Azure Recovery Services Azure-Microsoft.RecoveryServices

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.RecoveryServices rules that match the resource provider but no specific operation.NN
Microsoft.RecoveryServices/locations/allocateStamp/actionAllocateStamp is internal operation used by serviceNN
Microsoft.RecoveryServices/Locations/backupCrossRegionRestore/actionTrigger Cross region restore.NN
Microsoft.RecoveryServices/Locations/backupCrrJob/actionGet Cross Region Restore Job Details in the secondary region for Recovery Services Vault.NN
Microsoft.RecoveryServices/Locations/backupCrrJobCancel/actionGet Cross Region Restore Job Details in the secondary region for Recovery Services Vault.NN
Microsoft.RecoveryServices/Locations/backupCrrJobs/actionList Cross Region Restore Jobs in the secondary region for Recovery Services Vault.NN
Microsoft.RecoveryServices/Locations/backupPreValidateProtection/actionPre Validate Enable ProtectionNN
Microsoft.RecoveryServices/Locations/backupProtectedItem/writeCreate a backup Protected ItemNN
Microsoft.RecoveryServices/Locations/backupStatus/actionCheck Backup Status for Recovery Services VaultsNN
Microsoft.RecoveryServices/Locations/backupValidateFeatures/actionValidate FeaturesNN
Microsoft.RecoveryServices/locations/capabilities/actionList capabilities at a given location.NN
Microsoft.RecoveryServices/locations/checkNameAvailability/actionCheck Resource Name Availability is an API to check if resource name is availableNN
Microsoft.RecoveryServices/locations/deletedVaults/undelete/actionUndelete DeletedVault operation re-creates an Azure resource of type 'vault'.NN
Microsoft.RecoveryServices/register/actionRegisters subscription for given Resource ProviderNN
Microsoft.RecoveryServices/unregister/actionUnregisters subscription for given Resource ProviderNN
Microsoft.RecoveryServices/Vaults/backupconfig/writeUpdates Configuration for Recovery Services Vault.NN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/actionRestore recovery point from cross-tenant mapped vault for the protected items.NN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupTriggerValidateOperation/actionValidate Operation on Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupValidateOperation/actionValidate Operation on Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/remove/actionRemove the backup cross-tenant vault mapping.NN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/vaultCredentials/generate/actionRetrieves the cross-tenant vault mapping.NN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/writeCreate a backup cross-tenant vault mapping.NN
Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappingStatus/actionRetrieves the status of the cross-tenant vault mapping.NN
Microsoft.RecoveryServices/Vaults/backupEncryptionConfigs/writeUpdates Backup Resource Encryption ConfigurationNN
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/deleteDelete a backup Protection IntentNN
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/writeCreate a backup Protection IntentNN
Microsoft.RecoveryServices/Vaults/backupFabrics/getRecoveryPoints/actionGet Recovery Points for Protected Items.NN
Microsoft.RecoveryServices/Vaults/backupFabrics/preCheckRestore/actionRestore Recovery Points for Protected Items.NN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/deleteDeletes the registered ContainerNY
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/actionDo inquiry for workloads within a containerNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/actionPerforms Backup for Protected Item.NN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/deleteDeletes Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/actionGet AccessToken for Cross Region Restore.NN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/move/actionMove Recovery point to another tierNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/actionProvision Instant Item Recovery for Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/actionRestore Recovery Points for Protected Items.NN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/actionRevoke Instant Item Recovery for Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/writeUpdate Recovery Point for Protected Item.NN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPointsRecommendedForMove/actionGet Recovery points recommended for move to another tierNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/writeCreate a backup Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/writeCreates a registered containerNN
Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/actionRefreshes the container listNN
Microsoft.RecoveryServices/Vaults/backupFabrics/restore/actionRestore Recovery Points for Protected Items.NN
Microsoft.RecoveryServices/Vaults/backupJobs/cancel/actionCancel the JobNN
Microsoft.RecoveryServices/Vaults/backupJobs/retry/actionRetry the JobNN
Microsoft.RecoveryServices/Vaults/backupJobsExport/actionExport JobsNN
Microsoft.RecoveryServices/Vaults/backupPolicies/deleteDelete a Protection PolicyNN
