Rule Group

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firewallPolicies/write

#
Namespace
Microsoft.Network

Description

Creates a Firewall Policy or Updates an existing Firewall Policy

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/zcfwpol3",
    "action": "Microsoft.Network/firewallPolicies/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/zcfwpol3",
    "action": "Microsoft.Network/firewallPolicies/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "43280262-6fe3-45ea-bbaf-6f72a7094bf4",
  "EventDataId": "0e8da4a4-e2c8-469b-b565-bd2e2ff1ca11",
  "EventSubmissionTimestamp": "2026-06-29T19:02:17.1953723Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/FIREWALLPOLICIES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/zcfwpol3",
    "message": "Microsoft.Network/firewallPolicies/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "0e8da4a4-e2c8-469b-b565-bd2e2ff1ca11",
    "eventSubmissionTimestamp": "2026-06-29T19:02:17.1953723Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcfwpol3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/firewallPolicies/zcfwpol3",
    "message": "Microsoft.Network/firewallPolicies/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "0e8da4a4-e2c8-469b-b565-bd2e2ff1ca11",
    "eventSubmissionTimestamp": "2026-06-29T19:02:17.1953723Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcfwpol3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:17.1953723Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/firewallpolicies/zcfwpol3"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/firstPartyServiceTags/delete

#
Namespace
Microsoft.Network

Description

Delete First Party Service Tag

Microsoft.Network/firstPartyServiceTags/write

#
Namespace
Microsoft.Network

Description

Create or Update First Party Service Tag

Microsoft.Network/frontDoors/backendPools/delete

#
Namespace
Microsoft.Network

Description

Deletes a backend pool

Microsoft.Network/frontDoors/backendPools/write

#
Namespace
Microsoft.Network

Description

Creates or updates a backend pool

Microsoft.Network/frontDoors/delete

#
Namespace
Microsoft.Network

Description

Deletes a Front Door

Microsoft.Network/frontDoors/frontendEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes a frontend endpoint

Microsoft.Network/frontDoors/frontendEndpoints/disableHttps/action

#
Namespace
Microsoft.Network

Description

Disables HTTPS on a Frontend Endpoint

Microsoft.Network/frontDoors/frontendEndpoints/enableHttps/action

#
Namespace
Microsoft.Network

Description

Enables HTTPS on a Frontend Endpoint

Microsoft.Network/frontDoors/frontendEndpoints/write

#
Namespace
Microsoft.Network

Description

Creates or updates a frontend endpoint

Microsoft.Network/frontDoors/healthProbeSettings/delete

#
Namespace
Microsoft.Network

Description

Deletes health probe settings

Microsoft.Network/frontDoors/healthProbeSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates health probe settings

Microsoft.Network/frontDoors/loadBalancingSettings/delete

#
Namespace
Microsoft.Network

Description

Creates or updates load balancing settings

Microsoft.Network/frontDoors/loadBalancingSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates load balancing settings

Microsoft.Network/frontdoors/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the diagnostic setting for the Frontdoor resource

Microsoft.Network/frontDoors/purge/action

#
Namespace
Microsoft.Network

Description

Purge cached content from a Front Door

Microsoft.Network/frontDoors/routingRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a routing rule

Microsoft.Network/frontDoors/routingRules/write

#
Namespace
Microsoft.Network

Description

Creates or updates a routing rule

Microsoft.Network/frontDoors/rulesEngines/delete

#
Namespace
Microsoft.Network

Description

Deletes a Rules Engine

Microsoft.Network/frontDoors/rulesEngines/write

#
Namespace
Microsoft.Network

Description

Creates or updates a Rules Engine

Microsoft.Network/frontDoors/validateCustomDomain/action

#
Namespace
Microsoft.Network

Description

Validates a frontend endpoint for a Front Door

Microsoft.Network/frontDoors/write

#
Namespace
Microsoft.Network

Description

Creates or updates a Front Door

Microsoft.Network/frontDoorWebApplicationFirewallPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Web Application Firewall Policy

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Microsoft.Network/frontDoorWebApplicationFirewallPolicies/join/action

#
Namespace
Microsoft.Network

Description

Joins a Web Application Firewall Policy. Not Alertable.

Microsoft.Network/frontDoorWebApplicationFirewallPolicies/write

#
Namespace
Microsoft.Network

Description

Creates or updates a Web Application Firewall Policy

Microsoft.Network/gatewayLoadBalancerAliases/delete

#
Namespace
Microsoft.Network

Description

Delete Gateway LoadBalancer Alias

Microsoft.Network/gatewayLoadBalancerAliases/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Gateway LaodBalancer Alias

Microsoft.Network/getDnsResourceReference/action

#
Namespace
Microsoft.Network

Description

DNS alias resource dependency request

Microsoft.Network/interconnectGroups/delete

#
Namespace
Microsoft.Network

Description

Delete Interconnect Group

Microsoft.Network/interconnectGroups/write

#
Namespace
Microsoft.Network

Description

Create or update Interconnect Group

Microsoft.Network/internalNotify/action

#
Namespace
Microsoft.Network

Description

DNS alias resource notification

Microsoft.Network/ipAllocations/delete

#
Namespace
Microsoft.Network

Description

Deletes A IpAllocation

Microsoft.Network/ipAllocations/write

#
Namespace
Microsoft.Network

Description

Creates A IpAllocation Or Updates An Existing IpAllocation

Microsoft.Network/ipGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes an IpGroup

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwhc6a93dipgroups",
    "action": "Microsoft.Network/ipGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwhc6a93dipgroups",
    "action": "Microsoft.Network/ipGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "13ca6ac6-1552-4a78-8c4a-d5be26440c6e",
  "EventDataId": "abfa3e52-9cd1-589a-6b9f-5b9833a9899e",
  "EventSubmissionTimestamp": "2026-07-03T02:28:42.7689219Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/IPGROUPS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwhc6a93dipgroups",
    "message": "Microsoft.Network/ipGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "abfa3e52-9cd1-589a-6b9f-5b9833a9899e",
    "eventSubmissionTimestamp": "2026-07-03T02:28:42.7689219Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dipgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwhc6a93dipgroups",
    "message": "Microsoft.Network/ipGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "abfa3e52-9cd1-589a-6b9f-5b9833a9899e",
    "eventSubmissionTimestamp": "2026-07-03T02:28:42.7689219Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dipgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/ipGroups/join/action

#
Namespace
Microsoft.Network

Description

Joins an IpGroup. Not alertable.

Microsoft.Network/ipGroups/updateReferences/action

#
Namespace
Microsoft.Network

Description

Update references in an IpGroup

Microsoft.Network/ipGroups/validate/action

#
Namespace
Microsoft.Network

Description

Validates an IpGroup

Microsoft.Network/ipGroups/write

#
Namespace
Microsoft.Network

Description

Creates an IpGroup or Updates an Existing IpGroup

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwh2220afipgroups",
    "action": "Microsoft.Network/ipGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwh2220afipgroups",
    "action": "Microsoft.Network/ipGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "2c4f3240-95cc-402a-9ada-3ed0f9e3f27b",
  "EventDataId": "13cd197d-db08-5c83-f36b-69204ce41039",
  "EventSubmissionTimestamp": "2026-07-02T18:23:54.6089502Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/IPGROUPS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwh2220afipgroups",
    "message": "Microsoft.Network/ipGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "13cd197d-db08-5c83-f36b-69204ce41039",
    "eventSubmissionTimestamp": "2026-07-02T18:23:54.6089502Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afipgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/ipGroups/dwh2220afipgroups",
    "message": "Microsoft.Network/ipGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "13cd197d-db08-5c83-f36b-69204ce41039",
    "eventSubmissionTimestamp": "2026-07-02T18:23:54.6089502Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afipgroups",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/loadBalancers/backendAddressPools/delete

#
Namespace
Microsoft.Network

Description

Deletes a load balancer backend address pool

Microsoft.Network/loadBalancers/backendAddressPools/health/action

#
Namespace
Microsoft.Network

Description

Get Health Details of Backend Instance

Microsoft.Network/loadBalancers/backendAddressPools/join/action

#
Namespace
Microsoft.Network

Description

Joins a load balancer backend address pool. Not Alertable.

Microsoft.Network/loadBalancers/backendAddressPools/queryInboundNatRulePortMapping/action

#
Namespace
Microsoft.Network

Description

Query inbound Nat rule port mapping.

Microsoft.Network/loadBalancers/backendAddressPools/updateAdminState/action

#
Namespace
Microsoft.Network

Description

Update AdminStates of backend addresses of a pool

Microsoft.Network/loadBalancers/backendAddressPools/write

#
Namespace
Microsoft.Network

Description

Creates a load balancer backend address pool or updates an existing load balancer backend address pool

Microsoft.Network/loadBalancers/delete

#
Namespace
Microsoft.Network

Description

Deletes a load balancer

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "action": "Microsoft.Network/loadBalancers/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "action": "Microsoft.Network/loadBalancers/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "edeb9d20-34e2-4456-bf07-2ac115cc7575",
  "EventDataId": "9e228867-a50a-1cb8-8896-a8f304416bd3",
  "EventSubmissionTimestamp": "2026-07-02T17:15:32.7659361Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/LOADBALANCERS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "message": "Microsoft.Network/loadBalancers/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9e228867-a50a-1cb8-8896-a8f304416bd3",
    "eventSubmissionTimestamp": "2026-07-02T17:15:32.7659361Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0lb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "message": "Microsoft.Network/loadBalancers/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9e228867-a50a-1cb8-8896-a8f304416bd3",
    "eventSubmissionTimestamp": "2026-07-02T17:15:32.7659361Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0lb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/loadBalancers/frontendIPConfigurations/join/action

#
Namespace
Microsoft.Network

Description

Joins a Load Balancer Frontend IP Configuration. Not alertable.

Microsoft.Network/loadBalancers/frontendIPConfigurations/loadBalancerPools/delete

#
Namespace
Microsoft.Network

Description

Deletes a load balancer frontend IP address backend pool

Microsoft.Network/loadBalancers/frontendIPConfigurations/loadBalancerPools/join/action

#
Namespace
Microsoft.Network

Description

Joins a load balancer frontend IP address backend pool. Not alertable.

Microsoft.Network/loadBalancers/frontendIPConfigurations/loadBalancerPools/write

#
Namespace
Microsoft.Network

Description

Creates a load balancer frontend IP address backend pool or updates an existing public IP Address load balancer backend pool

Microsoft.Network/loadBalancers/health/action

#
Namespace
Microsoft.Network

Description

Get Health Summary of Load Balancer

Microsoft.Network/loadBalancers/inboundNatPools/join/action

#
Namespace
Microsoft.Network

Description

Joins a load balancer inbound NAT pool. Not alertable.

Microsoft.Network/loadBalancers/inboundNatRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a load balancer inbound nat rule

Microsoft.Network/loadBalancers/inboundNatRules/join/action

#
Namespace
Microsoft.Network

Description

Joins a load balancer inbound nat rule. Not Alertable.

Microsoft.Network/loadBalancers/inboundNatRules/write

#
Namespace
Microsoft.Network

Description

Creates a load balancer inbound nat rule or updates an existing load balancer inbound nat rule

Microsoft.Network/loadBalancers/loadBalancingRules/health/action

#
Namespace
Microsoft.Network

Description

Get Health Details of Load Balancing Rule

Microsoft.Network/loadBalancers/migrateToIpBased/action

#
Namespace
Microsoft.Network

Description

Migrate from NIC based to IP based Load Balancer

Microsoft.Network/loadBalancers/probes/join/action

#
Namespace
Microsoft.Network

Description

Allows using probes of a load balancer. For example, with this permission healthProbe property of VM scale set can reference the probe. Not alertable.

Microsoft.Network/loadBalancers/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the Load Balancer Diagnostic Settings

Microsoft.Network/loadBalancers/write

#
Namespace
Microsoft.Network

Description

Creates a load balancer or updates an existing load balancer

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "action": "Microsoft.Network/loadBalancers/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "action": "Microsoft.Network/loadBalancers/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "5d3baa24-50b6-485f-a362-6bf7e31874fc",
  "EventDataId": "9939e218-cdf0-3f77-c1f7-2a820a34bfdf",
  "EventSubmissionTimestamp": "2026-07-02T17:15:02.4099981Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/LOADBALANCERS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "dwh92eef0lb",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
      "etag": "W/\"96153c78-7d38-4776-b5f9-b2f5575cf62f\"",
      "type": "Microsoft.Network/loadBalancers",
      "location": "westus2",
      "tags": "******",
      "properties": {
        "provisioningState": "Succeeded",
        "resourceGuid": "9797790d-900c-4ef8-95e7-e498c0079cfc",
        "frontendIPConfigurations": [
          {
            "name": "LoadBalancerFrontEnd",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb/frontendIPConfigurations/LoadBalancerFrontEnd",
            "etag": "W/\"96153c78-7d38-4776-b5f9-b2f5575cf62f\"",
            "type": "Microsoft.Network/loadBalancers/frontendIPConfigurations",
            "properties": {
              "provisioningState": "Succeeded",
              "privateIPAllocationMethod": "Dynamic",
              "publicIPAddress": {
                "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/PublicIPdwh92eef0lb"
              }
            }
          }
        ],
        "backendAddressPools": [
          {
            "name": "dwh92eef0lbbepool",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb/backendAddressPools/dwh92eef0lbbepool",
            "etag": "W/\"96153c78-7d38-4776-b5f9-b2f5575cf62f\"",
            "properties": {
              "provisioningState": "Succeeded",
              "loadBalancerBackendAddresses": []
            },
            "type": "Microsoft.Network/loadBalancers/backendAddressPools"
          }
        ],
        "loadBalancingRules": [],
        "probes": [],
        "inboundNatRules": [],
        "outboundRules": [],
        "inboundNatPools": []
      },
      "sku": {
        "name": "Standard",
        "tier": "Regional"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "message": "Microsoft.Network/loadBalancers/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9939e218-cdf0-3f77-c1f7-2a820a34bfdf",
    "eventSubmissionTimestamp": "2026-07-02T17:15:02.4099981Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0lb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
    "message": "Microsoft.Network/loadBalancers/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9939e218-cdf0-3f77-c1f7-2a820a34bfdf",
    "eventSubmissionTimestamp": "2026-07-02T17:15:02.4099981Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0lb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created",
    "responseBody": {
      "name": "dwh92eef0lb",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb",
      "etag": "W/\"96153c78-7d38-4776-b5f9-b2f5575cf62f\"",
      "type": "Microsoft.Network/loadBalancers",
      "location": "westus2",
      "tags": "******",
      "properties": {
        "provisioningState": "Succeeded",
        "resourceGuid": "9797790d-900c-4ef8-95e7-e498c0079cfc",
        "frontendIPConfigurations": [
          {
            "name": "LoadBalancerFrontEnd",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb/frontendIPConfigurations/LoadBalancerFrontEnd",
            "etag": "W/\"96153c78-7d38-4776-b5f9-b2f5575cf62f\"",
            "type": "Microsoft.Network/loadBalancers/frontendIPConfigurations",
            "properties": {
              "provisioningState": "Succeeded",
              "privateIPAllocationMethod": "Dynamic",
              "publicIPAddress": {
                "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/PublicIPdwh92eef0lb"
              }
            }
          }
        ],
        "backendAddressPools": [
          {
            "name": "dwh92eef0lbbepool",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/loadBalancers/dwh92eef0lb/backendAddressPools/dwh92eef0lbbepool",
            "etag": "W/\"96153c78-7d38-4776-b5f9-b2f5575cf62f\"",
            "properties": {
              "provisioningState": "Succeeded",
              "loadBalancerBackendAddresses": []
            },
            "type": "Microsoft.Network/loadBalancers/backendAddressPools"
          }
        ],
        "loadBalancingRules": [],
        "probes": [],
        "inboundNatRules": [],
        "outboundRules": [],
        "inboundNatPools": []
      },
      "sku": {
        "name": "Standard",
        "tier": "Regional"
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/localnetworkgateways/delete

