Azure Recovery Services Azure-Microsoft.RecoveryServices
any: Azure Recovery Services (catch-all)
#Description
Catch-all for Azure-Microsoft.RecoveryServices rules that match the resource provider but no specific operation.
Microsoft.RecoveryServices/locations/allocateStamp/action
#Description
AllocateStamp is internal operation used by service
Microsoft.RecoveryServices/Locations/backupCrossRegionRestore/action
#Description
Trigger Cross region restore.
Microsoft.RecoveryServices/Locations/backupCrrJob/action
#Description
Get Cross Region Restore Job Details in the secondary region for Recovery Services Vault.
Microsoft.RecoveryServices/Locations/backupCrrJobCancel/action
#Description
Get Cross Region Restore Job Details in the secondary region for Recovery Services Vault.
Microsoft.RecoveryServices/Locations/backupCrrJobs/action
#Description
List Cross Region Restore Jobs in the secondary region for Recovery Services Vault.
Microsoft.RecoveryServices/Locations/backupPreValidateProtection/action
#Description
Pre Validate Enable Protection
Microsoft.RecoveryServices/Locations/backupProtectedItem/write
#Description
Create a backup Protected Item
Microsoft.RecoveryServices/Locations/backupStatus/action
#Description
Check Backup Status for Recovery Services Vaults
Microsoft.RecoveryServices/Locations/backupValidateFeatures/action
#Description
Validate Features
Microsoft.RecoveryServices/locations/capabilities/action
#Description
List capabilities at a given location.
Microsoft.RecoveryServices/locations/checkNameAvailability/action
#Description
Check Resource Name Availability is an API to check if resource name is available
Microsoft.RecoveryServices/locations/deletedVaults/undelete/action
#Description
Undelete DeletedVault operation re-creates an Azure resource of type 'vault'.
Microsoft.RecoveryServices/register/action
#Description
Registers subscription for given Resource Provider
Microsoft.RecoveryServices/unregister/action
#Description
Unregisters subscription for given Resource Provider
Microsoft.RecoveryServices/Vaults/backupconfig/write
#Description
Updates Configuration for Recovery Services Vault.
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/action
#Description
Restore recovery point from cross-tenant mapped vault for the protected items.
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupTriggerValidateOperation/action
#Description
Validate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupValidateOperation/action
#Description
Validate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/remove/action
#Description
Remove the backup cross-tenant vault mapping.
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/vaultCredentials/generate/action
#Description
Retrieves the cross-tenant vault mapping.
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/write
#Description
Create a backup cross-tenant vault mapping.
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappingStatus/action
#Description
Retrieves the status of the cross-tenant vault mapping.
Microsoft.RecoveryServices/Vaults/backupEncryptionConfigs/write
#Description
Updates Backup Resource Encryption Configuration
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/delete
#Description
Delete a backup Protection Intent
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/write
#Description
Create a backup Protection Intent
Microsoft.RecoveryServices/Vaults/backupFabrics/getRecoveryPoints/action
#Description
Get Recovery Points for Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/preCheckRestore/action
#Description
Restore Recovery Points for Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete
#Description
Deletes the registered Container
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490, T1562
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/action
#Description
Do inquiry for workloads within a container
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/action
#Description
Performs Backup for Protected Item.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/delete
#Description
Deletes Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/action
#Description
Get AccessToken for Cross Region Restore.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/move/action
#Description
Move Recovery point to another tier
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/action
#Description
Provision Instant Item Recovery for Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/action
#Description
Restore Recovery Points for Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/action
#Description
Revoke Instant Item Recovery for Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/write
#Description
Update Recovery Point for Protected Item.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPointsRecommendedForMove/action
#Description
Get Recovery points recommended for move to another tier
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/write
#Description
Create a backup Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/write
#Description
Creates a registered container
Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/action
#Description
Refreshes the container list
Microsoft.RecoveryServices/Vaults/backupFabrics/restore/action
#Description
Restore Recovery Points for Protected Items.
Microsoft.RecoveryServices/Vaults/backupJobs/cancel/action
#Description
Cancel the Job
Microsoft.RecoveryServices/Vaults/backupJobs/retry/action
#Description
Retry the Job
Microsoft.RecoveryServices/Vaults/backupJobsExport/action
#Description
Export Jobs
Microsoft.RecoveryServices/Vaults/backupPolicies/delete
#Description
Delete a Protection Policy
Microsoft.RecoveryServices/Vaults/backupPolicies/write
#Description
Creates or Updates Protection Policy
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/delete
#Description
The Delete ResourceGuard proxy operation deletes the specified Azure resource of type 'ResourceGuard proxy'
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/action
#Description
Unlock delete ResourceGuard proxy operation unlocks the next delete critical operation
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/write
#Description
Create ResourceGuard proxy operation creates an Azure resource of type 'ResourceGuard Proxy'
Microsoft.RecoveryServices/Vaults/backupSecurityPIN/action
#Description
Returns Security PIN Information for Recovery Services Vault.