Microsoft.RecoveryServices/Vaults/backupPolicies/writeCreates or Updates Protection PolicyNN
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/deleteThe Delete ResourceGuard proxy operation deletes the specified Azure resource of type 'ResourceGuard proxy'NN
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/actionUnlock delete ResourceGuard proxy operation unlocks the next delete critical operationNN
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/writeCreate ResourceGuard proxy operation creates an Azure resource of type 'ResourceGuard Proxy'NN
Microsoft.RecoveryServices/Vaults/backupSecurityPIN/actionReturns Security PIN Information for Recovery Services Vault.NN
Microsoft.RecoveryServices/Vaults/backupstorageconfig/writeUpdates Storage Configuration for Recovery Services Vault.NN
Microsoft.RecoveryServices/Vaults/backupTieringCost/fetchTieringCost/actionReturns the tiering related cost info.NN
Microsoft.RecoveryServices/Vaults/backupTriggerValidateOperation/actionValidate Operation on Protected ItemNN
Microsoft.RecoveryServices/Vaults/backupValidateOperation/actionValidate Operation on Protected ItemNN
Microsoft.RecoveryServices/Vaults/certificates/writeThe Update Resource Certificate operation updates the resource/vault credential certificate.NN
Microsoft.RecoveryServices/Vaults/deleteThe Delete Vault operation deletes the specified Azure resource of type 'vault'YN
Microsoft.RecoveryServices/Vaults/extendedInformation/deleteThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?NN
Microsoft.RecoveryServices/Vaults/extendedInformation/writeThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?NN
Microsoft.RecoveryServices/Vaults/monitoringAlerts/writeResolves the alert.NN
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/writeConfigures e-mail notifications to Recovery services vault.NN
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/deleteWait for a few minutes and then try the operation again. If the issue persists, please contact Microsoft support.NN
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/validate/actionGet all protectable containersNN
Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/writeGet all protectable containersNN
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/deleteDelete Private Endpoint requests. This call is made by Backup Admin.NN
Microsoft.RecoveryServices/Vaults/privateEndpointConnections/writeApprove or Reject Private Endpoint requests. This call is made by Backup Admin.NN
Microsoft.RecoveryServices/Vaults/PrivateEndpointConnectionsApproval/actionApprove the Private Endpoint Connection.NN
Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/diagnosticSettings/writeAzure Backup DiagnosticsNN
Microsoft.RecoveryServices/Vaults/registeredIdentities/deleteThe UnRegister Container operation can be used to unregister a container.NN
Microsoft.RecoveryServices/Vaults/registeredIdentities/writeThe Register Service Container operation can be used to register a container with Recovery Service.NN
Microsoft.RecoveryServices/vaults/replicationAlertSettings/writeCreate or Update any Alerts SettingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/checkConsistency/actionChecks Consistency of the FabricNN
Microsoft.RecoveryServices/vaults/replicationFabrics/deleteDelete any FabricsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/deployProcessServerImage/actionDeploy Process Server ImageNN
Microsoft.RecoveryServices/vaults/replicationFabrics/migratetoaad/actionMigrate Fabric To AADNN
Microsoft.RecoveryServices/vaults/replicationFabrics/moveWebApp/actionMove WebAppNN
Microsoft.RecoveryServices/vaults/replicationFabrics/reassociateGateway/actionReassociate GatewayNN
Microsoft.RecoveryServices/vaults/replicationFabrics/remove/actionRemove FabricNN
Microsoft.RecoveryServices/vaults/replicationFabrics/removeInfra/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/renewcertificate/actionRenew Certificate for FabricNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/deleteDelete any Network MappingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/writeCreate or Update any Network MappingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/discoverProtectableItem/actionDiscover Protectable ItemNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/remove/actionRemove Protection ContainerNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/deleteDelete any Migration ItemsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/migrate/actionMigrate ItemNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/pauseReplication/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resumeReplication/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resync/actionResynchronizeNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrate/actionTest MigrateNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrateCleanup/actionTest Migrate CleanupNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/writeCreate or Update any Migration ItemsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/addDisks/actionAdd disksNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/applyRecoveryPoint/actionApply Recovery PointNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/deleteDelete any Protected ItemsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCancel/actionFailover CancelNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCommit/actionFailover CommitNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/plannedFailover/actionPlanned FailoverNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reinstallMobilityService/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/remove/actionRemove Protected ItemNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/removeDisks/actionRemove disksNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/actionRepair replicationNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/actionReProtect Protected ItemNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/ResolveHealthErrors/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/submitFeedback/actionSubmit FeedbackNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/actionTest FailoverNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/actionTest Failover CleanupNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/actionFailoverNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateAppliance/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateMobilityService/actionUpdate Mobility ServiceNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/writeCreate or Update any Protected ItemsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/applyRecoveryPoint/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/deleteDelete anyNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/failoverCommit/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/repairReplication/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/testFailover/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/testFailoverCleanup/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/unplannedFailover/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/deleteDelete any Protection Container MappingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/remove/actionRemove Protection Container MappingNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/writeCreate or Update any Protection Container MappingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchClusterProtection/actionNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/actionSwitch Protection ContainerNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/writeCreate or Update any Protection ContainersNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/deleteDelete any Recovery Services ProvidersNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/refreshProvider/actionRefresh ProviderNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/remove/actionRemove Recovery Services ProviderNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/writeCreate or Update any Recovery Services ProvidersNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/deleteDelete any Storage Classification MappingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/writeCreate or Update any Storage Classification MappingsNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/deleteDelete any vCentersNN
Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/writeCreate or Update any vCentersNN
Microsoft.RecoveryServices/vaults/replicationFabrics/writeCreate or Update any FabricsNN
Microsoft.RecoveryServices/vaults/replicationJobs/cancel/actionCancel JobNN
Microsoft.RecoveryServices/vaults/replicationJobs/restart/actionRestart jobNN
Microsoft.RecoveryServices/vaults/replicationJobs/resume/actionResume JobNN
Microsoft.RecoveryServices/vaults/replicationPolicies/deleteDelete any PoliciesNN
Microsoft.RecoveryServices/vaults/replicationPolicies/writeCreate or Update any PoliciesNN
Microsoft.RecoveryServices/vaults/replicationProtectionIntents/writeCreate or Update anyNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/deleteDelete any Recovery PlansNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCancel/actionCancel Failover Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCommit/actionFailover Commit Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/plannedFailover/actionPlanned Failover Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/reProtect/actionReProtect Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailover/actionTest Failover Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailoverCleanup/actionTest Failover Cleanup Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/unplannedFailover/actionFailover Recovery PlanNN
Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/writeCreate or Update any Recovery PlansNN
Microsoft.RecoveryServices/vaults/replicationVaultHealth/refresh/actionRefresh Vault HealthNN
Microsoft.RecoveryServices/vaults/replicationVaultSettings/writeCreate or Update anyNN
Microsoft.RecoveryServices/Vaults/writeCreate Vault operation creates an Azure resource of type 'vault'YN