#
Namespace
Microsoft.Network

Description

Deletes LocalNetworkGateway

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "NoContent",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "action": "Microsoft.Network/localNetworkGateways/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "action": "Microsoft.Network/localNetworkGateways/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "e77cc504-0270-4752-a867-d4d0a3c5d8dc",
  "EventDataId": "1b64d4b7-0eea-11af-328a-0eda4b13cb2d",
  "EventSubmissionTimestamp": "2026-07-02T18:23:50.5406819Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/LOCALNETWORKGATEWAYS/DELETE",
  "Properties": {
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "message": "Microsoft.Network/localNetworkGateways/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1b64d4b7-0eea-11af-328a-0eda4b13cb2d",
    "eventSubmissionTimestamp": "2026-07-02T18:23:50.5406819Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aflocalnetworkga",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "NoContent"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "message": "Microsoft.Network/localNetworkGateways/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1b64d4b7-0eea-11af-328a-0eda4b13cb2d",
    "eventSubmissionTimestamp": "2026-07-02T18:23:50.5406819Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aflocalnetworkga",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "activitySubstatusValue": "NoContent"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/localnetworkgateways/write

#
Namespace
Microsoft.Network

Description

Creates or updates an existing LocalNetworkGateway

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "BadRequest",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "action": "Microsoft.Network/localNetworkGateways/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "action": "Microsoft.Network/localNetworkGateways/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "7c76074f-57ae-4586-96cc-1ebd43fd70e2",
  "EventDataId": "55113cf6-39b9-e96b-6509-fba7c592d875",
  "EventSubmissionTimestamp": "2026-07-02T18:23:48.8773102Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.NETWORK/LOCALNETWORKGATEWAYS/WRITE",
  "Properties": {
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "LocalNetworkGatewayCannotHaveEmptyAddressPrefixAndBgpSettings",
        "message": "The local network gateway /subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga cannot have both empty address prefix and empty BGP Settings.",
        "details": []
      }
    },
    "responseBody": {
      "error": {
        "code": "LocalNetworkGatewayCannotHaveEmptyAddressPrefixAndBgpSettings",
        "message": "The local network gateway /subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga cannot have both empty address prefix and empty BGP Settings.",
        "details": []
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "message": "Microsoft.Network/localNetworkGateways/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "55113cf6-39b9-e96b-6509-fba7c592d875",
    "eventSubmissionTimestamp": "2026-07-02T18:23:48.8773102Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aflocalnetworkga",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "BadRequest"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga",
    "message": "Microsoft.Network/localNetworkGateways/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "55113cf6-39b9-e96b-6509-fba7c592d875",
    "eventSubmissionTimestamp": "2026-07-02T18:23:48.8773102Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aflocalnetworkga",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "activitySubstatusValue": "BadRequest",
    "responseBody": {
      "error": {
        "code": "LocalNetworkGatewayCannotHaveEmptyAddressPrefixAndBgpSettings",
        "message": "The local network gateway /subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga cannot have both empty address prefix and empty BGP Settings.",
        "details": []
      }
    },
    "statusMessage": {
      "error": {
        "code": "LocalNetworkGatewayCannotHaveEmptyAddressPrefixAndBgpSettings",
        "message": "The local network gateway /subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/localNetworkGateways/dwh2220aflocalnetworkga cannot have both empty address prefix and empty BGP Settings.",
        "details": []
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/locations/bareMetalTenants/action

#
Namespace
Microsoft.Network

Description

Allocates or validates a Bare Metal Tenant

Microsoft.Network/locations/batchNotifyPrivateEndpointsForResourceMove/action

#
Namespace
Microsoft.Network

Description

Notifies to private endpoint in batches for resource move.

Microsoft.Network/locations/batchValidatePrivateEndpointsForResourceMove/action

#
Namespace
Microsoft.Network

Description

Validates private endpoints in batches for resource move.

Microsoft.Network/locations/checkAcceleratedNetworkingSupport/action

#
Namespace
Microsoft.Network

Description

Checks Accelerated Networking support

Microsoft.Network/locations/checkPrivateLinkServiceVisibility/action

#
Namespace
Microsoft.Network

Description

Checks Private Link Service Visibility

Microsoft.Network/locations/commitInternalAzureNetworkManagerConfiguration/action

#
Namespace
Microsoft.Network

Description

Commits Internal AzureNetworkManager Configuration In ANM

Microsoft.Network/locations/dataTasks/run/action

#
Namespace
Microsoft.Network

Description

Runs Data Task

Microsoft.Network/locations/deletePacketTagging/action

#
Namespace
Microsoft.Network

Description

Deletes Packet Tagging

Microsoft.Network/locations/effectiveResourceOwnership/action

#
Namespace
Microsoft.Network

Description

Gets Effective Resource Ownership

Microsoft.Network/locations/getAzureNetworkManagerConfiguration/action

#
Namespace
Microsoft.Network

Description

Gets Azure Network Manager Configuration

Microsoft.Network/locations/getPacketTagging/action

#
Namespace
Microsoft.Network

Description

Gets Packet Tagging

Microsoft.Network/locations/internalAzureVirtualNetworkManagerOperation/action

#
Namespace
Microsoft.Network

Description

Internal AzureVirtualNetworkManager Operation In ANM

Microsoft.Network/locations/privateLinkServices/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes an private endpoint connection proxy resource.

Microsoft.Network/locations/privateLinkServices/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.Network

Description

Creates a new private endpoint connection proxy, or updates an existing private endpoint connection proxy.

Microsoft.Network/locations/publicIPAddresses/cleanupDdppReference/action

#
Namespace
Microsoft.Network

Description

Cleanup DDPP reference on linked PublicIP upon DDPP subscription delete

Microsoft.Network/locations/publishResources/action

#
Namespace
Microsoft.Network

Description

Publish Subscrioption Resources

Microsoft.Network/locations/PutResourcePubsubData/action

#
Namespace
Microsoft.Network

Description

Put Resource PubSub Data

Microsoft.Network/locations/queryNetworkSecurityPerimeter/action

#
Namespace
Microsoft.Network

Description

Queries Network Security Perimeter by the perimeter GUID

Microsoft.Network/locations/rnmEffectiveNetworkSecurityGroups/action

#
Namespace
Microsoft.Network

Description

Gets Effective Security Groups Configured In Rnm Format

Microsoft.Network/locations/rnmEffectiveRouteTable/action

#
Namespace
Microsoft.Network

Description

Gets Effective Routes Configured In Rnm Format

Microsoft.Network/locations/setAzureNetworkManagerConfiguration/action

#
Namespace
Microsoft.Network

Description

Sets Azure Network Manager Configuration

Microsoft.Network/locations/setLbBackendAdminState/action

#
Namespace
Microsoft.Network

Description

Sets admin state for load balancer backend addresses associated with the specified virtual machines or VM scale set instances

Microsoft.Network/locations/setLoadBalancerFrontendPublicIpAddresses/action

#
Namespace
Microsoft.Network

Description

SetLoadBalancerFrontendPublicIpAddresses targets frontend IP configurations of 2 load balancers. Azure Resource Manager IDs of the IP configurations are provided in the body of the request.

Microsoft.Network/locations/setResourceOwnership/action

#
Namespace
Microsoft.Network

Description

Sets Resource Ownership

Microsoft.Network/locations/startPacketTagging/action

#
Namespace
Microsoft.Network

Description

Starts Packet Tagging

Microsoft.Network/locations/validateResourceOwnership/action

#
Namespace
Microsoft.Network

Description

Validates Resource Ownership

Microsoft.Network/locations/virtualNetworks/cleanupDdppReference/action

#
Namespace
Microsoft.Network

Description

Cleanup DDPP reference on linked VNET upon DDPP subscription delete

Microsoft.Network/masterCustomIpPrefixes/delete

#
Namespace
Microsoft.Network

Description

Deletes A Master Custom Ip Prefix

Microsoft.Network/masterCustomIpPrefixes/write

#
Namespace
Microsoft.Network

Description

Creates A Master Custom Ip Prefix Or Updates An Existing Master Custom Ip Prefix

Microsoft.Network/natGateways/delete

#
Namespace
Microsoft.Network

Description

Delete Nat Gateway

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "action": "Microsoft.Network/natGateways/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "action": "Microsoft.Network/natGateways/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "30ff168e-dd16-49b2-9cd2-ba17f24e4f8f",
  "EventDataId": "88e851b3-0d72-d74c-a936-84f980144490",
  "EventSubmissionTimestamp": "2026-07-02T17:15:50.4312515Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/NATGATEWAYS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "message": "Microsoft.Network/natGateways/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "88e851b3-0d72-d74c-a936-84f980144490",
    "eventSubmissionTimestamp": "2026-07-02T17:15:50.4312515Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0natgw",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "message": "Microsoft.Network/natGateways/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "88e851b3-0d72-d74c-a936-84f980144490",
    "eventSubmissionTimestamp": "2026-07-02T17:15:50.4312515Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0natgw",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/natGateways/join/action

#
Namespace
Microsoft.Network

Description

Joins a NAT Gateway

Microsoft.Network/natGateways/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Nat Gateway

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "action": "Microsoft.Network/natGateways/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "action": "Microsoft.Network/natGateways/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "c564e384-da2f-46c4-9e09-9e2c5fde0ac7",
  "EventDataId": "7b82c5ea-c29f-816a-483e-1984f15f63ec",
  "EventSubmissionTimestamp": "2026-07-02T17:15:44.4885532Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/NATGATEWAYS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "message": "Microsoft.Network/natGateways/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7b82c5ea-c29f-816a-483e-1984f15f63ec",
    "eventSubmissionTimestamp": "2026-07-02T17:15:44.4885532Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0natgw",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/natGateways/dwh92eef0natgw",
    "message": "Microsoft.Network/natGateways/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7b82c5ea-c29f-816a-483e-1984f15f63ec",
    "eventSubmissionTimestamp": "2026-07-02T17:15:44.4885532Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0natgw",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/networkExperimentProfiles/delete

#
Namespace
Microsoft.Network

Description

Delete an Internet Analyzer profile

Microsoft.Network/networkExperimentProfiles/experiments/delete

#
Namespace
Microsoft.Network

Description

Delete an Internet Analyzer test

Microsoft.Network/networkExperimentProfiles/experiments/latencyScorecard/action

#
Namespace
Microsoft.Network

Description

Get an Internet Analyzer test's latency scorecard

Microsoft.Network/networkExperimentProfiles/experiments/timeseries/action

#
Namespace
Microsoft.Network

Description

Get an Internet Analyzer test's time series

Microsoft.Network/networkExperimentProfiles/experiments/write

#
Namespace
Microsoft.Network

Description

Create or update an Internet Analyzer test

Microsoft.Network/networkExperimentProfiles/write

#
Namespace
Microsoft.Network

Description

Create or update an Internet Analyzer profile

Microsoft.Network/networkIntentPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes an Network Intent Policy

Microsoft.Network/networkIntentPolicies/join/action

#
Namespace
Microsoft.Network

Description

Joins a Network Intent Policy. Not alertable.

Microsoft.Network/networkIntentPolicies/write

#
Namespace
Microsoft.Network

Description

Creates an Network Intent Policy or updates an existing Network Intent Policy

Microsoft.Network/networkInterfaces/delete

#
Namespace
Microsoft.Network

Description

Deletes a network interface

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "NoContent",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/dwh38d665vmVMNic",
    "action": "Microsoft.Network/networkInterfaces/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/dwh38d665vmVMNic",
    "action": "Microsoft.Network/networkInterfaces/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "a4d8e876-788e-4efc-831e-7562d2c12909",
  "EventDataId": "8fd465d7-321b-e93f-ca4d-d9feef3c88bc",
  "EventSubmissionTimestamp": "2026-07-28T04:14:08.3142549Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKINTERFACES/DELETE",
  "Properties": {
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/dwh38d665vmVMNic",
    "message": "Microsoft.Network/networkInterfaces/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8fd465d7-321b-e93f-ca4d-d9feef3c88bc",
    "eventSubmissionTimestamp": "2026-07-28T04:14:08.3142549Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vmvmnic",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "NoContent"
  },
  "Properties_d": {
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/dwh38d665vmVMNic",
    "message": "Microsoft.Network/networkInterfaces/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8fd465d7-321b-e93f-ca4d-d9feef3c88bc",
    "eventSubmissionTimestamp": "2026-07-28T04:14:08.3142549Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh38d665vmvmnic",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "NoContent"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/networkInterfaces/effectiveNetworkSecurityGroups/action

#
Namespace
Microsoft.Network

Description

Get Network Security Groups configured On Network Interface Of The Vm

Microsoft.Network/networkInterfaces/effectiveRouteTable/action

#
Namespace
Microsoft.Network

Description

Get Route Table configured On Network Interface Of The Vm

Microsoft.Network/networkInterfaces/ipconfigurations/join/action

#
Namespace
Microsoft.Network

Description

Joins a Network Interface IP Configuration. Not alertable.

Microsoft.Network/networkInterfaces/join/action

#

Microsoft.Network/networkInterfaces/tapConfigurations/delete

#

Microsoft.Network/networkInterfaces/tapConfigurations/write

#
Namespace
Microsoft.Network

Description

Creates a Network Interface Tap Configuration or updates an existing Network Interface Tap Configuration.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/networkInterfaces/UpdateParentNicAttachmentOnElasticNic/action

#
Namespace
Microsoft.Network

Description

Updates the parent NIC associated to the elastic NIC

Microsoft.Network/networkInterfaces/write

#
Namespace
Microsoft.Network

Description

Creates a network interface or updates an existing network interface.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic",
    "action": "Microsoft.Network/networkInterfaces/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic",
    "action": "Microsoft.Network/networkInterfaces/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
  "EventDataId": "b55dc945-962c-8050-f3c4-53c4cd4a1410",
  "EventSubmissionTimestamp": "2026-06-29T18:02:41.7946944Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKINTERFACES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcvmVMNic",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic",
      "etag": "W/\"7cf861b2-5206-4329-968b-a00a72f9dcd1\"",
      "tags": "******",
      "properties": {
        "provisioningState": "Succeeded",
        "resourceGuid": "2a1f590b-c9ae-4e82-a861-64946830289f",
        "ipConfigurations": [
          {
            "name": "ipconfigzcvm",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic/ipConfigurations/ipconfigzcvm",
            "etag": "W/\"7cf861b2-5206-4329-968b-a00a72f9dcd1\"",
            "type": "Microsoft.Network/networkInterfaces/ipConfigurations",
            "properties": {
              "provisioningState": "Succeeded",
              "privateIPAddress": "10.42.1.4",
              "privateIPAllocationMethod": "Dynamic",
              "subnet": {
                "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/zcvnet/subnets/zcsub"
              },
              "primary": true
            }
          }
        ],
        "dnsSettings": {
          "dnsServers": [],
          "appliedDnsServers": []
        },
        "enableIPForwarding": false
      },
      "type": "Microsoft.Network/networkInterfaces",
      "location": "westus2"
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic",
    "message": "Microsoft.Network/networkInterfaces/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b55dc945-962c-8050-f3c4-53c4cd4a1410",
    "eventSubmissionTimestamp": "2026-06-29T18:02:41.7946944Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvmvmnic",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic",
    "message": "Microsoft.Network/networkInterfaces/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b55dc945-962c-8050-f3c4-53c4cd4a1410",
    "eventSubmissionTimestamp": "2026-06-29T18:02:41.7946944Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvmvmnic",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcvmVMNic",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic",
      "etag": "W/\"7cf861b2-5206-4329-968b-a00a72f9dcd1\"",
      "tags": "******",
      "properties": {
        "provisioningState": "Succeeded",
        "resourceGuid": "2a1f590b-c9ae-4e82-a861-64946830289f",
        "ipConfigurations": [
          {
            "name": "ipconfigzcvm",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkInterfaces/zcvmVMNic/ipConfigurations/ipconfigzcvm",
            "etag": "W/\"7cf861b2-5206-4329-968b-a00a72f9dcd1\"",
            "type": "Microsoft.Network/networkInterfaces/ipConfigurations",
            "properties": {
              "provisioningState": "Succeeded",
              "privateIPAddress": "10.42.1.4",
              "privateIPAllocationMethod": "Dynamic",
              "subnet": {
                "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/zcvnet/subnets/zcsub"
              },
              "primary": true
            }
          }
        ],
        "dnsSettings": {
          "dnsServers": [],
          "appliedDnsServers": []
        },
        "enableIPForwarding": false
      },
      "type": "Microsoft.Network/networkInterfaces",
      "location": "westus2"
    },
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:02:41.7946944Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/networkinterfaces/zcvmvmnic"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/networkManagerConnections/delete