Microsoft.RecoveryServices/Vaults/backupstorageconfig/write
#Description
Updates Storage Configuration for Recovery Services Vault.
Microsoft.RecoveryServices/Vaults/backupTieringCost/fetchTieringCost/action
#Description
Returns the tiering related cost info.
Microsoft.RecoveryServices/Vaults/backupTriggerValidateOperation/action
#Description
Validate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/backupValidateOperation/action
#Description
Validate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/certificates/write
#Description
The Update Resource Certificate operation updates the resource/vault credential certificate.
Microsoft.RecoveryServices/Vaults/delete
#Description
The Delete Vault operation deletes the specified Azure resource of type 'vault'
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "NoContent",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"action": "Microsoft.RecoveryServices/vaults/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"action": "Microsoft.RecoveryServices/vaults/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "21080611-87db-4895-96e3-6a384089ca85",
"EventDataId": "34308349-0d12-8d5d-b410-8428c65886d6",
"EventSubmissionTimestamp": "2026-07-02T18:28:40.3209307Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.RECOVERYSERVICES/VAULTS/DELETE",
"Properties": {
"statusCode": "NoContent",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"message": "Microsoft.RecoveryServices/vaults/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "34308349-0d12-8d5d-b410-8428c65886d6",
"eventSubmissionTimestamp": "2026-07-02T18:28:40.3209307Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afvaults",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "NoContent"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"message": "Microsoft.RecoveryServices/vaults/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "34308349-0d12-8d5d-b410-8428c65886d6",
"eventSubmissionTimestamp": "2026-07-02T18:28:40.3209307Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afvaults",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "NoContent",
"serviceRequestId": "",
"activitySubstatusValue": "NoContent"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.RecoveryServices/Vaults/extendedInformation/delete
#Description
The Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?
Microsoft.RecoveryServices/Vaults/extendedInformation/write
#Description
The Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?
Microsoft.RecoveryServices/Vaults/monitoringAlerts/write
#Description
Resolves the alert.
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/write
#Description
Configures e-mail notifications to Recovery services vault.
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/delete
#Description
Wait for a few minutes and then try the operation again. If the issue persists, please contact Microsoft support.
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/validate/action
#Description
Get all protectable containers
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/write
#Description
Get all protectable containers
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/delete
#Description
Delete Private Endpoint requests. This call is made by Backup Admin.
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/write
#Description
Approve or Reject Private Endpoint requests. This call is made by Backup Admin.
Microsoft.RecoveryServices/Vaults/PrivateEndpointConnectionsApproval/action
#Description
Approve the Private Endpoint Connection.
Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Azure Backup Diagnostics
Microsoft.RecoveryServices/Vaults/registeredIdentities/delete
#Description
The UnRegister Container operation can be used to unregister a container.
Microsoft.RecoveryServices/Vaults/registeredIdentities/write
#Description
The Register Service Container operation can be used to register a container with Recovery Service.
Microsoft.RecoveryServices/vaults/replicationAlertSettings/write
#Description
Create or Update any Alerts Settings
Microsoft.RecoveryServices/vaults/replicationFabrics/checkConsistency/action
#Description
Checks Consistency of the Fabric
Microsoft.RecoveryServices/vaults/replicationFabrics/delete
#Description
Delete any Fabrics
Microsoft.RecoveryServices/vaults/replicationFabrics/deployProcessServerImage/action
#Description
Deploy Process Server Image
Microsoft.RecoveryServices/vaults/replicationFabrics/migratetoaad/action
#Description
Migrate Fabric To AAD
Microsoft.RecoveryServices/vaults/replicationFabrics/moveWebApp/action
#Description
Move WebApp
Microsoft.RecoveryServices/vaults/replicationFabrics/reassociateGateway/action
#Description
Reassociate Gateway
Microsoft.RecoveryServices/vaults/replicationFabrics/remove/action
#Description
Remove Fabric
Microsoft.RecoveryServices/vaults/replicationFabrics/removeInfra/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/renewcertificate/action
#Description
Renew Certificate for Fabric
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/delete
#Description
Delete any Network Mappings
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/write
#Description
Create or Update any Network Mappings
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/discoverProtectableItem/action
#Description
Discover Protectable Item
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/remove/action
#Description
Remove Protection Container
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/delete
#Description
Delete any Migration Items
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/migrate/action
#Description
Migrate Item
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/pauseReplication/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resumeReplication/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resync/action
#Description
Resynchronize
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrate/action
#Description
Test Migrate
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrateCleanup/action
#Description
Test Migrate Cleanup
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/write
#Description
Create or Update any Migration Items
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/addDisks/action
#Description
Add disks
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/applyRecoveryPoint/action
#Description
Apply Recovery Point
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/delete
#Description
Delete any Protected Items
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCancel/action
#Description
Failover Cancel
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCommit/action
#Description
Failover Commit
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/plannedFailover/action
#Description
Planned Failover
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reinstallMobilityService/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/remove/action
#Description
Remove Protected Item
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/removeDisks/action
#Description
Remove disks