any: Azure Recovery Services (catch-all)

#
Namespace
Microsoft.RecoveryServices

Description

Catch-all for Azure-Microsoft.RecoveryServices rules that match the resource provider but no specific operation.

Microsoft.RecoveryServices/locations/allocateStamp/action

#
Namespace
Microsoft.RecoveryServices

Description

AllocateStamp is internal operation used by service

Microsoft.RecoveryServices/Locations/backupCrossRegionRestore/action

#
Namespace
Microsoft.RecoveryServices

Description

Trigger Cross region restore.

Microsoft.RecoveryServices/Locations/backupCrrJob/action

#
Namespace
Microsoft.RecoveryServices

Description

Get Cross Region Restore Job Details in the secondary region for Recovery Services Vault.

Microsoft.RecoveryServices/Locations/backupCrrJobCancel/action

#
Namespace
Microsoft.RecoveryServices

Description

Get Cross Region Restore Job Details in the secondary region for Recovery Services Vault.

Microsoft.RecoveryServices/Locations/backupCrrJobs/action

#
Namespace
Microsoft.RecoveryServices

Description

List Cross Region Restore Jobs in the secondary region for Recovery Services Vault.

Microsoft.RecoveryServices/Locations/backupPreValidateProtection/action

#
Namespace
Microsoft.RecoveryServices

Description

Pre Validate Enable Protection

Microsoft.RecoveryServices/Locations/backupProtectedItem/write

#
Namespace
Microsoft.RecoveryServices

Description

Create a backup Protected Item

Microsoft.RecoveryServices/Locations/backupStatus/action

#
Namespace
Microsoft.RecoveryServices

Description

Check Backup Status for Recovery Services Vaults

Microsoft.RecoveryServices/Locations/backupValidateFeatures/action

#
Namespace
Microsoft.RecoveryServices

Description

Validate Features

Microsoft.RecoveryServices/locations/capabilities/action

#
Namespace
Microsoft.RecoveryServices

Description

List capabilities at a given location.

Microsoft.RecoveryServices/locations/checkNameAvailability/action

#
Namespace
Microsoft.RecoveryServices

Description

Check Resource Name Availability is an API to check if resource name is available

Microsoft.RecoveryServices/locations/deletedVaults/undelete/action

#
Namespace
Microsoft.RecoveryServices

Description

Undelete DeletedVault operation re-creates an Azure resource of type 'vault'.

Microsoft.RecoveryServices/register/action

#
Namespace
Microsoft.RecoveryServices

Description

Registers subscription for given Resource Provider

Microsoft.RecoveryServices/unregister/action

#
Namespace
Microsoft.RecoveryServices

Description

Unregisters subscription for given Resource Provider

Microsoft.RecoveryServices/Vaults/backupconfig/write

#
Namespace
Microsoft.RecoveryServices

Description

Updates Configuration for Recovery Services Vault.

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/action

#
Namespace
Microsoft.RecoveryServices

Description

Restore recovery point from cross-tenant mapped vault for the protected items.

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupTriggerValidateOperation/action

#
Namespace
Microsoft.RecoveryServices

Description

Validate Operation on Protected Item

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/backupValidateOperation/action

#
Namespace
Microsoft.RecoveryServices

Description

Validate Operation on Protected Item

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/remove/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove the backup cross-tenant vault mapping.

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/vaultCredentials/generate/action

#
Namespace
Microsoft.RecoveryServices

Description

Retrieves the cross-tenant vault mapping.

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappings/write

#
Namespace
Microsoft.RecoveryServices

Description

Create a backup cross-tenant vault mapping.

Microsoft.RecoveryServices/Vaults/backupCrossTenantVaultMappingStatus/action

#
Namespace
Microsoft.RecoveryServices

Description

Retrieves the status of the cross-tenant vault mapping.

Microsoft.RecoveryServices/Vaults/backupEncryptionConfigs/write

#
Namespace
Microsoft.RecoveryServices

Description

Updates Backup Resource Encryption Configuration

Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete a backup Protection Intent

Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/write

#
Namespace
Microsoft.RecoveryServices

Description

Create a backup Protection Intent

Microsoft.RecoveryServices/Vaults/backupFabrics/getRecoveryPoints/action

#
Namespace
Microsoft.RecoveryServices

Description

Get Recovery Points for Protected Items.

Microsoft.RecoveryServices/Vaults/backupFabrics/preCheckRestore/action

#
Namespace
Microsoft.RecoveryServices

Description

Restore Recovery Points for Protected Items.