#
Namespace
Microsoft.Network

Description

Delete Network Manager Connection

Microsoft.Network/networkManagerConnections/write

#
Namespace
Microsoft.Network

Description

Create Or Update Network Manager Connection

Microsoft.Network/networkManagers/commit/action

#
Namespace
Microsoft.Network

Description

Network Manager Commit

Microsoft.Network/networkManagers/connectivityConfigurations/delete

#
Namespace
Microsoft.Network

Description

Delete Connectivity Configuration

Microsoft.Network/networkManagers/connectivityConfigurations/write

#
Namespace
Microsoft.Network

Description

Create Or Update Connectivity Configuration

Microsoft.Network/networkManagers/delete

#
Namespace
Microsoft.Network

Description

Delete Network Manager

Microsoft.Network/networkManagers/ipamPools/allocateAzureResource/action

#
Namespace
Microsoft.Network

Description

Allocate CIDR range for Azure resource from Ipam Pool

Microsoft.Network/networkManagers/ipamPools/allocateNonAzureResource/action

#
Namespace
Microsoft.Network

Description

Allocate CIDR range for non Azure resource from Ipam Pool

Microsoft.Network/networkManagers/ipamPools/allocateResourcePrefixes/action

#
Namespace
Microsoft.Network

Description

Allocate CIDR Range for Resource from Ipam Pool

Microsoft.Network/networkManagers/ipamPools/associatedResources/action

#
Namespace
Microsoft.Network

Description

Action permission for list Associated Resource To Ipam Pool

Microsoft.Network/networkManagers/ipamPools/associateResourcesToPool/action

#
Namespace
Microsoft.Network

Description

Action permission for associate resources to Ipam Pool

Microsoft.Network/networkManagers/ipamPools/delete

#
Namespace
Microsoft.Network

Description

Deletes a Ipam Pool

Microsoft.Network/networkManagers/ipamPools/disassociateResourcesFromPool/action

#
Namespace
Microsoft.Network

Description

Disassociate Azure resources (i.e. VNet) from Ipam Pool

Microsoft.Network/networkManagers/ipamPools/getPoolUsage/action

#
Namespace
Microsoft.Network

Description

Get pool usage for a Ipam Pool

microsoft.network/networkmanagers/ipampools/listassociatedresources/action

#
Namespace
Microsoft.Network

Description

Action permission for list Associated Resource To Ipam Pool

microsoft.network/networkmanagers/ipampools/staticcidrs/delete

#
Namespace
Microsoft.Network

Description

Deletes a static CIDR from an Ipam Pool

microsoft.network/networkmanagers/ipampools/staticcidrs/write

#
Namespace
Microsoft.Network

Description

Creates or updates a static CIDR in an Ipam Pool

Microsoft.Network/networkManagers/ipamPools/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Ipam Pool

Microsoft.Network/networkManagers/listActiveConnectivityConfigurations/action

#
Namespace
Microsoft.Network

Description

Lists Active Connectivity Configurations

Microsoft.Network/networkManagers/listActiveSecurityAdminRules/action

#
Namespace
Microsoft.Network

Description

Lists Active Security Admin Rules

Microsoft.Network/networkManagers/listActiveSecurityUserRules/action

#
Namespace
Microsoft.Network

Description

Lists Active Security User Rules

Microsoft.Network/networkManagers/listDeploymentStatus/action

#
Namespace
Microsoft.Network

Description

List Deployment Status

Microsoft.Network/networkManagers/networkGroups/delete

#
Namespace
Microsoft.Network

Description

Delete Network Group

Microsoft.Network/networkManagers/networkGroups/join/action

#
Namespace
Microsoft.Network

Description

Join Network Group

Microsoft.Network/networkManagers/networkGroups/staticMembers/delete

#
Namespace
Microsoft.Network

Description

Delete Network Group Static Member

Microsoft.Network/networkManagers/networkGroups/staticMembers/write

#
Namespace
Microsoft.Network

Description

Create Or Update Network Group Static Member

Microsoft.Network/networkManagers/networkGroups/write

#
Namespace
Microsoft.Network

Description

Create Or Update Network Group

Microsoft.Network/networkManagers/routingConfigurations/delete

#
Namespace
Microsoft.Network

Description

Delete Routing Configuration

Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/delete

#
Namespace
Microsoft.Network

Description

Delete Routing Rule Collection

Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/rules/delete

#
Namespace
Microsoft.Network

Description

Delete Routing Rule

Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/rules/write

#
Namespace
Microsoft.Network

Description

Create Or Update Routing Rule

Microsoft.Network/networkManagers/routingConfigurations/ruleCollections/write

#
Namespace
Microsoft.Network

Description

Create Or Update Routing Rule Collection

Microsoft.Network/networkManagers/routingConfigurations/write

#
Namespace
Microsoft.Network

Description

Create Or Update Routing Configuration

Microsoft.Network/networkManagers/scopeConnections/delete

#
Namespace
Microsoft.Network

Description

Delete Network Manager Scope Connection

Microsoft.Network/networkManagers/scopeConnections/write

#
Namespace
Microsoft.Network

Description

Create Or Update Network Manager Scope Connection

Microsoft.Network/networkManagers/securityAdminConfigurations/delete

#
Namespace
Microsoft.Network

Description

Delete Security Admin Configuration

Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/delete

#
Namespace
Microsoft.Network

Description

Delete Security Admin Rule Collection

Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/rules/delete

#
Namespace
Microsoft.Network

Description

Delete Security Admin Rule

Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/rules/write

#
Namespace
Microsoft.Network

Description

Create Or Update Security Admin Rule

Microsoft.Network/networkManagers/securityAdminConfigurations/ruleCollections/write

#
Namespace
Microsoft.Network

Description

Create Or Update Security Admin Rule Collection

Microsoft.Network/networkManagers/securityAdminConfigurations/write

#
Namespace
Microsoft.Network

Description

Create Or Update Security Admin Configuration

Microsoft.Network/networkManagers/securityUserConfigurations/delete

#
Namespace
Microsoft.Network

Description

Delete Security User Configuration

Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/delete

#
Namespace
Microsoft.Network

Description

Delete Security User Rule Collection

Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/rules/delete

#
Namespace
Microsoft.Network

Description

Delete Security User Rule

Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/rules/write

#
Namespace
Microsoft.Network

Description

Create Or Update Security User Rule

Microsoft.Network/networkManagers/securityUserConfigurations/ruleCollections/write

#
Namespace
Microsoft.Network

Description

Create Or Update Security User Rule Collection

Microsoft.Network/networkManagers/securityUserConfigurations/write

#
Namespace
Microsoft.Network

Description

Create Or Update Security User Configuration

Microsoft.Network/networkManagers/verifierWorkspaces/delete

#
Namespace
Microsoft.Network

Description

Deletes a Verifier Workspace

Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisIntents/delete

#
Namespace
Microsoft.Network

Description

Deletes a Reachability Analysis Intent

Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisIntents/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Reachability Analysis Intent

Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisRuns/delete

#
Namespace
Microsoft.Network

Description

Deletes a Reachability Analysis Run

Microsoft.Network/networkManagers/verifierWorkspaces/reachabilityAnalysisRuns/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Reachability Analysis Run

Microsoft.Network/networkManagers/verifierWorkspaces/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Verifier Workspace

Microsoft.Network/networkManagers/write

#
Namespace
Microsoft.Network

Description

Create Or Update Network Manager

Microsoft.Network/networkProfiles/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Profile

Microsoft.Network/networkProfiles/removeContainers/action

#
Namespace
Microsoft.Network

Description

Removes Containers

Microsoft.Network/networkProfiles/setContainers/action

#
Namespace
Microsoft.Network

Description

Sets Containers

Microsoft.Network/networkProfiles/setNetworkInterfaces/action

#
Namespace
Microsoft.Network

Description

Sets Container Network Interfaces

Microsoft.Network/networkProfiles/write

#
Namespace
Microsoft.Network

Description

Creates or updates a Network Profile

Microsoft.Network/networkSecurityGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes a network security group

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg",
    "action": "Microsoft.Network/networkSecurityGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg",
    "action": "Microsoft.Network/networkSecurityGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "923e602a-81cf-4485-880c-0f72ae08f863",
  "EventDataId": "8dad7bd8-c480-9d6c-08be-bf07b69c92d2",
  "EventSubmissionTimestamp": "2026-06-29T17:46:28.2996691Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg",
    "message": "Microsoft.Network/networkSecurityGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8dad7bd8-c480-9d6c-08be-bf07b69c92d2",
    "eventSubmissionTimestamp": "2026-06-29T17:46:28.2996691Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg",
    "message": "Microsoft.Network/networkSecurityGroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8dad7bd8-c480-9d6c-08be-bf07b69c92d2",
    "eventSubmissionTimestamp": "2026-06-29T17:46:28.2996691Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:46:28.2996691Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/networksecuritygroups/zcnsg"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

Microsoft.Network/networkSecurityGroups/join/action

#
Namespace
Microsoft.Network

Description

Joins a network security group. Not Alertable.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

Microsoft.Network/networksecuritygroups/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the Network Security Groups diagnostic settings, this operation is supplemented by insights resource provider.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

Microsoft.Network/networkSecurityGroups/securityRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a security rule

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg/securityRules/zcrule",
    "action": "Microsoft.Network/networkSecurityGroups/securityRules/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg/securityRules/zcrule",
    "action": "Microsoft.Network/networkSecurityGroups/securityRules/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "f07893dd-4d47-44be-b28b-3f818ad7a04d",
  "EventDataId": "403afd45-dbf2-707e-586e-8fc1dcd42392",
  "EventSubmissionTimestamp": "2026-06-29T17:46:22.8046279Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/SECURITYRULES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg/securityRules/zcrule",
    "message": "Microsoft.Network/networkSecurityGroups/securityRules/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "403afd45-dbf2-707e-586e-8fc1dcd42392",
    "eventSubmissionTimestamp": "2026-06-29T17:46:22.8046279Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg/zcrule",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg/securityRules/zcrule",
    "message": "Microsoft.Network/networkSecurityGroups/securityRules/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "403afd45-dbf2-707e-586e-8fc1dcd42392",
    "eventSubmissionTimestamp": "2026-06-29T17:46:22.8046279Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg/zcrule",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:46:22.8046279Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/networksecuritygroups/zcnsg/securityrules/zcrule"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

Microsoft.Network/networkSecurityGroups/securityRules/write

#
Namespace
Microsoft.Network

Description

Creates a security rule or updates an existing security rule

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/securityRules/r",
    "action": "Microsoft.Network/networkSecurityGroups/securityRules/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/securityRules/r",
    "action": "Microsoft.Network/networkSecurityGroups/securityRules/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "061dfa78-b770-4f39-a0c4-e543b1b0f009",
  "EventDataId": "72a0a514-bb8c-d5fb-6957-b5598f8c1e40",
  "EventSubmissionTimestamp": "2026-06-29T19:02:05.0211795Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/SECURITYRULES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "r",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/securityRules/r",
      "etag": "W/\"38e0ff1e-4b96-46a7-b431-59f524ceefd8\"",
      "type": "Microsoft.Network/networkSecurityGroups/securityRules",
      "properties": {
        "provisioningState": "Updating",
        "protocol": "Tcp",
        "sourcePortRange": "*",
        "destinationPortRange": "22",
        "sourceAddressPrefix": "*",
        "destinationAddressPrefix": "*",
        "access": "Allow",
        "priority": 100,
        "direction": "Inbound",
        "sourcePortRanges": [],
        "destinationPortRanges": [],
        "sourceAddressPrefixes": [],
        "destinationAddressPrefixes": []
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/securityRules/r",
    "message": "Microsoft.Network/networkSecurityGroups/securityRules/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "72a0a514-bb8c-d5fb-6957-b5598f8c1e40",
    "eventSubmissionTimestamp": "2026-06-29T19:02:05.0211795Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg3/r",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "r",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/securityRules/r",
      "etag": "W/\"38e0ff1e-4b96-46a7-b431-59f524ceefd8\"",
      "type": "Microsoft.Network/networkSecurityGroups/securityRules",
      "properties": {
        "provisioningState": "Updating",
        "protocol": "Tcp",
        "sourcePortRange": "*",
        "destinationPortRange": "22",
        "sourceAddressPrefix": "*",
        "destinationAddressPrefix": "*",
        "access": "Allow",
        "priority": 100,
        "direction": "Inbound",
        "sourcePortRanges": [],
        "destinationPortRanges": [],
        "sourceAddressPrefixes": [],
        "destinationAddressPrefixes": []
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/securityRules/r",
    "message": "Microsoft.Network/networkSecurityGroups/securityRules/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "72a0a514-bb8c-d5fb-6957-b5598f8c1e40",
    "eventSubmissionTimestamp": "2026-06-29T19:02:05.0211795Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg3/r",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:05.0211795Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/networksecuritygroups/zcnsg3/securityrules/r"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
properties.statusCode (sigma rule field)eqcreated1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

Microsoft.Network/networkSecurityGroups/write

#
Namespace
Microsoft.Network

Description

Creates a network security group or updates an existing network security group

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3",
    "action": "Microsoft.Network/networkSecurityGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3",
    "action": "Microsoft.Network/networkSecurityGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "23087631-d74f-41bd-afca-5c55c0747021",
  "EventDataId": "304bd4d8-e4b4-9a35-966b-dda969e54996",
  "EventSubmissionTimestamp": "2026-06-29T19:02:02.4492674Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcnsg3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3",
      "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
      "type": "Microsoft.Network/networkSecurityGroups",
      "location": "westus2",
      "properties": {
        "provisioningState": "Updating",
        "resourceGuid": "5242775b-6ebd-40fa-a1d0-261184036c09",
        "securityRules": [],
        "defaultSecurityRules": [
          {
            "name": "AllowVnetInBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowVnetInBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow inbound traffic from all VMs in VNET",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "VirtualNetwork",
              "destinationAddressPrefix": "VirtualNetwork",
              "access": "Allow",
              "priority": 65000,
              "direction": "Inbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "AllowAzureLoadBalancerInBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowAzureLoadBalancerInBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow inbound traffic from azure load balancer",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "AzureLoadBalancer",
              "destinationAddressPrefix": "*",
              "access": "Allow",
              "priority": 65001,
              "direction": "Inbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "DenyAllInBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/DenyAllInBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Deny all inbound traffic",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "*",
              "access": "Deny",
              "priority": 65500,
              "direction": "Inbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "AllowVnetOutBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowVnetOutBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow outbound traffic from all VMs to all VMs in VNET",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "VirtualNetwork",
              "destinationAddressPrefix": "VirtualNetwork",
              "access": "Allow",
              "priority": 65000,
              "direction": "Outbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "AllowInternetOutBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowInternetOutBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow outbound traffic from all VMs to Internet",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "Internet",
              "access": "Allow",
              "priority": 65001,
              "direction": "Outbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "DenyAllOutBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/DenyAllOutBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Deny all outbound traffic",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "*",
              "access": "Deny",
              "priority": 65500,
              "direction": "Outbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          }
        ]
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3",
    "message": "Microsoft.Network/networkSecurityGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "304bd4d8-e4b4-9a35-966b-dda969e54996",
    "eventSubmissionTimestamp": "2026-06-29T19:02:02.4492674Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcnsg3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3",
      "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
      "type": "Microsoft.Network/networkSecurityGroups",
      "location": "westus2",
      "properties": {
        "provisioningState": "Updating",
        "resourceGuid": "5242775b-6ebd-40fa-a1d0-261184036c09",
        "securityRules": [],
        "defaultSecurityRules": [
          {
            "name": "AllowVnetInBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowVnetInBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow inbound traffic from all VMs in VNET",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "VirtualNetwork",
              "destinationAddressPrefix": "VirtualNetwork",
              "access": "Allow",
              "priority": 65000,
              "direction": "Inbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "AllowAzureLoadBalancerInBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowAzureLoadBalancerInBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow inbound traffic from azure load balancer",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "AzureLoadBalancer",
              "destinationAddressPrefix": "*",
              "access": "Allow",
              "priority": 65001,
              "direction": "Inbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "DenyAllInBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/DenyAllInBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Deny all inbound traffic",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "*",
              "access": "Deny",
              "priority": 65500,
              "direction": "Inbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "AllowVnetOutBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowVnetOutBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow outbound traffic from all VMs to all VMs in VNET",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "VirtualNetwork",
              "destinationAddressPrefix": "VirtualNetwork",
              "access": "Allow",
              "priority": 65000,
              "direction": "Outbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "AllowInternetOutBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/AllowInternetOutBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Allow outbound traffic from all VMs to Internet",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "Internet",
              "access": "Allow",
              "priority": 65001,
              "direction": "Outbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          },
          {
            "name": "DenyAllOutBound",
            "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3/defaultSecurityRules/DenyAllOutBound",
            "etag": "W/\"ba2ee45d-8e31-48e3-b005-1d2601d63c25\"",
            "type": "Microsoft.Network/networkSecurityGroups/defaultSecurityRules",
            "properties": {
              "provisioningState": "Updating",
              "description": "Deny all outbound traffic",
              "protocol": "*",
              "sourcePortRange": "*",
              "destinationPortRange": "*",
              "sourceAddressPrefix": "*",
              "destinationAddressPrefix": "*",
              "access": "Deny",
              "priority": 65500,
              "direction": "Outbound",
              "sourcePortRanges": [],
              "destinationPortRanges": [],
              "sourceAddressPrefixes": [],
              "destinationAddressPrefixes": []
            }
          }
        ]
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/networkSecurityGroups/zcnsg3",
    "message": "Microsoft.Network/networkSecurityGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "304bd4d8-e4b4-9a35-966b-dda969e54996",
    "eventSubmissionTimestamp": "2026-06-29T19:02:02.4492674Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcnsg3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:02.4492674Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/networksecuritygroups/zcnsg3"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ActivityStatusValue (kusto rule field)eqsuccess1 rulekusto
count_ (kusto rule field)ge51 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

