Azure portal Azure-Microsoft.Portal
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.Portal rules that match the resource provider but no specific operation. | N | N |
| Microsoft.Portal/ | Removes the Cloud Shell instance. | N | N |
| Microsoft.Portal/ | Create or update a Cloud Shell instance. | N | Y |
| Microsoft.Portal/ | Removes the dashboard from the subscription. | N | N |
| Microsoft.Portal/ | Add or modify dashboard to a subscription. | Y | N |
| Microsoft.Portal/ | Register to Portal | N | N |
| Microsoft.Portal/ | Removes Tenant configuration. User has to be a Tenant Admin for this operation. | N | N |
| Microsoft.Portal/ | Adds or updates Tenant configuration. User has to be a Tenant Admin for this operation. | N | N |
| Microsoft.Portal/ | Removes the Cloud Shell user settings. | N | N |
| Microsoft.Portal/ | Create or update Cloud Shell user setting. | N | N |
any: Azure portal (catch-all)
#Description
Catch-all for Azure-Microsoft.Portal rules that match the resource provider but no specific operation.
Microsoft.Portal/consoles/delete
#Description
Removes the Cloud Shell instance.
Microsoft.Portal/consoles/write
#Description
Create or update a Cloud Shell instance.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1059
Microsoft.Portal/dashboards/delete
#Description
Removes the dashboard from the subscription.
Microsoft.Portal/dashboards/write
#Description
Add or modify dashboard to a subscription.
Example Resource Log Record #
{
"ActivityStatusValue": "Failure",
"ActivitySubstatusValue": "BadRequest",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
"action": "Microsoft.Portal/dashboards/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
"action": "Microsoft.Portal/dashboards/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "5df9aaa3-7ec9-4559-a4af-6bd1c33bae02",
"EventDataId": "c7c29557-8a16-2fee-1c58-f1cb7d04958c",
"EventSubmissionTimestamp": "2026-07-03T01:30:16.1570732Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Error",
"OperationNameValue": "MICROSOFT.PORTAL/DASHBOARDS/WRITE",
"Properties": {
"statusCode": "BadRequest",
"serviceRequestId": "",
"statusMessage": {
"error": {
"code": "37",
"message": "The request content was invalid and could not be deserialized: 'Cannot deserialize the current JSON object (e.g. {\"name\":\"value\"}) into type 'System.Collections.Generic.List`1[Microsoft.WindowsAzure.ResourceStack.Providers.Feature.Definitions.V2020_09_01.DashboardLensDefinition_V2020_09_01]' because the type requires a JSON array (e.g. [1,2,3]) to deserialize correctly.\r\nTo fix this error either change the JSON to a JSON array (e.g. [1,2,3]) or change the deserialized type so that it is a normal .NET type (e.g. not a primitive type like integer, not a collection type like an array or List<T>) that can be deserialized from a JSON object. JsonObjectAttribute can also be added to the type to force it to deserialize from a JSON object.\r\nPath 'properties.lenses', line 1, position 47.'."
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
"message": "Microsoft.Portal/dashboards/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "c7c29557-8a16-2fee-1c58-f1cb7d04958c",
"eventSubmissionTimestamp": "2026-07-03T01:30:16.1570732Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhprobe1",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.PORTAL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "BadRequest"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
"message": "Microsoft.Portal/dashboards/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "c7c29557-8a16-2fee-1c58-f1cb7d04958c",
"eventSubmissionTimestamp": "2026-07-03T01:30:16.1570732Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhprobe1",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.PORTAL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"statusCode": "BadRequest",
"serviceRequestId": "",
"activitySubstatusValue": "BadRequest",
"statusMessage": {
"error": {
"code": "37",
"message": "The request content was invalid and could not be deserialized: 'Cannot deserialize the current JSON object (e.g. {\"name\":\"value\"}) into type 'System.Collections.Generic.List`1[Microsoft.WindowsAzure.ResourceStack.Providers.Feature.Definitions.V2020_09_01.DashboardLensDefinition_V2020_09_01]' because the type requires a JSON array (e.g. [1,2,3]) to deserialize correctly.\r\nTo fix this error either change the JSON to a JSON array (e.g. [1,2,3]) or change the deserialized type so that it is a normal .NET type (e.g. not a primitive type like integer, not a collection type like an array or List<T>) that can be deserialized from a JSON object. JsonObjectAttribute can also be added to the type to force it to deserialize from a JSON object.\r\nPath 'properties.lenses', line 1, position 47.'."
}
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.PORTAL",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Portal/register/action
#Description
Register to Portal
Microsoft.Portal/tenantConfigurations/delete
#Description
Removes Tenant configuration. User has to be a Tenant Admin for this operation.
Microsoft.Portal/tenantConfigurations/write
#Description
Adds or updates Tenant configuration. User has to be a Tenant Admin for this operation.
Microsoft.Portal/usersettings/delete
#Description
Removes the Cloud Shell user settings.
Microsoft.Portal/usersettings/write
#Description
Create or update Cloud Shell user setting.