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete

#
Namespace
Microsoft.RecoveryServices

Description

Deletes the registered Container

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Recovery Services Protection Container Deleted source high: Detects deletion of Azure Recovery Services protection containers containing VM and workload backups. Storm-0501 systematically deletes backup containers before deploying ransomware to prevent recovery. This operation permanently destroys all recovery points for protected resources.T1485, T1490, T1562

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/action

#
Namespace
Microsoft.RecoveryServices

Description

Do inquiry for workloads within a container

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/action

#
Namespace
Microsoft.RecoveryServices

Description

Performs Backup for Protected Item.

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/delete

#
Namespace
Microsoft.RecoveryServices

Description

Deletes Protected Item

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/action

#
Namespace
Microsoft.RecoveryServices

Description

Get AccessToken for Cross Region Restore.

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/move/action

#
Namespace
Microsoft.RecoveryServices

Description

Move Recovery point to another tier

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/action

#
Namespace
Microsoft.RecoveryServices

Description

Provision Instant Item Recovery for Protected Item

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/action

#
Namespace
Microsoft.RecoveryServices

Description

Restore Recovery Points for Protected Items.

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/action

#
Namespace
Microsoft.RecoveryServices

Description

Revoke Instant Item Recovery for Protected Item

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/write

#
Namespace
Microsoft.RecoveryServices

Description

Update Recovery Point for Protected Item.

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPointsRecommendedForMove/action

#
Namespace
Microsoft.RecoveryServices

Description

Get Recovery points recommended for move to another tier

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/write

#
Namespace
Microsoft.RecoveryServices

Description

Create a backup Protected Item

Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/write

#
Namespace
Microsoft.RecoveryServices

Description

Creates a registered container

Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/action

#
Namespace
Microsoft.RecoveryServices

Description

Refreshes the container list

Microsoft.RecoveryServices/Vaults/backupFabrics/restore/action

#
Namespace
Microsoft.RecoveryServices

Description

Restore Recovery Points for Protected Items.

Microsoft.RecoveryServices/Vaults/backupJobs/cancel/action

#
Namespace
Microsoft.RecoveryServices

Description

Cancel the Job

Microsoft.RecoveryServices/Vaults/backupJobs/retry/action

#
Namespace
Microsoft.RecoveryServices

Description

Retry the Job

Microsoft.RecoveryServices/Vaults/backupJobsExport/action

#
Namespace
Microsoft.RecoveryServices

Description

Export Jobs

Microsoft.RecoveryServices/Vaults/backupPolicies/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete a Protection Policy

Microsoft.RecoveryServices/Vaults/backupPolicies/write

#
Namespace
Microsoft.RecoveryServices

Description

Creates or Updates Protection Policy

Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/delete

#
Namespace
Microsoft.RecoveryServices

Description

The Delete ResourceGuard proxy operation deletes the specified Azure resource of type 'ResourceGuard proxy'

Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/action

#
Namespace
Microsoft.RecoveryServices

Description

Unlock delete ResourceGuard proxy operation unlocks the next delete critical operation

Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/write

#
Namespace
Microsoft.RecoveryServices

Description

Create ResourceGuard proxy operation creates an Azure resource of type 'ResourceGuard Proxy'

Microsoft.RecoveryServices/Vaults/backupSecurityPIN/action

#
Namespace
Microsoft.RecoveryServices

Description

Returns Security PIN Information for Recovery Services Vault.

Microsoft.RecoveryServices/Vaults/backupstorageconfig/write

#
Namespace
Microsoft.RecoveryServices

Description

Updates Storage Configuration for Recovery Services Vault.

Microsoft.RecoveryServices/Vaults/backupTieringCost/fetchTieringCost/action

#
Namespace
Microsoft.RecoveryServices

Description

Returns the tiering related cost info.