Microsoft.Network/networkSecurityPerimeters/backingResourceAssociations/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter Backing Resource Association

Microsoft.Network/networkSecurityPerimeters/backingResourceAssociations/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter Backing Resource Association

Microsoft.Network/networkSecurityPerimeters/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter

Microsoft.Network/networkSecurityPerimeters/joinPerimeterRule/action

#
Namespace
Microsoft.Network

Description

Joins an NSP Access Rule

Microsoft.Network/networkSecurityPerimeters/linkPerimeter/action

#
Namespace
Microsoft.Network

Description

Link Perimeter in Auto-Approval mode

Microsoft.Network/networkSecurityPerimeters/linkProxies/write

#
Namespace
Microsoft.Network

Description

Updates a Network Security Perimeter Link Proxy

Microsoft.Network/networkSecurityPerimeters/linkReferenceProxies/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter LinkReference Proxy

Microsoft.Network/networkSecurityPerimeters/linkReferences/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter LinkReference

Microsoft.Network/networkSecurityPerimeters/linkReferences/reconcile/action

#
Namespace
Microsoft.Network

Description

Reconciles a Network Security Perimeter LinkReference

Microsoft.Network/networkSecurityPerimeters/linkReferences/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter LinkReference

Microsoft.Network/networkSecurityPerimeters/links/delete

#
Namespace
Microsoft.Network

Microsoft.Network/networkSecurityPerimeters/links/write

#
Namespace
Microsoft.Network

Microsoft.Network/networkSecurityPerimeters/loggingConfigurations/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter Logging Configuration

Microsoft.Network/networkSecurityPerimeters/loggingConfigurations/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter Logging Configuration

Microsoft.Network/networkSecurityPerimeters/profiles/accessRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter Access Rule

Microsoft.Network/networkSecurityPerimeters/profiles/accessRules/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter Access Rule

Microsoft.Network/networkSecurityPerimeters/profiles/checkMembers/action

#
Namespace
Microsoft.Network

Description

Checks if members can be accessed or not

Microsoft.Network/networkSecurityPerimeters/profiles/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter Profile

Microsoft.Network/networkSecurityPerimeters/profiles/join/action

#
Namespace
Microsoft.Network

Description

Joins a Network Security Perimeter Profile

Microsoft.Network/networkSecurityPerimeters/profiles/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter Profile

Microsoft.Network/networkSecurityPerimeters/resourceAssociationProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter Resource Association Proxy

Microsoft.Network/networkSecurityPerimeters/resourceAssociationProxies/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter Resource Association Proxy

Microsoft.Network/networkSecurityPerimeters/resourceAssociations/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Security Perimeter Resource Association

Microsoft.Network/networkSecurityPerimeters/resourceAssociations/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter Resource Association

Microsoft.Network/networkSecurityPerimeters/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Security Perimeter

Microsoft.Network/networkVerifiers/analysisIntents/analysisRuns/delete

#
Namespace
Microsoft.Network

Description

Deletes a Analysis Run

Microsoft.Network/networkVerifiers/analysisIntents/analysisRuns/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Analysis Run

Microsoft.Network/networkVerifiers/analysisIntents/delete

#
Namespace
Microsoft.Network

Description

Deletes a Analysis Intent

Microsoft.Network/networkVerifiers/analysisIntents/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Analysis Intent

Microsoft.Network/networkVerifiers/configurationSnapshots/delete

#
Namespace
Microsoft.Network

Description

Deletes a Configuration Snapshot

Microsoft.Network/networkVerifiers/configurationSnapshots/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Configuration Snapshot

Microsoft.Network/networkVerifiers/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Verifier

Microsoft.Network/networkVerifiers/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Network Verifier

Microsoft.Network/networkVirtualAppliances/delete

#

Microsoft.Network/networkVirtualAppliances/getBootDiagnosticLogs/action

#
Namespace
Microsoft.Network

Description

Get Network Virtual Appliance Boot Diagnostic Logs

Microsoft.Network/networkVirtualAppliances/getDelegatedSubnets/action

#
Namespace
Microsoft.Network

Description

Get Network Virtual Appliance delegated subnets

Microsoft.Network/networkVirtualAppliances/getVmssResourceId/action

#
Namespace
Microsoft.Network

Description

Get VMSS Resource ID

Microsoft.Network/networkVirtualAppliances/inboundSecurityRules/delete

#
Namespace
Microsoft.Network

Description

Delete a InboundSecurityRule

Microsoft.Network/networkVirtualAppliances/inboundSecurityRules/write

#
Namespace
Microsoft.Network

Description

Create or update a InboundSecurityRule

Microsoft.Network/networkVirtualAppliances/networkVirtualApplianceConnections/delete

#
Namespace
Microsoft.Network

Description

Delete a Network Virtual Appliance Connection

Microsoft.Network/networkVirtualAppliances/networkVirtualApplianceConnections/write

#
Namespace
Microsoft.Network

Description

Update a Network Virtual Appliance Connection

Microsoft.Network/networkVirtualAppliances/reimage/action

#
Namespace
Microsoft.Network

Description

Reimage Network Virtual Appliance

Microsoft.Network/networkVirtualAppliances/restart/action

#
Namespace
Microsoft.Network

Description

Restart Network Virtual Appliance

Microsoft.Network/networkVirtualAppliances/write

#

Microsoft.Network/networkWatchers/agents/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Watcher Agent

Microsoft.Network/networkWatchers/agents/register/action

#
Namespace
Microsoft.Network

Description

Registers a network watcher agent

Microsoft.Network/networkWatchers/agents/write

#
Namespace
Microsoft.Network

Description

Creates a Network Watcher Agent

Microsoft.Network/networkWatchers/availableProvidersList/action

#
Namespace
Microsoft.Network

Description

Returns all available internet service providers for a specified Azure region.

Microsoft.Network/networkWatchers/azureReachabilityReport/action

#
Namespace
Microsoft.Network

Description

Returns the relative latency score for internet service providers from a specified location to Azure regions.

Microsoft.Network/networkWatchers/configureFlowLog/action

#
Namespace
Microsoft.Network

Description

Configures flow logging for a target resource.

Microsoft.Network/networkWatchers/connectionAnalyzers/delete

#
Namespace
Microsoft.Network

Description

Deletes a Connection Analyzer

Microsoft.Network/networkWatchers/connectionAnalyzers/queryStatus/action

#
Namespace
Microsoft.Network

Description

Query status and details of Connection Analyzer

Microsoft.Network/networkWatchers/connectionAnalyzers/write

#
Namespace
Microsoft.Network

Description

Creates a Connection Analyzer

Microsoft.Network/networkWatchers/connectionMonitors/delete

#
Namespace
Microsoft.Network

Description

Deletes a Connection Monitor

Microsoft.Network/networkWatchers/connectionMonitors/query/action

#
Namespace
Microsoft.Network

Description

Query monitoring connectivity between specified endpoints

Microsoft.Network/networkWatchers/connectionMonitors/start/action

#
Namespace
Microsoft.Network

Description

Start monitoring connectivity between specified endpoints

Microsoft.Network/networkWatchers/connectionMonitors/stop/action

#
Namespace
Microsoft.Network

Description

Stop/pause monitoring connectivity between specified endpoints

Microsoft.Network/networkWatchers/connectionMonitors/write

#
Namespace
Microsoft.Network

Description

Creates a Connection Monitor

Microsoft.Network/networkWatchers/connectivityCheck/action

#
Namespace
Microsoft.Network

Description

Verifies the possibility of establishing a direct TCP connection from a virtual machine to a given endpoint including another VM or an arbitrary remote server.

Microsoft.Network/networkWatchers/delete

#
Namespace
Microsoft.Network

Description

Deletes a network watcher

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure VNet Network Watcher Deleted source medium: Identifies the deletion of a Network Watcher in Azure. Network Watchers are used to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network. An adversary may delete a Network Watcher in an attempt to evade defenses.T1562, T1562.001, T1562.008

Panther #

  • Azure Network Watcher Deleted source medium: Detects when an Azure Network Watcher is deleted. Network Watcher is a regional service that enables monitoring and diagnostics for network resources in Azure, including packet capture, connection monitoring, flow logging, and network performance diagnostics. Adversaries may delete Network Watchers to disable network visibility and evade detection during lateral movement, data exfiltration, or other network-based attacks.T1562.001

Microsoft.Network/networkWatchers/flowLogs/delete

#
Namespace
Microsoft.Network

Description

Deletes a Flow Log

Microsoft.Network/networkWatchers/flowLogs/write

#
Namespace
Microsoft.Network

Description

Creates a Flow Log

Microsoft.Network/networkWatchers/ipFlowVerify/action

#
Namespace
Microsoft.Network

Description

Returns whether the packet is allowed or denied to or from a particular destination.

Microsoft.Network/networkWatchers/lenses/delete

#
Namespace
Microsoft.Network

Description

Deletes a Lens

Microsoft.Network/networkWatchers/lenses/query/action

#
Namespace
Microsoft.Network

Description

Query monitoring network traffic on a specified endpoint

Microsoft.Network/networkWatchers/lenses/start/action

#
Namespace
Microsoft.Network

Description

Start monitoring network traffic on a specified endpoint

Microsoft.Network/networkWatchers/lenses/stop/action

#
Namespace
Microsoft.Network

Description

Stop/pause monitoring network traffic on a specified endpoint

Microsoft.Network/networkWatchers/lenses/write

#
Namespace
Microsoft.Network

Description

Creates a Lens

Microsoft.Network/networkWatchers/networkConfigurationDiagnostic/action

#
Namespace
Microsoft.Network

Description

Diagnostic of network configuration.

Microsoft.Network/networkWatchers/nextHop/action

#
Namespace
Microsoft.Network

Description

For a specified target and destination IP address, return the next hop type and next hope IP address.

Microsoft.Network/networkWatchers/packetCaptures/delete

#
Namespace
Microsoft.Network

Description

Deletes a packet capture

Microsoft.Network/networkWatchers/packetCaptures/queryStatus/action

#
Namespace
Microsoft.Network

Description

Gets information about properties and status of a packet capture resource.

Microsoft.Network/networkWatchers/packetCaptures/stop/action

#
Namespace
Microsoft.Network

Description

Stop the running packet capture session.

Microsoft.Network/networkWatchers/packetCaptures/write

#
Namespace
Microsoft.Network

Description

Creates a packet capture

Microsoft.Network/networkWatchers/pingMeshes/delete

#
Namespace
Microsoft.Network

Description

Deletes a PingMesh

Microsoft.Network/networkWatchers/pingMeshes/start/action

#
Namespace
Microsoft.Network

Description

Start PingMesh between specified VMs

Microsoft.Network/networkWatchers/pingMeshes/stop/action

#
Namespace
Microsoft.Network

Description

Stop PingMesh between specified VMs

Microsoft.Network/networkWatchers/pingMeshes/write

#
Namespace
Microsoft.Network

Description

Creates a PingMesh

Microsoft.Network/networkWatchers/queryConnectionMonitors/action

#
Namespace
Microsoft.Network

Description

Batch query monitoring connectivity between specified endpoints

Microsoft.Network/networkWatchers/queryFlowLogStatus/action

#
Namespace
Microsoft.Network

Description

Gets the status of flow logging on a resource.

Microsoft.Network/networkWatchers/queryTroubleshootResult/action

#
Namespace
Microsoft.Network

Description

Gets the troubleshooting result from the previously run or currently running troubleshooting operation.

Microsoft.Network/networkWatchers/securityGroupView/action

#
Namespace
Microsoft.Network

Description

View the configured and effective network security group rules applied on a VM.

Microsoft.Network/networkWatchers/topology/action

#
Namespace
Microsoft.Network

Description

Gets a network level view of resources and their relationships in a resource group.

Microsoft.Network/networkWatchers/troubleshoot/action

#
Namespace
Microsoft.Network

Description

Starts troubleshooting on a Networking resource in Azure.

Microsoft.Network/networkWatchers/write

#
Namespace
Microsoft.Network

Description

Creates a network watcher or updates an existing network watcher

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_westus2",
    "action": "Microsoft.Network/networkWatchers/write",
    "evidence": {
      "role": "Azure Network Service Role",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "38b9f786807649bfbf92c21363fec2de",
      "roleDefinitionId": "13ba9ab419f04804adc414ece36cc7a1",
      "principalId": "d098cd85ed3e43b69a78b60191430ddc",
      "principalType": "ServicePrincipal"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_westus2",
    "action": "Microsoft.Network/networkWatchers/write",
    "evidence": {
      "role": "Azure Network Service Role",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "38b9f786807649bfbf92c21363fec2de",
      "roleDefinitionId": "13ba9ab419f04804adc414ece36cc7a1",
      "principalId": "d098cd85ed3e43b69a78b60191430ddc",
      "principalType": "ServicePrincipal"
    }
  },
  "Caller": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783010170",
    "nbf": "1783010170",
    "exp": "1783096870",
    "aio": "AWQAm/8cAAAALWXjr80jLidYYy7jxMvwaUgLnQeu2nlRoMlfP7wsLMixVBp1ahfl4H10iVDIoD4sAPF3pUoQNE/fAd0OWIxST45MLJqPVVnXJloghpnL2Fvt7imY27kF1NSLX/wQmnhR",
    "appid": "2cf9eb86-36b5-49dc-86ae-9a63135dfa8c",
    "appidacr": "2",
    "http://schemas.microsoft.com/identity/claims/identityprovider": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "idtyp": "app",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAAB4AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "nFS1_m6hnEWAUpisX9oBAA",
    "ver": "1.0",
    "wids": "0997a1d0-0d1d-4acb-b408-d5ca73121e90",
    "xms_act_fct": "3 5",
    "xms_ftd": "G5gfOS6YvVGOXxIkm_H11GABlyggo_3qb8vLbgD-9fMBdXN3ZXN0Mi1kc21z",
    "xms_idrel": "7 24",
    "xms_rd": "0.AW8AkP8KBQgCEgF4EhQICRIQUQFaCpTCQkKUJ3vGiHYN9RIUCAgSEEZIf3kAutdPukPawfj2MBMSFAgLEhCYgW0cJgvBfjFe1LpxvGqHIiQIAxIgYOS2w9wccSIvDSWXhRUYJrVHaMGNSgWx6gEjn6L-6bM",
    "xms_sub_fct": "3 5",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783010170",
    "nbf": "1783010170",
    "exp": "1783096870",
    "aio": "AWQAm/8cAAAALWXjr80jLidYYy7jxMvwaUgLnQeu2nlRoMlfP7wsLMixVBp1ahfl4H10iVDIoD4sAPF3pUoQNE/fAd0OWIxST45MLJqPVVnXJloghpnL2Fvt7imY27kF1NSLX/wQmnhR",
    "appid": "2cf9eb86-36b5-49dc-86ae-9a63135dfa8c",
    "appidacr": "2",
    "http://schemas.microsoft.com/identity/claims/identityprovider": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "idtyp": "app",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAAB4AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "nFS1_m6hnEWAUpisX9oBAA",
    "ver": "1.0",
    "wids": "0997a1d0-0d1d-4acb-b408-d5ca73121e90",
    "xms_act_fct": "3 5",
    "xms_ftd": "G5gfOS6YvVGOXxIkm_H11GABlyggo_3qb8vLbgD-9fMBdXN3ZXN0Mi1kc21z",
    "xms_idrel": "7 24",
    "xms_rd": "0.AW8AkP8KBQgCEgF4EhQICRIQUQFaCpTCQkKUJ3vGiHYN9RIUCAgSEEZIf3kAutdPukPawfj2MBMSFAgLEhCYgW0cJgvBfjFe1LpxvGqHIiQIAxIgYOS2w9wccSIvDSWXhRUYJrVHaMGNSgWx6gEjn6L-6bM",
    "xms_sub_fct": "3 5",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "553b3774-fc41-43a8-9e7e-21683a474470",
  "EventDataId": "9e929ced-fba9-ba74-2ff8-8dd79e6e56ac",
  "EventSubmissionTimestamp": "2026-07-02T17:24:29.1328514Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/NETWORKWATCHERS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_westus2",
    "message": "Microsoft.Network/networkWatchers/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
    "eventDataId": "9e929ced-fba9-ba74-2ff8-8dd79e6e56ac",
    "eventSubmissionTimestamp": "2026-07-02T17:24:29.1328514Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "networkwatcher_westus2",
    "resourceGroup": "NETWORKWATCHERRG",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_westus2",
    "message": "Microsoft.Network/networkWatchers/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "d098cd85-ed3e-43b6-9a78-b60191430ddc",
    "eventDataId": "9e929ced-fba9-ba74-2ff8-8dd79e6e56ac",
    "eventSubmissionTimestamp": "2026-07-02T17:24:29.1328514Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "networkwatcher_westus2",
    "resourceGroup": "NETWORKWATCHERRG",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "NETWORKWATCHERRG",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

