Azure portal Azure-Microsoft.Portal

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Portal rules that match the resource provider but no specific operation.NN
Microsoft.Portal/consoles/deleteRemoves the Cloud Shell instance.NN
Microsoft.Portal/consoles/writeCreate or update a Cloud Shell instance.NY
Microsoft.Portal/dashboards/deleteRemoves the dashboard from the subscription.NN
Microsoft.Portal/dashboards/writeAdd or modify dashboard to a subscription.YN
Microsoft.Portal/register/actionRegister to PortalNN
Microsoft.Portal/tenantConfigurations/deleteRemoves Tenant configuration. User has to be a Tenant Admin for this operation.NN
Microsoft.Portal/tenantConfigurations/writeAdds or updates Tenant configuration. User has to be a Tenant Admin for this operation.NN
Microsoft.Portal/usersettings/deleteRemoves the Cloud Shell user settings.NN
Microsoft.Portal/usersettings/writeCreate or update Cloud Shell user setting.NN

any: Azure portal (catch-all)

#
Namespace
Microsoft.Portal

Description

Catch-all for Azure-Microsoft.Portal rules that match the resource provider but no specific operation.

Microsoft.Portal/consoles/delete

#
Namespace
Microsoft.Portal

Description

Removes the Cloud Shell instance.

Microsoft.Portal/consoles/write

#
Namespace
Microsoft.Portal

Description

Create or update a Cloud Shell instance.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Microsoft.Portal/dashboards/delete

#
Namespace
Microsoft.Portal

Description

Removes the dashboard from the subscription.

Microsoft.Portal/dashboards/write

#
Namespace
Microsoft.Portal

Description

Add or modify dashboard to a subscription.

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "BadRequest",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
    "action": "Microsoft.Portal/dashboards/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
    "action": "Microsoft.Portal/dashboards/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "5df9aaa3-7ec9-4559-a4af-6bd1c33bae02",
  "EventDataId": "c7c29557-8a16-2fee-1c58-f1cb7d04958c",
  "EventSubmissionTimestamp": "2026-07-03T01:30:16.1570732Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.PORTAL/DASHBOARDS/WRITE",
  "Properties": {
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "37",
        "message": "The request content was invalid and could not be deserialized: 'Cannot deserialize the current JSON object (e.g. {\"name\":\"value\"}) into type 'System.Collections.Generic.List`1[Microsoft.WindowsAzure.ResourceStack.Providers.Feature.Definitions.V2020_09_01.DashboardLensDefinition_V2020_09_01]' because the type requires a JSON array (e.g. [1,2,3]) to deserialize correctly.\r\nTo fix this error either change the JSON to a JSON array (e.g. [1,2,3]) or change the deserialized type so that it is a normal .NET type (e.g. not a primitive type like integer, not a collection type like an array or List<T>) that can be deserialized from a JSON object. JsonObjectAttribute can also be added to the type to force it to deserialize from a JSON object.\r\nPath 'properties.lenses', line 1, position 47.'."
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
    "message": "Microsoft.Portal/dashboards/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c7c29557-8a16-2fee-1c58-f1cb7d04958c",
    "eventSubmissionTimestamp": "2026-07-03T01:30:16.1570732Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhprobe1",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.PORTAL",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "BadRequest"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Portal/dashboards/dwhprobe1",
    "message": "Microsoft.Portal/dashboards/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c7c29557-8a16-2fee-1c58-f1cb7d04958c",
    "eventSubmissionTimestamp": "2026-07-03T01:30:16.1570732Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhprobe1",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.PORTAL",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "activitySubstatusValue": "BadRequest",
    "statusMessage": {
      "error": {
        "code": "37",
        "message": "The request content was invalid and could not be deserialized: 'Cannot deserialize the current JSON object (e.g. {\"name\":\"value\"}) into type 'System.Collections.Generic.List`1[Microsoft.WindowsAzure.ResourceStack.Providers.Feature.Definitions.V2020_09_01.DashboardLensDefinition_V2020_09_01]' because the type requires a JSON array (e.g. [1,2,3]) to deserialize correctly.\r\nTo fix this error either change the JSON to a JSON array (e.g. [1,2,3]) or change the deserialized type so that it is a normal .NET type (e.g. not a primitive type like integer, not a collection type like an array or List<T>) that can be deserialized from a JSON object. JsonObjectAttribute can also be added to the type to force it to deserialize from a JSON object.\r\nPath 'properties.lenses', line 1, position 47.'."
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.PORTAL",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Portal/register/action

#
Namespace
Microsoft.Portal

Description

Register to Portal

Microsoft.Portal/tenantConfigurations/delete

#
Namespace
Microsoft.Portal

Description

Removes Tenant configuration. User has to be a Tenant Admin for this operation.

Microsoft.Portal/tenantConfigurations/write

#
Namespace
Microsoft.Portal

Description

Adds or updates Tenant configuration. User has to be a Tenant Admin for this operation.

Microsoft.Portal/usersettings/delete

#
Namespace
Microsoft.Portal

Description

Removes the Cloud Shell user settings.

Microsoft.Portal/usersettings/write

#
Namespace
Microsoft.Portal

Description

Create or update Cloud Shell user setting.

References #