Microsoft.RecoveryServices/Vaults/backupTriggerValidateOperation/action

#
Namespace
Microsoft.RecoveryServices

Description

Validate Operation on Protected Item

Microsoft.RecoveryServices/Vaults/backupValidateOperation/action

#
Namespace
Microsoft.RecoveryServices

Description

Validate Operation on Protected Item

Microsoft.RecoveryServices/Vaults/certificates/write

#
Namespace
Microsoft.RecoveryServices

Description

The Update Resource Certificate operation updates the resource/vault credential certificate.

Microsoft.RecoveryServices/Vaults/delete

#
Namespace
Microsoft.RecoveryServices

Description

The Delete Vault operation deletes the specified Azure resource of type 'vault'

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "NoContent",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "action": "Microsoft.RecoveryServices/vaults/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "action": "Microsoft.RecoveryServices/vaults/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "21080611-87db-4895-96e3-6a384089ca85",
  "EventDataId": "34308349-0d12-8d5d-b410-8428c65886d6",
  "EventSubmissionTimestamp": "2026-07-02T18:28:40.3209307Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.RECOVERYSERVICES/VAULTS/DELETE",
  "Properties": {
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "message": "Microsoft.RecoveryServices/vaults/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "34308349-0d12-8d5d-b410-8428c65886d6",
    "eventSubmissionTimestamp": "2026-07-02T18:28:40.3209307Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afvaults",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "NoContent"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "message": "Microsoft.RecoveryServices/vaults/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "34308349-0d12-8d5d-b410-8428c65886d6",
    "eventSubmissionTimestamp": "2026-07-02T18:28:40.3209307Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afvaults",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "activitySubstatusValue": "NoContent"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.RecoveryServices/Vaults/extendedInformation/delete

#
Namespace
Microsoft.RecoveryServices

Description

The Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?

Microsoft.RecoveryServices/Vaults/extendedInformation/write

#
Namespace
Microsoft.RecoveryServices

Description

The Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?

Microsoft.RecoveryServices/Vaults/monitoringAlerts/write

#
Namespace
Microsoft.RecoveryServices

Description

Resolves the alert.

Microsoft.RecoveryServices/Vaults/monitoringConfigurations/write

#
Namespace
Microsoft.RecoveryServices

Description

Configures e-mail notifications to Recovery services vault.

Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.RecoveryServices

Description

Wait for a few minutes and then try the operation again. If the issue persists, please contact Microsoft support.

Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.RecoveryServices

Description

Get all protectable containers

Microsoft.RecoveryServices/Vaults/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.RecoveryServices

Description

Get all protectable containers

Microsoft.RecoveryServices/Vaults/privateEndpointConnections/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete Private Endpoint requests. This call is made by Backup Admin.

Microsoft.RecoveryServices/Vaults/privateEndpointConnections/write

#
Namespace
Microsoft.RecoveryServices

Description

Approve or Reject Private Endpoint requests. This call is made by Backup Admin.

Microsoft.RecoveryServices/Vaults/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.RecoveryServices

Description

Approve the Private Endpoint Connection.

Microsoft.RecoveryServices/Vaults/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.RecoveryServices

Description

Azure Backup Diagnostics

Microsoft.RecoveryServices/Vaults/registeredIdentities/delete

#
Namespace
Microsoft.RecoveryServices

Description

The UnRegister Container operation can be used to unregister a container.

Microsoft.RecoveryServices/Vaults/registeredIdentities/write

#
Namespace
Microsoft.RecoveryServices

Description

The Register Service Container operation can be used to register a container with Recovery Service.