microsoft.network/p2sVpnGateways/attach/action

#
Namespace
Microsoft.Network

Description

Attaches a P2SVpnGateway Hub from WAN Traffic manager

Microsoft.Network/p2sVpnGateways/delete

#

microsoft.network/p2sVpnGateways/detach/action

#
Namespace
Microsoft.Network

Description

Detaches a P2SVpnGateway Hub from WAN Traffic manager

Microsoft.Network/p2sVpnGateways/disconnectp2svpnconnections/action

#

Microsoft.Network/p2sVpnGateways/generatevpnprofile/action

#

Microsoft.Network/p2sVpnGateways/getp2svpnconnectionhealth/action

#
Namespace
Microsoft.Network

Description

Gets a P2S Vpn Connection health for P2SVpnGateway

Microsoft.Network/p2sVpnGateways/getp2svpnconnectionhealthdetailed/action

#
Namespace
Microsoft.Network

Description

Gets a P2S Vpn Connection health detailed for P2SVpnGateway

Microsoft.Network/p2sVpnGateways/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the P2S Vpn Gateway diagnostic settings, this operation is supplemented by insights resource provider.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

microsoft.network/p2sVpnGateways/reset/action

#

Microsoft.Network/p2sVpnGateways/write

#

Microsoft.Network/privateDnsZones/A/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'A' from a Private DNS zone.

Microsoft.Network/privateDnsZones/A/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'A' within a Private DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/privateDnsZones/AAAA/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'AAAA' from a Private DNS zone.

Microsoft.Network/privateDnsZones/AAAA/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'AAAA' within a Private DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/privateDnsZones/CNAME/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'CNAME' from a Private DNS zone.

Microsoft.Network/privateDnsZones/CNAME/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'CNAME' within a Private DNS zone.

Microsoft.Network/privateDnsZones/delete

#
Namespace
Microsoft.Network

Description

Delete a Private DNS zone.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "action": "Microsoft.Network/privateDnsZones/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "action": "Microsoft.Network/privateDnsZones/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "bb6b2a37-c4a5-401a-8cfa-bf4d2525f8c6",
  "EventDataId": "9bb4eab6-dd8f-2737-6f08-443d55ad74b5",
  "EventSubmissionTimestamp": "2026-07-02T17:16:54.4218506Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/PRIVATEDNSZONES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "message": "Microsoft.Network/privateDnsZones/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9bb4eab6-dd8f-2737-6f08-443d55ad74b5",
    "eventSubmissionTimestamp": "2026-07-02T17:16:54.4218506Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0pdns.internal",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "message": "Microsoft.Network/privateDnsZones/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9bb4eab6-dd8f-2737-6f08-443d55ad74b5",
    "eventSubmissionTimestamp": "2026-07-02T17:16:54.4218506Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0pdns.internal",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/privateDnsZones/join/action

#
Namespace
Microsoft.Network

Description

Joins a Private DNS Zone

Microsoft.Network/privateDnsZones/MX/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'MX' from a Private DNS zone.

Microsoft.Network/privateDnsZones/MX/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'MX' within a Private DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/privateDnsZones/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the Private DNS zone diagnostic settings

Microsoft.Network/privateDnsZones/PTR/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'PTR' from a Private DNS zone.

Microsoft.Network/privateDnsZones/PTR/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'PTR' within a Private DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/privateDnsZones/SOA/write

#
Namespace
Microsoft.Network

Description

Update a record set of type 'SOA' within a Private DNS zone.

Microsoft.Network/privateDnsZones/SRV/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'SRV' from a Private DNS zone.

Microsoft.Network/privateDnsZones/SRV/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'SRV' within a Private DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/privateDnsZones/TXT/delete

#
Namespace
Microsoft.Network

Description

Remove the record set of a given name and type 'TXT' from a Private DNS zone.

Microsoft.Network/privateDnsZones/TXT/write

#
Namespace
Microsoft.Network

Description

Create or update a record set of type 'TXT' within a Private DNS zone. The records specified will replace the current records in the record set.

Microsoft.Network/privateDnsZones/virtualNetworkLinks/delete

#
Namespace
Microsoft.Network

Microsoft.Network/privateDnsZones/virtualNetworkLinks/write

#
Namespace
Microsoft.Network

Microsoft.Network/privateDnsZones/write

#
Namespace
Microsoft.Network

Description

Create or update a Private DNS zone within a resource group. Note that this command cannot be used to create or update virtual network links or record sets within the zone.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "action": "Microsoft.Network/privateDnsZones/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "action": "Microsoft.Network/privateDnsZones/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "89b8c343-70ed-4374-aaae-902d907793d9",
  "EventDataId": "c14aacb0-5715-70ad-f1d8-582d8d20bb72",
  "EventSubmissionTimestamp": "2026-07-02T17:16:21.939653Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/PRIVATEDNSZONES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "message": "Microsoft.Network/privateDnsZones/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c14aacb0-5715-70ad-f1d8-582d8d20bb72",
    "eventSubmissionTimestamp": "2026-07-02T17:16:21.939653Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0pdns.internal",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/privateDnsZones/dwh92eef0pdns.internal",
    "message": "Microsoft.Network/privateDnsZones/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c14aacb0-5715-70ad-f1d8-582d8d20bb72",
    "eventSubmissionTimestamp": "2026-07-02T17:16:21.9396530Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0pdns.internal",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/privateDnsZonesInternal/action

#
Namespace
Microsoft.Network

Description

Executes Private DNS Zones Internal APIs

Microsoft.Network/privateEndpointRedirectMaps/write

#
Namespace
Microsoft.Network

Description

Creates Private Endpoint RedirectMap Or Updates An Existing Private Endpoint RedirectMap

Microsoft.Network/privateEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes an private endpoint resource.

Microsoft.Network/privateEndpoints/privateDnsZoneGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes a Private DNS Zone Group

Microsoft.Network/privateEndpoints/privateDnsZoneGroups/write

#
Namespace
Microsoft.Network

Description

Puts a Private DNS Zone Group

Microsoft.Network/privateEndpoints/privateLinkServiceProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes an private link service proxy resource.

Microsoft.Network/privateEndpoints/privateLinkServiceProxies/write

#
Namespace
Microsoft.Network

Description

Creates a new private link service proxy, or updates an existing private link service proxy.

Microsoft.Network/privateEndpoints/pushPropertiesToResource/action

#
Namespace
Microsoft.Network

Description

Operation to push private endpoint property updates from NRP client

Microsoft.Network/privateEndpoints/write

#
Namespace
Microsoft.Network

Description

Creates a new private endpoint, or updates an existing private endpoint.

Microsoft.Network/privateLinkServices/delete

#
Namespace
Microsoft.Network

Description

Deletes an private link service resource.

Microsoft.Network/privateLinkServices/notifyPrivateEndpointMove/action

#
Namespace
Microsoft.Network

Description

Notifies a connected Private Link Service of Private Endpoint move

Microsoft.Network/privateLinkServices/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes an private endpoint connection proxy resource.

Microsoft.Network/privateLinkServices/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.Network

Description

Creates a new private endpoint connection proxy, or updates an existing private endpoint connection proxy.

Microsoft.Network/privateLinkServices/privateEndpointConnections/delete

#
Namespace
Microsoft.Network

Description

Deletes an private endpoint connection.

Microsoft.Network/privateLinkServices/privateEndpointConnections/write

#
Namespace
Microsoft.Network

Description

Creates a new private endpoint connection, or updates an existing private endpoint connection.

Microsoft.Network/privateLinkServices/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Network

Description

Approve or reject PrivateEndpoint connection on PrivateLinkService

Microsoft.Network/privateLinkServices/write

#
Namespace
Microsoft.Network

Description

Creates a new private link service, or updates an existing private link service.

Microsoft.Network/publicIPAddresses/ddosProtectionStatus/action

#
Namespace
Microsoft.Network

Description

Gets the effective Ddos protection status for a Public IP Address resource.

Microsoft.Network/publicIPAddresses/delete

#
Namespace
Microsoft.Network

Description

Deletes a public IP address.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/dwharn-pip-7000408c",
    "action": "Microsoft.Network/publicIPAddresses/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/dwharn-pip-7000408c",
    "action": "Microsoft.Network/publicIPAddresses/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783008141",
    "nbf": "1783008141",
    "exp": "1783012267",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "joig862JV0W_vEH8aP97AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 8",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783008141",
    "nbf": "1783008141",
    "exp": "1783012267",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "joig862JV0W_vEH8aP97AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 8",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "1393de9f-0ca2-4666-a720-2e9f0f342331",
  "EventDataId": "9c8ff064-01f8-6ebc-5e85-6c456da84ae8",
  "EventSubmissionTimestamp": "2026-07-02T16:41:21.8745439Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/PUBLICIPADDRESSES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/dwharn-pip-7000408c",
    "message": "Microsoft.Network/publicIPAddresses/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9c8ff064-01f8-6ebc-5e85-6c456da84ae8",
    "eventSubmissionTimestamp": "2026-07-02T16:41:21.8745439Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwharn-pip-7000408c",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/dwharn-pip-7000408c",
    "message": "Microsoft.Network/publicIPAddresses/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9c8ff064-01f8-6ebc-5e85-6c456da84ae8",
    "eventSubmissionTimestamp": "2026-07-02T16:41:21.8745439Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwharn-pip-7000408c",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/publicIPAddresses/dnsAliases/delete

#
Namespace
Microsoft.Network

Description

Deletes a Public IP Address Dns Alias resource

Microsoft.Network/publicIPAddresses/dnsAliases/write

#
Namespace
Microsoft.Network

Description

Creates a Public IP Address Dns Alias resource

Microsoft.Network/publicIPAddresses/join/action

#
Namespace
Microsoft.Network

Description

Joins a public IP address. Not Alertable.

Microsoft.Network/publicIPAddresses/joinServiceEndpointNetworkIdentifier/action

#
Namespace
Microsoft.Network

Description

Joins a Public Ip Address Service Endpoint Network Identifier

Microsoft.Network/publicIPAddresses/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Create or update the diagnostic settings of Public IP Address

Microsoft.Network/publicIPAddresses/write

#
Namespace
Microsoft.Network

Description

Creates a public IP address or updates an existing public IP address.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/zcpip3",
    "action": "Microsoft.Network/publicIPAddresses/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/zcpip3",
    "action": "Microsoft.Network/publicIPAddresses/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "5ac944fe-4c04-4b18-896f-bf7bbc81f9d8",
  "EventDataId": "876605a6-5a7d-549d-303c-33141cf08253",
  "EventSubmissionTimestamp": "2026-06-29T19:02:08.189945Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/PUBLICIPADDRESSES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcpip3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/zcpip3",
      "etag": "W/\"3c4f8075-7821-474d-8eae-bdfd61404158\"",
      "location": "westus2",
      "properties": {
        "provisioningState": "Updating",
        "resourceGuid": "580aea5d-bfff-4505-8a78-a64b2b20e260",
        "publicIPAddressVersion": "IPv4",
        "publicIPAllocationMethod": "Static",
        "idleTimeoutInMinutes": 4,
        "ipTags": [],
        "ddosSettings": {
          "protectionMode": "VirtualNetworkInherited"
        }
      },
      "type": "Microsoft.Network/publicIPAddresses",
      "sku": {
        "name": "Standard",
        "tier": "Regional"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/zcpip3",
    "message": "Microsoft.Network/publicIPAddresses/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "876605a6-5a7d-549d-303c-33141cf08253",
    "eventSubmissionTimestamp": "2026-06-29T19:02:08.189945Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcpip3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcpip3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/zcpip3",
      "etag": "W/\"3c4f8075-7821-474d-8eae-bdfd61404158\"",
      "location": "westus2",
      "properties": {
        "provisioningState": "Updating",
        "resourceGuid": "580aea5d-bfff-4505-8a78-a64b2b20e260",
        "publicIPAddressVersion": "IPv4",
        "publicIPAllocationMethod": "Static",
        "idleTimeoutInMinutes": 4,
        "ipTags": [],
        "ddosSettings": {
          "protectionMode": "VirtualNetworkInherited"
        }
      },
      "type": "Microsoft.Network/publicIPAddresses",
      "sku": {
        "name": "Standard",
        "tier": "Regional"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPAddresses/zcpip3",
    "message": "Microsoft.Network/publicIPAddresses/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "876605a6-5a7d-549d-303c-33141cf08253",
    "eventSubmissionTimestamp": "2026-06-29T19:02:08.1899450Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcpip3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:08.189945Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/publicipaddresses/zcpip3"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
properties.statusCode (sigma rule field)eqcreated1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/publicIPPrefixes/delete

#
Namespace
Microsoft.Network

Description

Deletes A Public Ip Prefix

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "action": "Microsoft.Network/publicIPPrefixes/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "action": "Microsoft.Network/publicIPPrefixes/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "3ae43eea-91c2-4c39-b398-130d767cf5a6",
  "EventDataId": "8ce80f68-4c65-0df4-b9e1-f08154c98fb7",
  "EventSubmissionTimestamp": "2026-07-02T18:24:19.3775628Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/PUBLICIPPREFIXES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "message": "Microsoft.Network/publicIPPrefixes/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8ce80f68-4c65-0df4-b9e1-f08154c98fb7",
    "eventSubmissionTimestamp": "2026-07-02T18:24:19.3775628Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afpublicipprefix",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "message": "Microsoft.Network/publicIPPrefixes/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8ce80f68-4c65-0df4-b9e1-f08154c98fb7",
    "eventSubmissionTimestamp": "2026-07-02T18:24:19.3775628Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afpublicipprefix",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/publicIPPrefixes/join/action

#
Namespace
Microsoft.Network

Description

Joins a PublicIPPrefix. Not alertable.