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/action
#Description
Repair replication
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/action
#Description
ReProtect Protected Item
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/ResolveHealthErrors/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/submitFeedback/action
#Description
Submit Feedback
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/action
#Description
Test Failover
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/action
#Description
Test Failover Cleanup
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/action
#Description
Failover
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateAppliance/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateMobilityService/action
#Description
Update Mobility Service
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/write
#Description
Create or Update any Protected Items
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/applyRecoveryPoint/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/delete
#Description
Delete any
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/failoverCommit/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/repairReplication/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/testFailover/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/testFailoverCleanup/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/unplannedFailover/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/delete
#Description
Delete any Protection Container Mappings
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/remove/action
#Description
Remove Protection Container Mapping
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/write
#Description
Create or Update any Protection Container Mappings
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchClusterProtection/action
#Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/action
#Description
Switch Protection Container
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/write
#Description
Create or Update any Protection Containers
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/delete
#Description
Delete any Recovery Services Providers
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/refreshProvider/action
#Description
Refresh Provider
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/remove/action
#Description
Remove Recovery Services Provider
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/write
#Description
Create or Update any Recovery Services Providers
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/delete
#Description
Delete any Storage Classification Mappings
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/write
#Description
Create or Update any Storage Classification Mappings
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/delete
#Description
Delete any vCenters
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/write
#Description
Create or Update any vCenters
Microsoft.RecoveryServices/vaults/replicationFabrics/write
#Description
Create or Update any Fabrics
Microsoft.RecoveryServices/vaults/replicationJobs/cancel/action
#Description
Cancel Job
Microsoft.RecoveryServices/vaults/replicationJobs/restart/action
#Description
Restart job
Microsoft.RecoveryServices/vaults/replicationJobs/resume/action
#Description
Resume Job
Microsoft.RecoveryServices/vaults/replicationPolicies/delete
#Description
Delete any Policies
Microsoft.RecoveryServices/vaults/replicationPolicies/write
#Description
Create or Update any Policies
Microsoft.RecoveryServices/vaults/replicationProtectionIntents/write
#Description
Create or Update any
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/delete
#Description
Delete any Recovery Plans
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCancel/action
#Description
Cancel Failover Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCommit/action
#Description
Failover Commit Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/plannedFailover/action
#Description
Planned Failover Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/reProtect/action
#Description
ReProtect Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailover/action
#Description
Test Failover Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailoverCleanup/action
#Description
Test Failover Cleanup Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/unplannedFailover/action
#Description
Failover Recovery Plan
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/write
#Description
Create or Update any Recovery Plans
Microsoft.RecoveryServices/vaults/replicationVaultHealth/refresh/action
#Description
Refresh Vault Health
Microsoft.RecoveryServices/vaults/replicationVaultSettings/write
#Description
Create or Update any
Microsoft.RecoveryServices/Vaults/write
#Description
Create Vault operation creates an Azure resource of type 'vault'
Example Resource Log Record #
{
"ActivityStatusValue": "Failure",
"ActivitySubstatusValue": "Conflict",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"action": "Microsoft.RecoveryServices/vaults/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"action": "Microsoft.RecoveryServices/vaults/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "7849ac19-15dd-4b53-93d6-d21dc49d6183",
"EventDataId": "e7b81ee1-3027-5f09-9b76-dac77115bea7",
"EventSubmissionTimestamp": "2026-07-02T18:28:39.0525582Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Error",
"OperationNameValue": "MICROSOFT.RECOVERYSERVICES/VAULTS/WRITE",
"Properties": {
"statusCode": "Conflict",
"serviceRequestId": "",
"statusMessage": {
"error": {
"code": "MissingSubscriptionRegistration",
"message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions.",
"details": [
{
"code": "MissingSubscriptionRegistration",
"target": "Microsoft.RecoveryServices",
"message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions."
}
]
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"message": "Microsoft.RecoveryServices/vaults/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e7b81ee1-3027-5f09-9b76-dac77115bea7",
"eventSubmissionTimestamp": "2026-07-02T18:28:39.0525582Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afvaults",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "Conflict"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
"message": "Microsoft.RecoveryServices/vaults/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e7b81ee1-3027-5f09-9b76-dac77115bea7",
"eventSubmissionTimestamp": "2026-07-02T18:28:39.0525582Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afvaults",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"statusCode": "Conflict",
"serviceRequestId": "",
"activitySubstatusValue": "Conflict",
"statusMessage": {
"error": {
"code": "MissingSubscriptionRegistration",
"message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions.",
"details": [
{
"code": "MissingSubscriptionRegistration",
"target": "Microsoft.RecoveryServices",
"message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions."
}
]
}
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}