Microsoft.RecoveryServices/vaults/replicationAlertSettings/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Alerts Settings

Microsoft.RecoveryServices/vaults/replicationFabrics/checkConsistency/action

#
Namespace
Microsoft.RecoveryServices

Description

Checks Consistency of the Fabric

Microsoft.RecoveryServices/vaults/replicationFabrics/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Fabrics

Microsoft.RecoveryServices/vaults/replicationFabrics/deployProcessServerImage/action

#
Namespace
Microsoft.RecoveryServices

Description

Deploy Process Server Image

Microsoft.RecoveryServices/vaults/replicationFabrics/migratetoaad/action

#
Namespace
Microsoft.RecoveryServices

Description

Migrate Fabric To AAD

Microsoft.RecoveryServices/vaults/replicationFabrics/moveWebApp/action

#
Namespace
Microsoft.RecoveryServices

Description

Move WebApp

Microsoft.RecoveryServices/vaults/replicationFabrics/reassociateGateway/action

#
Namespace
Microsoft.RecoveryServices

Description

Reassociate Gateway

Microsoft.RecoveryServices/vaults/replicationFabrics/remove/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove Fabric

Microsoft.RecoveryServices/vaults/replicationFabrics/removeInfra/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/renewcertificate/action

#
Namespace
Microsoft.RecoveryServices

Description

Renew Certificate for Fabric

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Network Mappings

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Network Mappings

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/discoverProtectableItem/action

#
Namespace
Microsoft.RecoveryServices

Description

Discover Protectable Item

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/remove/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove Protection Container

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Migration Items

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/migrate/action

#
Namespace
Microsoft.RecoveryServices

Description

Migrate Item

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/pauseReplication/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resumeReplication/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/resync/action

#
Namespace
Microsoft.RecoveryServices

Description

Resynchronize

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrate/action

#
Namespace
Microsoft.RecoveryServices

Description

Test Migrate

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/testMigrateCleanup/action

#
Namespace
Microsoft.RecoveryServices

Description

Test Migrate Cleanup

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationMigrationItems/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Migration Items

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/addDisks/action

#
Namespace
Microsoft.RecoveryServices

Description

Add disks

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/applyRecoveryPoint/action

#
Namespace
Microsoft.RecoveryServices

Description

Apply Recovery Point

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Protected Items

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCancel/action

#
Namespace
Microsoft.RecoveryServices

Description

Failover Cancel

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/failoverCommit/action

#
Namespace
Microsoft.RecoveryServices

Description

Failover Commit

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/plannedFailover/action

#
Namespace
Microsoft.RecoveryServices

Description

Planned Failover

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reinstallMobilityService/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/remove/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove Protected Item

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/removeDisks/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove disks

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/repairReplication/action

#
Namespace
Microsoft.RecoveryServices

Description

Repair replication

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/reProtect/action

#
Namespace
Microsoft.RecoveryServices

Description

ReProtect Protected Item

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/ResolveHealthErrors/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/submitFeedback/action

#
Namespace
Microsoft.RecoveryServices

Description

Submit Feedback

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailover/action

#
Namespace
Microsoft.RecoveryServices

Description

Test Failover

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/testFailoverCleanup/action

#
Namespace
Microsoft.RecoveryServices

Description

Test Failover Cleanup

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/unplannedFailover/action

#
Namespace
Microsoft.RecoveryServices

Description

Failover

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateAppliance/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/updateMobilityService/action

#
Namespace
Microsoft.RecoveryServices

Description

Update Mobility Service

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Protected Items

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/applyRecoveryPoint/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/failoverCommit/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/repairReplication/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/testFailover/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/testFailoverCleanup/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionClusters/unplannedFailover/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Protection Container Mappings

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/remove/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove Protection Container Mapping

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Protection Container Mappings

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchClusterProtection/action

#
Namespace
Microsoft.RecoveryServices

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/switchprotection/action

#
Namespace
Microsoft.RecoveryServices

Description

Switch Protection Container

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Protection Containers

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Recovery Services Providers

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/refreshProvider/action

#
Namespace
Microsoft.RecoveryServices

Description

Refresh Provider

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/remove/action

#
Namespace
Microsoft.RecoveryServices

Description

Remove Recovery Services Provider

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Recovery Services Providers

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Storage Classification Mappings