Microsoft.Network/publicIPPrefixes/write

#
Namespace
Microsoft.Network

Description

Creates A Public Ip Prefix Or Updates An Existing Public Ip Prefix

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "action": "Microsoft.Network/publicIPPrefixes/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "action": "Microsoft.Network/publicIPPrefixes/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "3d873728-f375-4fe7-b0b7-3c2625528d73",
  "EventDataId": "6473b4cf-5b31-31e8-a88b-4d2cff79d553",
  "EventSubmissionTimestamp": "2026-07-02T18:23:55.9739272Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/PUBLICIPPREFIXES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "message": "Microsoft.Network/publicIPPrefixes/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6473b4cf-5b31-31e8-a88b-4d2cff79d553",
    "eventSubmissionTimestamp": "2026-07-02T18:23:55.9739272Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afpublicipprefix",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/publicIPPrefixes/dwh2220afpublicipprefix",
    "message": "Microsoft.Network/publicIPPrefixes/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6473b4cf-5b31-31e8-a88b-4d2cff79d553",
    "eventSubmissionTimestamp": "2026-07-02T18:23:55.9739272Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afpublicipprefix",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/queryExpressRoutePortsBandwidth/action

#
Namespace
Microsoft.Network

Description

Query ExpressRoute Ports Bandwidth

Microsoft.Network/register/action

#
Namespace
Microsoft.Network

Description

Registers the subscription

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Network/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Network/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1785209876",
    "nbf": "1785209876",
    "exp": "1785215473",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAPURen4ovrhqDdFs0nhKRoSyF0GPVqO+JHPOsYdQPfzBZPUvCJEhxG5Ow/6nvUfqn2arqzvfadEGJHxGAKBILk0ph1H06195MJ99i9jv4ulIialxdbbi7QtnpHTxJggL9m/yPQGCll8eXrsZ1sRJgmg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMAAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "006ea83a-2932-54d9-1731-544dd799b8f0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "C7K3Vvx9ykO4R4sH5a0vAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "kW0jgyDmbcRP3yR_rNi-PYb4iTwIvzIzWcW9z_r3jRoBdXNlYXN0LWRzbXM",
    "xms_idrel": "26 1",
    "xms_sub_fct": "3 16",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "56cd70e1-88f7-4ab2-a48a-1e2223f3a719",
  "EventDataId": "a3c0d162-349c-fb51-c6e0-41467d1e65f5",
  "EventSubmissionTimestamp": "2026-07-28T04:09:00.2784275Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Network",
    "message": "Microsoft.Network/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a3c0d162-349c-fb51-c6e0-41467d1e65f5",
    "eventSubmissionTimestamp": "2026-07-28T04:09:00.2784275Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Network",
    "message": "Microsoft.Network/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a3c0d162-349c-fb51-c6e0-41467d1e65f5",
    "eventSubmissionTimestamp": "2026-07-28T04:09:00.2784275Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/routeFilters/delete

#
Namespace
Microsoft.Network

Description

Deletes a route filter definition

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "action": "Microsoft.Network/routeFilters/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "action": "Microsoft.Network/routeFilters/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "fa10fa8b-6464-45bf-8ab7-42569e47eb4c",
  "EventDataId": "c8deb253-959a-3924-6bec-0a61410d2870",
  "EventSubmissionTimestamp": "2026-07-02T18:34:32.5505587Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/ROUTEFILTERS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "message": "Microsoft.Network/routeFilters/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c8deb253-959a-3924-6bec-0a61410d2870",
    "eventSubmissionTimestamp": "2026-07-02T18:34:32.5505587Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afroutefilters",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "message": "Microsoft.Network/routeFilters/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c8deb253-959a-3924-6bec-0a61410d2870",
    "eventSubmissionTimestamp": "2026-07-02T18:34:32.5505587Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afroutefilters",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/routeFilters/join/action

#
Namespace
Microsoft.Network

Description

Joins a route filter. Not Alertable.

Microsoft.Network/routeFilters/routeFilterRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a route filter rule definition

Microsoft.Network/routeFilters/routeFilterRules/write

#
Namespace
Microsoft.Network

Description

Creates a route filter rule or Updates an existing route filter rule

Microsoft.Network/routeFilters/write

#
Namespace
Microsoft.Network

Description

Creates a route filter or Updates an existing route filter

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "action": "Microsoft.Network/routeFilters/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "action": "Microsoft.Network/routeFilters/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "2392ab4f-b81a-4134-b74c-5c92d8adc7c1",
  "EventDataId": "552053d6-587c-06f8-4dae-bd51a18d6b7d",
  "EventSubmissionTimestamp": "2026-07-02T18:24:23.5531562Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/ROUTEFILTERS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "message": "Microsoft.Network/routeFilters/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "552053d6-587c-06f8-4dae-bd51a18d6b7d",
    "eventSubmissionTimestamp": "2026-07-02T18:24:23.5531562Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afroutefilters",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/routeFilters/dwh2220afroutefilters",
    "message": "Microsoft.Network/routeFilters/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "552053d6-587c-06f8-4dae-bd51a18d6b7d",
    "eventSubmissionTimestamp": "2026-07-02T18:24:23.5531562Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afroutefilters",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/routeTables/delete

#
Namespace
Microsoft.Network

Description

Deletes a route table definition

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/dwh92eef0routetable",
    "action": "Microsoft.Network/routeTables/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/dwh92eef0routetable",
    "action": "Microsoft.Network/routeTables/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "d208a7b2-f8f0-4338-8a02-a61d114d6aaf",
  "EventDataId": "bd16f239-4bd5-a14f-6102-2c378b3f6094",
  "EventSubmissionTimestamp": "2026-07-02T17:14:50.8383006Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/ROUTETABLES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/dwh92eef0routetable",
    "message": "Microsoft.Network/routeTables/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bd16f239-4bd5-a14f-6102-2c378b3f6094",
    "eventSubmissionTimestamp": "2026-07-02T17:14:50.8383006Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0routetable",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/dwh92eef0routetable",
    "message": "Microsoft.Network/routeTables/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bd16f239-4bd5-a14f-6102-2c378b3f6094",
    "eventSubmissionTimestamp": "2026-07-02T17:14:50.8383006Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0routetable",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/routeTables/join/action

#
Namespace
Microsoft.Network

Description

Joins a route table. Not Alertable.

Microsoft.Network/routeTables/routes/delete

#
Namespace
Microsoft.Network

Description

Deletes a route definition

Microsoft.Network/routeTables/routes/write

#
Namespace
Microsoft.Network

Description

Creates a route or Updates an existing route

Microsoft.Network/routeTables/write

#
Namespace
Microsoft.Network

Description

Creates a route table or Updates an existing route table

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/zcrt3",
    "action": "Microsoft.Network/routeTables/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/zcrt3",
    "action": "Microsoft.Network/routeTables/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "1ffff5fe-5ea4-415d-b427-e1da169cdf64",
  "EventDataId": "26849061-2316-03ab-1880-48fe3640be33",
  "EventSubmissionTimestamp": "2026-06-29T19:02:11.0698822Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/ROUTETABLES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcrt3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/zcrt3",
      "etag": "W/\"50c01eea-fa28-494d-82c3-501b0c478e14\"",
      "type": "Microsoft.Network/routeTables",
      "location": "westus2",
      "properties": {
        "provisioningState": "Updating",
        "resourceGuid": "47a5bc2b-d43d-4bb5-97b5-f3ce6198bde6",
        "disableBgpRoutePropagation": false,
        "routes": []
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/zcrt3",
    "message": "Microsoft.Network/routeTables/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "26849061-2316-03ab-1880-48fe3640be33",
    "eventSubmissionTimestamp": "2026-06-29T19:02:11.0698822Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcrt3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "name": "zcrt3",
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/zcrt3",
      "etag": "W/\"50c01eea-fa28-494d-82c3-501b0c478e14\"",
      "type": "Microsoft.Network/routeTables",
      "location": "westus2",
      "properties": {
        "provisioningState": "Updating",
        "resourceGuid": "47a5bc2b-d43d-4bb5-97b5-f3ce6198bde6",
        "disableBgpRoutePropagation": false,
        "routes": []
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/routeTables/zcrt3",
    "message": "Microsoft.Network/routeTables/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "26849061-2316-03ab-1880-48fe3640be33",
    "eventSubmissionTimestamp": "2026-06-29T19:02:11.0698822Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcrt3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:11.0698822Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/routetables/zcrt3"
}

Microsoft.Network/securityPartnerProviders/delete

#
Namespace
Microsoft.Network

Description

Deletes a SecurityPartnerProvider

Microsoft.Network/securityPartnerProviders/join/action

#
Namespace
Microsoft.Network

Description

Joins a SecurityPartnerProvider. Not alertable.

Microsoft.Network/securityPartnerProviders/updateReferences/action

#
Namespace
Microsoft.Network

Description

Update references in a SecurityPartnerProvider

Microsoft.Network/securityPartnerProviders/validate/action

#
Namespace
Microsoft.Network

Description

Validates a SecurityPartnerProvider

Microsoft.Network/securityPartnerProviders/write

#
Namespace
Microsoft.Network

Description

Creates a SecurityPartnerProvider or Updates An Existing SecurityPartnerProvider

Microsoft.Network/serviceEndpointPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Service Endpoint Policy

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "action": "Microsoft.Network/serviceEndpointPolicies/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "action": "Microsoft.Network/serviceEndpointPolicies/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "df88c839-a73a-41fb-a6c1-8d2567de02eb",
  "EventDataId": "6f1b1cf2-e98e-74fa-60d1-ee3a14e6b7a1",
  "EventSubmissionTimestamp": "2026-07-02T18:25:01.602995Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/SERVICEENDPOINTPOLICIES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "message": "Microsoft.Network/serviceEndpointPolicies/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6f1b1cf2-e98e-74fa-60d1-ee3a14e6b7a1",
    "eventSubmissionTimestamp": "2026-07-02T18:25:01.602995Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afserviceendpoin",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "message": "Microsoft.Network/serviceEndpointPolicies/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6f1b1cf2-e98e-74fa-60d1-ee3a14e6b7a1",
    "eventSubmissionTimestamp": "2026-07-02T18:25:01.6029950Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afserviceendpoin",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/serviceEndpointPolicies/join/action

#
Namespace
Microsoft.Network

Description

Joins a Service Endpoint Policy. Not alertable.

Microsoft.Network/serviceEndpointPolicies/joinSubnet/action

#
Namespace
Microsoft.Network

Description

Joins a Subnet To Service Endpoint Policies. Not alertable.

Microsoft.Network/serviceEndpointPolicies/serviceEndpointPolicyDefinitions/delete

#
Namespace
Microsoft.Network

Description

Deletes a Service Endpoint Policy Definition

Microsoft.Network/serviceEndpointPolicies/serviceEndpointPolicyDefinitions/write

#
Namespace
Microsoft.Network

Description

Creates a Service Endpoint Policy Definition or updates an existing Service Endpoint Policy Definition

Microsoft.Network/serviceEndpointPolicies/write

#
Namespace
Microsoft.Network

Description

Creates a Service Endpoint Policy or updates an existing Service Endpoint Policy

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "action": "Microsoft.Network/serviceEndpointPolicies/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "action": "Microsoft.Network/serviceEndpointPolicies/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "4d4c14a6-e5da-4fdb-bae4-67fa55c16eef",
  "EventDataId": "b483f3ce-8d32-d0ee-dcbb-d8f7b1b2e518",
  "EventSubmissionTimestamp": "2026-07-02T18:24:48.5572233Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/SERVICEENDPOINTPOLICIES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "message": "Microsoft.Network/serviceEndpointPolicies/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b483f3ce-8d32-d0ee-dcbb-d8f7b1b2e518",
    "eventSubmissionTimestamp": "2026-07-02T18:24:48.5572233Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afserviceendpoin",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/serviceEndpointPolicies/dwh2220afserviceendpoin",
    "message": "Microsoft.Network/serviceEndpointPolicies/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b483f3ce-8d32-d0ee-dcbb-d8f7b1b2e518",
    "eventSubmissionTimestamp": "2026-07-02T18:24:48.5572233Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afserviceendpoin",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/trafficManagerProfiles/azureEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes an Azure Endpoint from an existing Traffic Manager Profile. Traffic Manager will stop routing traffic to the deleted Azure Endpoint.

Microsoft.Network/trafficManagerProfiles/azureEndpoints/write

#
Namespace
Microsoft.Network

Description

Add a new Azure Endpoint in an existing Traffic Manager Profile or update the properties of an existing Azure Endpoint in that Traffic Manager Profile.

Microsoft.Network/trafficManagerProfiles/delete

#
Namespace
Microsoft.Network

Description

Delete the Traffic Manager profile. All settings associated with the Traffic Manager profile will be lost, and the profile can no longer be used to route traffic.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "action": "Microsoft.Network/trafficmanagerprofiles/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "action": "Microsoft.Network/trafficmanagerprofiles/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783031103",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "87f7741a-5361-404a-a147-6b88e848f2f2"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783031103",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "correlationid": "87f7741a-5361-404a-a147-6b88e848f2f2"
  },
  "CorrelationId": "87f7741a-5361-404a-a147-6b88e848f2f2",
  "EventDataId": "1083ebb2-9953-2c18-6086-dafb0491628b",
  "EventSubmissionTimestamp": "2026-07-02T18:25:04.6320924Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/TRAFFICMANAGERPROFILES/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "responseBody": {
      "properties": {
        "boolean": true
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "message": "Microsoft.Network/trafficmanagerprofiles/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1083ebb2-9953-2c18-6086-dafb0491628b",
    "eventSubmissionTimestamp": "2026-07-02T18:25:04.6320924Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftrafficmanager",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "message": "Microsoft.Network/trafficmanagerprofiles/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1083ebb2-9953-2c18-6086-dafb0491628b",
    "eventSubmissionTimestamp": "2026-07-02T18:25:04.6320924Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftrafficmanager",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK",
    "responseBody": {
      "properties": {
        "boolean": true
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/trafficManagerProfiles/externalEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes an External Endpoint from an existing Traffic Manager Profile. Traffic Manager will stop routing traffic to the deleted External Endpoint.

Microsoft.Network/trafficManagerProfiles/externalEndpoints/write

#
Namespace
Microsoft.Network

Description

Add a new External Endpoint in an existing Traffic Manager Profile or update the properties of an existing External Endpoint in that Traffic Manager Profile.

Microsoft.Network/trafficManagerProfiles/nestedEndpoints/delete

#
Namespace
Microsoft.Network

Description

Deletes an Nested Endpoint from an existing Traffic Manager Profile. Traffic Manager will stop routing traffic to the deleted Nested Endpoint.

Microsoft.Network/trafficManagerProfiles/nestedEndpoints/write

#
Namespace
Microsoft.Network

Description

Add a new Nested Endpoint in an existing Traffic Manager Profile or update the properties of an existing Nested Endpoint in that Traffic Manager Profile.

Microsoft.Network/trafficManagerProfiles/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the Traffic Manager diagnostic settings, this operation is supplemented by insights resource provider.

Microsoft.Network/trafficManagerProfiles/validateLink/action

#
Namespace
Microsoft.Network

Microsoft.Network/trafficManagerProfiles/write

#
Namespace
Microsoft.Network

Description

Create a Traffic Manager profile, or modify the configuration of an existing Traffic Manager profile.<br>This includes enabling or disabling a profile and modifying DNS settings, traffic routing settings, or endpoint monitoring settings.<br>Endpoints routed by the Traffic Manager profile can be added, removed, enabled or disabled.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "action": "Microsoft.Network/trafficmanagerprofiles/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "action": "Microsoft.Network/trafficmanagerprofiles/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "77228109-a036-44e1-87e8-99c55a34097e",
  "EventDataId": "8878816e-aa50-5683-4181-45027498f99b",
  "EventSubmissionTimestamp": "2026-07-02T18:25:02.0132348Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/TRAFFICMANAGERPROFILES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "responseBody": {
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficManagerProfiles/dwh2220aftrafficmanager",
      "name": "dwh2220aftrafficmanager",
      "type": "Microsoft.Network/trafficManagerProfiles",
      "location": "global",
      "properties": {
        "profileStatus": "Enabled",
        "trafficRoutingMethod": "Performance",
        "dnsConfig": {
          "relativeName": "dwh2220aftrafficmanager",
          "fqdn": "dwh2220aftrafficmanager.trafficmanager.net",
          "ttl": 30
        },
        "monitorConfig": {
          "profileMonitorStatus": "Inactive",
          "protocol": "HTTP",
          "port": 80,
          "path": "/",
          "intervalInSeconds": 30,
          "toleratedNumberOfFailures": 3,
          "timeoutInSeconds": 10
        },
        "endpoints": [],
        "trafficViewEnrollmentStatus": "Disabled",
        "maxReturn": null,
        "recordType": null
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "message": "Microsoft.Network/trafficmanagerprofiles/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8878816e-aa50-5683-4181-45027498f99b",
    "eventSubmissionTimestamp": "2026-07-02T18:25:02.0132348Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftrafficmanager",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficmanagerprofiles/dwh2220aftrafficmanager",
    "message": "Microsoft.Network/trafficmanagerprofiles/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8878816e-aa50-5683-4181-45027498f99b",
    "eventSubmissionTimestamp": "2026-07-02T18:25:02.0132348Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftrafficmanager",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created",
    "responseBody": {
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/trafficManagerProfiles/dwh2220aftrafficmanager",
      "name": "dwh2220aftrafficmanager",
      "type": "Microsoft.Network/trafficManagerProfiles",
      "location": "global",
      "properties": {
        "profileStatus": "Enabled",
        "trafficRoutingMethod": "Performance",
        "dnsConfig": {
          "relativeName": "dwh2220aftrafficmanager",
          "fqdn": "dwh2220aftrafficmanager.trafficmanager.net",
          "ttl": 30
        },
        "monitorConfig": {
          "profileMonitorStatus": "Inactive",
          "protocol": "HTTP",
          "port": 80,
          "path": "/",
          "intervalInSeconds": 30,
          "toleratedNumberOfFailures": 3,
          "timeoutInSeconds": 10
        },
        "endpoints": [],
        "trafficViewEnrollmentStatus": "Disabled",
        "maxReturn": null,
        "recordType": null
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/trafficManagerUserMetricsKeys/delete

#
Namespace
Microsoft.Network

Description

Deletes the subscription-level key used for Realtime User Metrics collection.

Microsoft.Network/trafficManagerUserMetricsKeys/write

#
Namespace
Microsoft.Network

Description

Creates a new subscription-level key to be used for Realtime User Metrics collection.

Microsoft.Network/unregister/action

#
Namespace
Microsoft.Network

Description

Unregisters the subscription

Microsoft.Network/virtualHubs/bgpConnections/advertisedRoutes/action

#
Namespace
Microsoft.Network

Description

Gets virtualrouter advertised routes

Microsoft.Network/virtualHubs/bgpConnections/delete

#
Namespace
Microsoft.Network

Description

Deletes a Hub Bgp Connection child resource of Virtual Hub

Microsoft.Network/virtualHubs/bgpConnections/learnedRoutes/action

#
Namespace
Microsoft.Network

Description

Gets virtualrouter learned routes

Microsoft.Network/virtualHubs/bgpConnections/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Hub Bgp Connection child resource of Virtual Hub

Microsoft.Network/virtualHubs/connectionPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes Connection Policy child resource of Virtual Hub

Microsoft.Network/virtualHubs/connectionPolicies/write

#
Namespace
Microsoft.Network

Description

Creates or Updates Connection Policy child resource of Virtual Hub

Microsoft.Network/virtualHubs/delete

#

Microsoft.Network/virtualHubs/effectiveRoutes/action

#
Namespace
Microsoft.Network

Description

Gets effective route configured on Virtual Hub

Microsoft.Network/virtualHubs/hubRouteTables/delete

#
Namespace
Microsoft.Network

Description

Deletes a Route Table child resource of Virtual Hub

Microsoft.Network/virtualHubs/hubRouteTables/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Route Table child resource of Virtual Hub

Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/delete

#
Namespace
Microsoft.Network

Description

Deletes a HubVirtualNetworkConnection

Microsoft.Network/virtualHubs/hubVirtualNetworkConnections/write

#
Namespace
Microsoft.Network

Description

Create or update a HubVirtualNetworkConnection

Microsoft.Network/virtualHubs/inboundRoutes/action

#
Namespace
Microsoft.Network

Description

Gets routes learnt from a virtual wan connection

Microsoft.Network/virtualHubs/ipConfigurations/delete

#
Namespace
Microsoft.Network

Description

Deletes a Hub IpConfiguration child resource of Virtual Hub

Microsoft.Network/virtualHubs/ipConfigurations/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Hub IpConfiguration child resource of Virtual Hub

Microsoft.Network/virtualHubs/migrateRouteService/action

#
Namespace
Microsoft.Network

Description

Validate or execute the hub router migration

Microsoft.Network/virtualHubs/outboundRoutes/action

#
Namespace
Microsoft.Network

Description

Get Routes advertised by a virtual wan connection

Microsoft.Network/virtualHubs/routeMaps/delete

#
Namespace
Microsoft.Network

Description

Deletes a Route Map child resource of Virtual Hub

Microsoft.Network/virtualHubs/routeMaps/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Route Map child resource of Virtual Hub

Microsoft.Network/virtualHubs/routeTables/delete

#
Namespace
Microsoft.Network

Description

Delete a VirtualHubRouteTableV2

Microsoft.Network/virtualHubs/routeTables/write

#
Namespace
Microsoft.Network

Description

Create or Update a VirtualHubRouteTableV2

Microsoft.Network/virtualHubs/routingIntent/delete

#
Namespace
Microsoft.Network

Description

Deletes a Routing Intent child resource of Virtual Hub

Microsoft.Network/virtualHubs/routingIntent/write

#
Namespace
Microsoft.Network

Description

Creates or Updates a Routing Intent child resource of Virtual Hub

Microsoft.Network/virtualHubs/write

#

Microsoft.Network/virtualNetworkAppliances/delete

#
Namespace
Microsoft.Network

Description

Delete Virtual Network Appliance

Microsoft.Network/virtualNetworkAppliances/write

#
Namespace
Microsoft.Network

Description

Create or update Virtual Network Appliance

microsoft.network/virtualnetworkgateways/abortMigration/action

#
Namespace
Microsoft.Network

Description

Abort Migrate Virtual Network Gateway Operation

microsoft.network/virtualnetworkgateways/commitMigration/action

#
Namespace
Microsoft.Network

Description

Commit Migrate Virtual Network Gateway Operation

Microsoft.Network/virtualNetworkGateways/delete

#
Namespace
Microsoft.Network

Description

Deletes a virtualNetworkGateway

microsoft.network/virtualnetworkgateways/disconnectvirtualnetworkgatewayvpnconnections/action

#
Namespace
Microsoft.Network

Description

Disconnect virtual network gateway vpn connections

microsoft.network/virtualnetworkgateways/executeMigration/action

#
Namespace
Microsoft.Network

Description

Execute Migrate Virtual Network Gateway Operation

microsoft.network/virtualnetworkgateways/generatevpnclientpackage/action

#
Namespace
Microsoft.Network

Description

Generate VpnClient package for virtualNetworkGateway

microsoft.network/virtualnetworkgateways/generatevpnprofile/action

#
Namespace
Microsoft.Network

Description

Generate VpnProfile package for VirtualNetworkGateway

microsoft.network/virtualnetworkgateways/getadvertisedroutes/action

#
Namespace
Microsoft.Network

Description

Gets virtualNetworkGateway advertised routes

microsoft.network/virtualnetworkgateways/getbgppeerstatus/action

#
Namespace
Microsoft.Network

Description

Gets virtualNetworkGateway bgp peer status

microsoft.network/virtualnetworkgateways/geteffectiveroutes/action

#
Namespace
Microsoft.Network

Description

Gets virtualnetworkgateway effective routes

microsoft.network/virtualnetworkgateways/getlearnedroutes/action

#
Namespace
Microsoft.Network

Description

Gets virtualnetworkgateway learned routes

microsoft.network/virtualnetworkgateways/getvpnclientconnectionhealth/action

#
Namespace
Microsoft.Network

Description

Get Per Vpn Client Connection Health for VirtualNetworkGateway

microsoft.network/virtualnetworkgateways/getvpnclientipsecparameters/action

#
Namespace
Microsoft.Network

Description

Get Vpnclient Ipsec parameters for VirtualNetworkGateway P2S client.

microsoft.network/virtualnetworkgateways/getvpnprofilepackageurl/action

#
Namespace
Microsoft.Network

Description

Gets the URL of a pre-generated vpn client profile package

microsoft.network/virtualnetworkgateways/listAllRadiusServersSecrets/action

#
Namespace
Microsoft.Network

Description

List all VirtualNetworkGateway RadiusServer secrets

microsoft.network/virtualNetworkGateways/natRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a NAT rule resource

microsoft.network/virtualNetworkGateways/natRules/write

#
Namespace
Microsoft.Network

Description

Puts a NAT rule resource

microsoft.network/virtualnetworkgateways/prepareMigration/action

#
Namespace
Microsoft.Network

Description

Prepare Migrate Virtual Network Gateway Operation

Microsoft.Network/virtualNetworkGateways/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the Virtual Network Gateway diagnostic settings, this operation is supplemented by insights resource provider.

microsoft.network/virtualnetworkgateways/reset/action

#
Namespace
Microsoft.Network

Description

Resets a virtualNetworkGateway

microsoft.network/virtualnetworkgateways/resetvpnclientsharedkey/action

#
Namespace
Microsoft.Network

Description

Reset Vpnclient shared key for VirtualNetworkGateway P2S client.

microsoft.network/virtualnetworkgateways/setvpnclientipsecparameters/action

#
Namespace
Microsoft.Network

Description

Set Vpnclient Ipsec parameters for VirtualNetworkGateway P2S client.

microsoft.network/virtualnetworkgateways/startpacketcapture/action

#
Namespace
Microsoft.Network

Description

Starts a Virtual Network Gateway Packet Capture.

microsoft.network/virtualnetworkgateways/stoppacketcapture/action

#
Namespace
Microsoft.Network

Description

Stops a Virtual Network Gateway Packet Capture.

Microsoft.Network/virtualnetworkgateways/supportedvpndevices/action

#
Namespace
Microsoft.Network

Description

Lists Supported Vpn Devices

Microsoft.Network/virtualNetworkGateways/write

#
Namespace
Microsoft.Network

Description

Creates or updates a VirtualNetworkGateway

Microsoft.Network/virtualNetworks/BastionHosts/action

#
Namespace
Microsoft.Network

Description

Gets Bastion Host references in a Virtual Network.

Microsoft.Network/virtualNetworks/bastionHosts/default/action

#
Namespace
Microsoft.Network

Description

Gets Bastion Host references in a Virtual Network.

Microsoft.Network/virtualNetworks/customViews/get/action

#
Namespace
Microsoft.Network

Description

Get a Virtual Network custom view content

Microsoft.Network/virtualNetworks/ddosProtectionStatus/action

#
Namespace
Microsoft.Network

Description

Gets the effective Ddos protection status for a Virtual Network resource.

Microsoft.Network/virtualNetworks/delete

#
Namespace
Microsoft.Network

Description

Deletes a virtual network

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/dwh92eef0vnet",
    "action": "Microsoft.Network/virtualNetworks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/dwh92eef0vnet",
    "action": "Microsoft.Network/virtualNetworks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "d956a0cc-a613-4275-82b6-e20ade0c4b2f",
  "EventDataId": "487f2e08-2522-d9b4-e1ac-a894c3df8d3b",
  "EventSubmissionTimestamp": "2026-07-02T17:14:41.6803143Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/VIRTUALNETWORKS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/dwh92eef0vnet",
    "message": "Microsoft.Network/virtualNetworks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "487f2e08-2522-d9b4-e1ac-a894c3df8d3b",
    "eventSubmissionTimestamp": "2026-07-02T17:14:41.6803143Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0vnet",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/dwh92eef0vnet",
    "message": "Microsoft.Network/virtualNetworks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "487f2e08-2522-d9b4-e1ac-a894c3df8d3b",
    "eventSubmissionTimestamp": "2026-07-02T17:14:41.6803143Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0vnet",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Virtual Network Deleted source high: Detects when an Azure Virtual Network (VNet) is deleted. VNet deletion removes the entire network infrastructure and disconnects all resources within it, causing significant service disruption. This may indicate ransomware activity, sabotage, or unauthorized infrastructure destruction.T1485, T1499

Microsoft.Network/virtualNetworks/join/action

#
Namespace
Microsoft.Network

Description

Joins a virtual network. Not Alertable.

Microsoft.Network/virtualNetworks/joinLoadBalancer/action

#
Namespace
Microsoft.Network

Description

Joins a load balancer to virtual networks

Microsoft.Network/virtualNetworks/listDnsForwardingRulesets/action

#
Namespace
Microsoft.Network

Description

Gets the DNS Forwarding Ruleset for Virtual Network, in JSON format

Microsoft.Network/virtualNetworks/listDnsResolverPolicies/action

#
Namespace
Microsoft.Network

Description

Gets the DNS Resolver Policy associated with a Virtual Network, in JSON format.

Microsoft.Network/virtualNetworks/listDnsResolvers/action

#
Namespace
Microsoft.Network

Description

Gets the DNS Resolver for Virtual Network, in JSON format

Microsoft.Network/virtualNetworks/listNetworkManagerEffectiveConnectivityConfigurations/action

#
Namespace
Microsoft.Network

Description

Lists Network Manager Effective Connectivity Configurations

Microsoft.Network/virtualNetworks/listNetworkManagerEffectiveSecurityAdminRules/action

#
Namespace
Microsoft.Network

Description

Lists Network Manager Effective Security Admin Rules

Microsoft.Network/virtualNetworks/manageIpFromPool/action

#
Namespace
Microsoft.Network

Description

Manage Private Ip Inventory Pool Operation Description

Microsoft.Network/virtualNetworks/moveIpConfigurations/action

#
Namespace
Microsoft.Network

Description

Moves secondary IP configurations between resources

Microsoft.Network/virtualNetworks/peer/action

#
Namespace
Microsoft.Network

Description

Peers a virtual network with another virtual network

Microsoft.Network/virtualNetworks/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Create or update the diagnostic settings of the Virtual Network

Microsoft.Network/virtualNetworks/remoteVirtualNetworkPeeringProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a virtual network peering proxy

Microsoft.Network/virtualNetworks/remoteVirtualNetworkPeeringProxies/write

#
Namespace
Microsoft.Network

Description

Creates a virtual network peering proxy or updates an existing virtual network peering proxy

Microsoft.Network/virtualNetworks/removeAdminNetworkSecurityGroup/action

#
Namespace
Microsoft.Network

Description

Removes Admin Network Security Group Reference From Virtual Network

Microsoft.Network/virtualNetworks/rnmEffectiveNetworkSecurityGroups/action

#
Namespace
Microsoft.Network

Description

Gets Security Groups Configured On CA Of The Vnet In Rnm Format

Microsoft.Network/virtualNetworks/rnmEffectiveRouteTable/action

#
Namespace
Microsoft.Network

Description

Gets RouteTables Configured On CA Of The Vnet In Rnm Format

Microsoft.Network/virtualNetworks/setAdminNetworkSecurityGroup/action

#
Namespace
Microsoft.Network

Description

Sets Admin Network Security Group Reference On Virtual Network

Microsoft.Network/virtualNetworks/subnets/contextualServiceEndpointPolicies/delete

#
Namespace
Microsoft.Network

Description

Deletes A Contextual Service Endpoint Policy

Microsoft.Network/virtualNetworks/subnets/contextualServiceEndpointPolicies/write

#
Namespace
Microsoft.Network

Description

Creates a Contextual Service Endpoint Policy or updates an existing Contextual Service Endpoint Policy

Microsoft.Network/virtualNetworks/subnets/delete

#
Namespace
Microsoft.Network

Description

Deletes a virtual network subnet

Microsoft.Network/virtualNetworks/subnets/join/action

#
Namespace
Microsoft.Network

Description

Joins a virtual network. Not Alertable.

Microsoft.Network/virtualNetworks/subnets/joinLoadBalancer/action

#
Namespace
Microsoft.Network

Description

Joins a load balancer to virtual network subnets

Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/action

#
Namespace
Microsoft.Network

Description

Joins resource such as storage account or SQL database to a subnet. Not alertable.

Microsoft.Network/virtualNetworks/subnets/prepareNetworkPolicies/action

#
Namespace
Microsoft.Network

Description

Prepares a subnet by applying necessary Network Policies

Microsoft.Network/virtualNetworks/subnets/resourceNavigationLinks/delete

#
Namespace
Microsoft.Network

Microsoft.Network/virtualNetworks/subnets/resourceNavigationLinks/write

#
Namespace
Microsoft.Network

Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/delete

#
Namespace
Microsoft.Network

Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/validate/action

#
Namespace
Microsoft.Network

Microsoft.Network/virtualNetworks/subnets/serviceAssociationLinks/write

#
Namespace
Microsoft.Network

Microsoft.Network/virtualNetworks/subnets/unprepareNetworkPolicies/action

#
Namespace
Microsoft.Network

Description

Unprepare a subnet by removing the applied Network Policies

Microsoft.Network/virtualNetworks/subnets/write

#
Namespace
Microsoft.Network

Description

Creates a virtual network subnet or updates an existing virtual network subnet

Microsoft.Network/virtualNetworks/taggedTrafficConsumers/delete

#
Namespace
Microsoft.Network

Description

Deletes a Tagged Traffic Consumer

Microsoft.Network/virtualNetworks/taggedTrafficConsumers/validate/action

#
Namespace
Microsoft.Network

Description

Validates a Tagged Traffic Consumer

Microsoft.Network/virtualNetworks/taggedTrafficConsumers/write

#
Namespace
Microsoft.Network

Description

Creates a Tagged Traffic Consumer or updates an existing Tagged Traffic Consumer

Microsoft.Network/virtualNetworks/virtualNetworkPeerings/delete

#
Namespace
Microsoft.Network

Description

Deletes a virtual network peering

Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write

#
Namespace
Microsoft.Network

Description

Creates a virtual network peering or updates an existing virtual network peering

Microsoft.Network/virtualNetworks/write

#
Namespace
Microsoft.Network

Description

Creates a virtual network or updates an existing virtual network

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/zcvnet3",
    "action": "Microsoft.Network/virtualNetworks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/zcvnet3",
    "action": "Microsoft.Network/virtualNetworks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "39857d95-c78a-4351-bc34-52aff21f7e57",
  "EventDataId": "79a39c42-78d8-ff83-98ef-239ca2edd340",
  "EventSubmissionTimestamp": "2026-06-29T19:01:51.5433442Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.NETWORK/VIRTUALNETWORKS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/zcvnet3",
    "message": "Microsoft.Network/virtualNetworks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "79a39c42-78d8-ff83-98ef-239ca2edd340",
    "eventSubmissionTimestamp": "2026-06-29T19:01:51.5433442Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvnet3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualNetworks/zcvnet3",
    "message": "Microsoft.Network/virtualNetworks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "79a39c42-78d8-ff83-98ef-239ca2edd340",
    "eventSubmissionTimestamp": "2026-06-29T19:01:51.5433442Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcvnet3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:01:51.5433442Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.network/virtualnetworks/zcvnet3"
}

Microsoft.Network/virtualNetworkTaps/delete

#
Namespace
Microsoft.Network

Description

Delete Virtual Network Tap

Microsoft.Network/virtualNetworkTaps/join/action

#
Namespace
Microsoft.Network

Description

Joins a virtual network tap. Not Alertable.

Microsoft.Network/virtualNetworkTaps/networkInterfaceTapConfigurationProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Network Interface Tap Configuration Proxy.

Microsoft.Network/virtualNetworkTaps/networkInterfaceTapConfigurationProxies/write

#
Namespace
Microsoft.Network

Description

Creates a Network Interface Tap Configuration Proxy Or updates an existing Network Interface Tap Configuration Proxy.

Microsoft.Network/virtualNetworkTaps/write

#
Namespace
Microsoft.Network

Description

Create or Update Virtual Network Tap

Microsoft.Network/virtualRouters/delete

#

Microsoft.Network/virtualRouters/join/action

#
Namespace
Microsoft.Network

Description

Joins A VirtualRouter. Not alertable.

Microsoft.Network/virtualRouters/peerings/delete

#
Namespace
Microsoft.Network

Description

Deletes A VirtualRouterPeering

Microsoft.Network/virtualRouters/peerings/write

#
Namespace
Microsoft.Network

Description

Creates A VirtualRouterPeering or Updates An Existing VirtualRouterPeering

Microsoft.Network/virtualRouters/write

#

Microsoft.Network/virtualWans/delete

#
Namespace
Microsoft.Network

Description

Deletes a Virtual Wan

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwhc6a93dvirtualwans",
    "action": "Microsoft.Network/virtualWans/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwhc6a93dvirtualwans",
    "action": "Microsoft.Network/virtualWans/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "5b5bbafd-9819-4b57-8a0f-cadadeaa3f35",
  "EventDataId": "7a8390df-45cd-1722-45b0-fff2c0275f86",
  "EventSubmissionTimestamp": "2026-07-03T02:18:51.0373859Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/VIRTUALWANS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwhc6a93dvirtualwans",
    "message": "Microsoft.Network/virtualWans/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7a8390df-45cd-1722-45b0-fff2c0275f86",
    "eventSubmissionTimestamp": "2026-07-03T02:18:51.0373859Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dvirtualwans",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwhc6a93dvirtualwans",
    "message": "Microsoft.Network/virtualWans/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7a8390df-45cd-1722-45b0-fff2c0275f86",
    "eventSubmissionTimestamp": "2026-07-03T02:18:51.0373859Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dvirtualwans",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/virtualwans/generateVpnProfile/action

#
Namespace
Microsoft.Network

Description

Generate VirtualWanVpnServerConfiguration VpnProfile

Microsoft.Network/virtualWans/join/action

#
Namespace
Microsoft.Network

Description

Joins a Virtual WAN. Not alertable.

Microsoft.network/virtualWans/p2sVpnServerConfigurations/delete

#
Namespace
Microsoft.Network

Description

Deletes a virtual Wan P2SVpnServerConfiguration

Microsoft.network/virtualWans/p2sVpnServerConfigurations/write

#
Namespace
Microsoft.Network

Description

Creates a virtual Wan P2SVpnServerConfiguration or updates an existing virtual Wan P2SVpnServerConfiguration

Microsoft.Network/virtualWans/updateVhubReferences/action

#
Namespace
Microsoft.Network

Description

Update VirtualHub reference in VirtualWan

Microsoft.Network/virtualWans/updateVpnReferences/action

#
Namespace
Microsoft.Network

Description

Update VPN reference in VirtualWan

Microsoft.Network/virtualWans/virtualHubProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Virtual Hub proxy

Microsoft.Network/virtualWans/virtualHubProxies/write

#
Namespace
Microsoft.Network

Description

Creates a Virtual Hub proxy or updates a Virtual Hub proxy

Microsoft.Network/virtualwans/vpnconfiguration/action

#
Namespace
Microsoft.Network

Description

Gets a Vpn Configuration

Microsoft.Network/virtualwans/vpnServerConfigurations/action

#
Namespace
Microsoft.Network

Description

Get VirtualWanVpnServerConfigurations

Microsoft.Network/virtualWans/vpnSiteProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a Vpn Site proxy

Microsoft.Network/virtualWans/vpnSiteProxies/write

#
Namespace
Microsoft.Network

Description

Creates a Vpn Site proxy or updates a Vpn Site proxy

Microsoft.Network/virtualWans/write

#
Namespace
Microsoft.Network

Description

Create or update a Virtual Wan

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwh2220afvirtualwans",
    "action": "Microsoft.Network/virtualWans/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwh2220afvirtualwans",
    "action": "Microsoft.Network/virtualWans/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "17f9804f-5560-4806-a88a-caa0e9530203",
  "EventDataId": "1cd09f16-dfb1-9c0d-5402-f854f993449f",
  "EventSubmissionTimestamp": "2026-07-02T18:25:28.8189271Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.NETWORK/VIRTUALWANS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwh2220afvirtualwans",
    "message": "Microsoft.Network/virtualWans/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1cd09f16-dfb1-9c0d-5402-f854f993449f",
    "eventSubmissionTimestamp": "2026-07-02T18:25:28.8189271Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afvirtualwans",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Network/virtualWans/dwh2220afvirtualwans",
    "message": "Microsoft.Network/virtualWans/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "1cd09f16-dfb1-9c0d-5402-f854f993449f",
    "eventSubmissionTimestamp": "2026-07-02T18:25:28.8189271Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afvirtualwans",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.NETWORK",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.NETWORK",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Network/vpnGateways/delete

#
Namespace
Microsoft.Network

Description

Deletes a VpnGateway.

microsoft.network/vpngateways/getadvertisedroutes/action

#
Namespace
Microsoft.Network

Description

Gets advertised routes of a VpnGateway

microsoft.network/vpngateways/getbgppeerstatus/action

#
Namespace
Microsoft.Network

Description

Gets bgp peer status of a VpnGateway

microsoft.network/vpngateways/getlearnedroutes/action

#
Namespace
Microsoft.Network

Description

Gets learned routes of a VpnGateway

microsoft.network/vpngateways/listvpnconnectionshealth/action

#
Namespace
Microsoft.Network

Description

Gets connection health for all or a subset of connections on a VpnGateway

microsoft.network/vpnGateways/natRules/delete

#
Namespace
Microsoft.Network

Description

Deletes a NAT rule resource

microsoft.network/vpnGateways/natRules/write

#
Namespace
Microsoft.Network

Description

Puts a NAT rule resource

Microsoft.Network/vpnGateways/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Network

Description

Creates or updates the Vpn Gateway diagnostic settings, this operation is supplemented by insights resource provider.

microsoft.network/vpngateways/reset/action

#
Namespace
Microsoft.Network

Description

Resets a VpnGateway

microsoft.network/vpngateways/startpacketcapture/action

#
Namespace
Microsoft.Network

Description

Start Vpn gateway Packet Capture with according resource

microsoft.network/vpngateways/stoppacketcapture/action

#
Namespace
Microsoft.Network

Description

Stop Vpn gateway Packet Capture with sasURL

microsoft.network/vpnGateways/vpnConnections/delete

#
Namespace
Microsoft.Network

Description

Deletes a VpnConnection.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

microsoft.network/vpnGateways/vpnConnections/startpacketcapture/action

#
Namespace
Microsoft.Network

Description

Start packet capture for selected linked in vpn connection

microsoft.network/vpnGateways/vpnConnections/stoppacketcapture/action

#
Namespace
Microsoft.Network

Description

Stop packet capture for selected linked in vpn connection

microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/getikesas/action

#
Namespace
Microsoft.Network

Description

Lists Vpn Link Connection IKE Security Associations

microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/resetconnection/action

#
Namespace
Microsoft.Network

Description

Resets connection for vWAN

microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/sharedKeys/default/listSharedKey/action

#
Namespace
Microsoft.Network

Description

Gets Vpn Link Connection Shared Key

microsoft.network/vpnGateways/vpnConnections/vpnLinkConnections/sharedKeys/default/write

#
Namespace
Microsoft.Network

Description

Puts Vpn Link Connection Shared Key

microsoft.network/vpnGateways/vpnConnections/write

#
Namespace
Microsoft.Network

Description

Puts a VpnConnection.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Network/vpnGateways/write

#
Namespace
Microsoft.Network

Description

Puts a VpnGateway.

microsoft.network/vpnServerConfigurations/configurationPolicyGroups/delete

#
Namespace
Microsoft.Network

Description

Deletes a Configuration Policy Group

Microsoft.Network/vpnServerConfigurations/configurationPolicyGroups/p2sConnectionConfigurationProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes A P2S Connection Configuration Proxy

Microsoft.Network/vpnServerConfigurations/configurationPolicyGroups/p2sConnectionConfigurationProxies/write

#
Namespace
Microsoft.Network

Description

Creates A P2S Connection Configuration Proxy Or Updates An Existing P2S Connection Configuration Proxy

microsoft.network/vpnServerConfigurations/configurationPolicyGroups/write

#
Namespace
Microsoft.Network

Description

Puts a Configuration Policy Group

Microsoft.Network/vpnServerConfigurations/delete

#
Namespace
Microsoft.Network

Description

Delete VpnServerConfiguration

microsoft.network/vpnServerConfigurations/listAllRadiusServersSecrets/action

#
Namespace
Microsoft.Network

Description

List all VpnServerConfiguration RadiusServer secrets

Microsoft.Network/vpnServerConfigurations/p2sVpnGatewayProxies/delete

#
Namespace
Microsoft.Network

Description

Deletes a P2SVpnGateway Proxy

Microsoft.Network/vpnServerConfigurations/p2sVpnGatewayProxies/write

#
Namespace
Microsoft.Network

Description

Creates a P2SVpnGateway Proxy or updates a P2SVpnGateway Proxy

Microsoft.Network/vpnServerConfigurations/write

#
Namespace
Microsoft.Network

Description

Create or Update VpnServerConfiguration

Microsoft.Network/vpnsites/delete

#
Namespace
Microsoft.Network

Description

Deletes a Vpn Site resource.

Microsoft.Network/vpnsites/write

#
Namespace
Microsoft.Network

Description

Creates or updates a Vpn Site resource.

Microsoft.Network/azureserviceconnectioncontrollers/delete

#
Namespace
Microsoft.Network

Description

Delete Azure Service Connection Controller

Microsoft.Network/azureserviceconnectioncontrollers/write

#
Namespace
Microsoft.Network

Description

Create Or Update Azure Service Connection Controller

Microsoft.Network/expressRouteCircuits/routeTable/action

#
Namespace
Microsoft.Network

Description

Get MultiCloud Circuit Route Table

Microsoft.Network/firewallPolicies/kubeSelectorGroups/delete

#
Namespace
Microsoft.Network

Description

Delete Firewall Policy Kube Selector Group

Microsoft.Network/firewallPolicies/kubeSelectorGroups/write

#
Namespace
Microsoft.Network

Description

Create or Update Firewall Policy Kube Selector Group

Microsoft.Network/firstPartyServiceTags/join/action

#
Namespace
Microsoft.Network

Description

Join First Party Service Tag

Microsoft.Network/interconnectGroups/nodeAvailability/action

#
Namespace
Microsoft.Network

Description

Get InterconnectGroup Node Availability

Microsoft.Network/networkWatchers/packetCaptures/queryInsight/action

#
Namespace
Microsoft.Network

Description

Query Packet Capture Insight

Microsoft.Network/networkWatchers/packetCaptures/startInsight/action

#
Namespace
Microsoft.Network

Description

Start Packet Capture Insight

Microsoft.Network/networkWatchers/trafficAnalytics/delete

#
Namespace
Microsoft.Network

Description

Delete Traffic Analytics

Microsoft.Network/networkWatchers/trafficAnalytics/write

#
Namespace
Microsoft.Network

Description

Create Traffic Analytics

Microsoft.Network/privateEndpoints/copy/action

#
Namespace
Microsoft.Network

Description

Copy an private endpoint.

Microsoft.Network/privatetrafficmanagerprofiles/delete

#
Namespace
Microsoft.Network

Description

Delete a Private Traffic Manager Profile

Microsoft.Network/privatetrafficmanagerprofiles/endpoints/delete

#
Namespace
Microsoft.Network

Description

Delete a Private Traffic Manager Profile Endpoint

Microsoft.Network/privatetrafficmanagerprofiles/endpoints/write

#
Namespace
Microsoft.Network

Description

Create Or Update a Private Traffic Manager Profile Endpoint

Microsoft.Network/privatetrafficmanagerprofiles/healthPolicies/delete

#
Namespace
Microsoft.Network

Description

Delete a Private Traffic Manager Profile Health Policy

Microsoft.Network/privatetrafficmanagerprofiles/healthPolicies/write

#
Namespace
Microsoft.Network

Description

Create Or Update a Private Traffic Manager Profile Health Policy

Microsoft.Network/privatetrafficmanagerprofiles/validateLink/action

#
Namespace
Microsoft.Network

Microsoft.Network/privatetrafficmanagerprofiles/write

#
Namespace
Microsoft.Network

Description

Create Or Update a Private Traffic Manager Profile

Microsoft.Network/probinggateways/delete

#
Namespace
Microsoft.Network

Description

Delete a Probing Gateway

Microsoft.Network/probinggateways/write

#
Namespace
Microsoft.Network

Description

Create Or Update a Probing Gateway

Microsoft.Network/topologymaps/delete

#
Namespace
Microsoft.Network

Description

Delete a Topology Map

Microsoft.Network/topologymaps/sites/delete

#
Namespace
Microsoft.Network

Description

Delete a Topology Map Site

Microsoft.Network/topologymaps/sites/write

#
Namespace
Microsoft.Network

Description

Create Or Update a Topology Map Site

Microsoft.Network/topologymaps/write

#
Namespace
Microsoft.Network

Description

Create Or Update a Topology Map

Microsoft.Network/virtualNetworks/subnets/getNetworkPolicies/action

#
Namespace
Microsoft.Network

Description

Get Subnet Network Intent Policies

References #