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Storage Classification Mappings

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any vCenters

Microsoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any vCenters

Microsoft.RecoveryServices/vaults/replicationFabrics/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Fabrics

Microsoft.RecoveryServices/vaults/replicationJobs/cancel/action

#
Namespace
Microsoft.RecoveryServices

Description

Cancel Job

Microsoft.RecoveryServices/vaults/replicationJobs/restart/action

#
Namespace
Microsoft.RecoveryServices

Description

Restart job

Microsoft.RecoveryServices/vaults/replicationJobs/resume/action

#
Namespace
Microsoft.RecoveryServices

Description

Resume Job

Microsoft.RecoveryServices/vaults/replicationPolicies/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Policies

Microsoft.RecoveryServices/vaults/replicationPolicies/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Policies

Microsoft.RecoveryServices/vaults/replicationProtectionIntents/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/delete

#
Namespace
Microsoft.RecoveryServices

Description

Delete any Recovery Plans

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCancel/action

#
Namespace
Microsoft.RecoveryServices

Description

Cancel Failover Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/failoverCommit/action

#
Namespace
Microsoft.RecoveryServices

Description

Failover Commit Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/plannedFailover/action

#
Namespace
Microsoft.RecoveryServices

Description

Planned Failover Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/reProtect/action

#
Namespace
Microsoft.RecoveryServices

Description

ReProtect Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailover/action

#
Namespace
Microsoft.RecoveryServices

Description

Test Failover Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/testFailoverCleanup/action

#
Namespace
Microsoft.RecoveryServices

Description

Test Failover Cleanup Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/unplannedFailover/action

#
Namespace
Microsoft.RecoveryServices

Description

Failover Recovery Plan

Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any Recovery Plans

Microsoft.RecoveryServices/vaults/replicationVaultHealth/refresh/action

#
Namespace
Microsoft.RecoveryServices

Description

Refresh Vault Health

Microsoft.RecoveryServices/vaults/replicationVaultSettings/write

#
Namespace
Microsoft.RecoveryServices

Description

Create or Update any

Microsoft.RecoveryServices/Vaults/write

#
Namespace
Microsoft.RecoveryServices

Description

Create Vault operation creates an Azure resource of type 'vault'

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "Conflict",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "action": "Microsoft.RecoveryServices/vaults/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "action": "Microsoft.RecoveryServices/vaults/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "7849ac19-15dd-4b53-93d6-d21dc49d6183",
  "EventDataId": "e7b81ee1-3027-5f09-9b76-dac77115bea7",
  "EventSubmissionTimestamp": "2026-07-02T18:28:39.0525582Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.RECOVERYSERVICES/VAULTS/WRITE",
  "Properties": {
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "MissingSubscriptionRegistration",
        "message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions.",
        "details": [
          {
            "code": "MissingSubscriptionRegistration",
            "target": "Microsoft.RecoveryServices",
            "message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions."
          }
        ]
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "message": "Microsoft.RecoveryServices/vaults/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e7b81ee1-3027-5f09-9b76-dac77115bea7",
    "eventSubmissionTimestamp": "2026-07-02T18:28:39.0525582Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afvaults",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "Conflict"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.RecoveryServices/vaults/dwh2220afvaults",
    "message": "Microsoft.RecoveryServices/vaults/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e7b81ee1-3027-5f09-9b76-dac77115bea7",
    "eventSubmissionTimestamp": "2026-07-02T18:28:39.0525582Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afvaults",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "activitySubstatusValue": "Conflict",
    "statusMessage": {
      "error": {
        "code": "MissingSubscriptionRegistration",
        "message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions.",
        "details": [
          {
            "code": "MissingSubscriptionRegistration",
            "target": "Microsoft.RecoveryServices",
            "message": "The subscription is not registered to use namespace 'Microsoft.RecoveryServices'. See https://aka.ms/rps-not-found for how to register subscriptions."
          }
        ]
      }
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.RECOVERYSERVICES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #