Azure Resource Manager Azure-Microsoft.Resources
any: Azure Resource Manager (catch-all)
#Description
Catch-all for Azure-Microsoft.Resources rules that match the resource provider but no specific operation.
References #
Microsoft.Resources/calculateTemplateHash/action
#Description
Calculate the hash of provided template.
References #
Microsoft.Resources/checkResourceName/action
#Description
Check the resource name for validity.
References #
Microsoft.Resources/deployments/exportTemplate/action
#Description
Export template for a deployment
References #
Microsoft.Resources/deployments/operationstatuses/read
#Description
Gets or lists deployment operation statuses.
References #
Microsoft.Resources/deployments/validate/action
#Description
Validates a deployment.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"action": "Microsoft.Resources/deployments/validate/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"action": "Microsoft.Resources/deployments/validate/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "e376a701-e2c0-42b5-88d8-08f5ab6eadc0",
"EventDataId": "616073e7-cfb7-28c0-7274-2341b6daa048",
"EventSubmissionTimestamp": "2026-06-29T19:03:25.7433608Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.RESOURCES/DEPLOYMENTS/VALIDATE/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"message": "Microsoft.Resources/deployments/validate/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "616073e7-cfb7-28c0-7274-2341b6daa048",
"eventSubmissionTimestamp": "2026-06-29T19:03:25.7433608Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcdeploy3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"message": "Microsoft.Resources/deployments/validate/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "616073e7-cfb7-28c0-7274-2341b6daa048",
"eventSubmissionTimestamp": "2026-06-29T19:03:25.7433608Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcdeploy3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.RESOURCES",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:03:25.7433608Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.resources/deployments/zcdeploy3"
}
References #
Microsoft.Resources/deployments/whatIf/action
#Description
Predicts template deployment changes.
References #
Microsoft.Resources/deployments/write
#Description
Creates or updates an deployment.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Accept",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"action": "Microsoft.Resources/deployments/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"action": "Microsoft.Resources/deployments/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "3063388a-5c40-4da9-8fb6-6c1dabc4edf9",
"EventDataId": "44701c29-2e40-2d60-efbd-28ee6caf0ac7",
"EventSubmissionTimestamp": "2026-06-29T19:03:26.3230097Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.RESOURCES/DEPLOYMENTS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"message": "Microsoft.Resources/deployments/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "44701c29-2e40-2d60-efbd-28ee6caf0ac7",
"eventSubmissionTimestamp": "2026-06-29T19:03:26.3230097Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcdeploy3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
"message": "Microsoft.Resources/deployments/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "44701c29-2e40-2d60-efbd-28ee6caf0ac7",
"eventSubmissionTimestamp": "2026-06-29T19:03:26.3230097Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcdeploy3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Created"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.RESOURCES",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:03:26.3230097Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.resources/deployments/zcdeploy3"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure_ad::operation_name_value (kusto rule field) | in | microsoft.compute/virtualmachines/write | 4 rules | kusto |
azure_ad::operation_name_value (kusto rule field) | in | microsoft.resources/deployments/write | 4 rules | kusto |
ActivityStatusValue (kusto rule field) | starts_with | Accept | 2 rules | kusto |
Properties (kusto rule field) | contains | vmsize | 2 rules | kusto |
vmSize (kusto rule field) | cross_field_compare | token | 2 rules | kusto |
anomalies (kusto rule field) | gt | 0 | 1 rule | kusto |
baseline (kusto rule field) | gt | 0 | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098Kusto #
T1496T1578T1578
References #
Microsoft.Resources/deploymentScripts/write
#Description
Creates or updates a deployment script
References #
Microsoft.Resources/deploymentStacks/exportTemplate/action
#Description
Export the template for a deployment stack
References #
Microsoft.Resources/deploymentStacks/manageDenySetting/action
#Description
Manage the denySettings property of a deployment stack.
References #
Microsoft.Resources/deploymentStacks/validate/action
#Description
Validates a deployment stack.
References #
Microsoft.Resources/deploymentStacks/write
#Description
Creates or updates a deployment stack
References #
Microsoft.Resources/deploymentStacksWhatIfResults/delete
#Description
Deletes a deployment stack what-if result
References #
Microsoft.Resources/deploymentStacksWhatIfResults/whatIf/action
#Description
Provides property-level detail for the changes predicted by the deployment stack what-if result.
References #
Microsoft.Resources/deploymentStacksWhatIfResults/write
#Description
Creates or updates a deployment stack what-if result, which will predict changes to the specified deployment stack
References #
Microsoft.Resources/marketplace/purchase/action
#Description
Purchases a resource from the marketplace.
References #
Microsoft.Resources/populateRegionalMoveTargetResource/action
#Description
Populate Regional Move Target Resource
References #
Microsoft.Resources/relayRegionalMoveRequest/action
#Description
Relay Regional Move Request
References #
Microsoft.Resources/subscriptions/resourceGroups/delete
#Description
Deletes a resource group and all its resources.
Example Resource Log Record #
{
"TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
"SourceSystem": "Azure",
"CallerIpAddress": "37.142.150.162",
"CategoryValue": "Administrative",
"CorrelationId": "84fcb0a6-91db-4f09-a74e-97d1d41f2c6f",
"Authorization": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
"action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
"action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"OperationNameValue": "MICROSOFT.RESOURCES/SUBSCRIPTIONS/RESOURCEGROUPS/DELETE",
"Properties": {
"statusCode": "Accepted",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
"message": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "a16b075b-6bc3-4b66-8745-6b7a36adb050",
"eventSubmissionTimestamp": "2021-04-28T14:43:48.5341324Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resourceGroup": "EY_DEMO",
"subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Properties_d": {
"statusCode": "Accepted",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
"message": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "a16b075b-6bc3-4b66-8745-6b7a36adb050",
"eventSubmissionTimestamp": "2021-04-28T14:43:48.5341324Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resourceGroup": "EY_DEMO",
"subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Caller": "AdeleV@M365x816222.OnMicrosoft.com",
"EventDataId": "a16b075b-6bc3-4b66-8745-6b7a36adb050",
"EventSubmissionTimestamp": "4/28/2021, 2:43:48.534 PM",
"HTTPRequest": {
"clientIpAddress": "37.142.150.162"
},
"ResourceGroup": "EY_DEMO",
"ActivityStatusValue": "Accept",
"ActivitySubstatusValue": "Accepted",
"Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"TimeGenerated": "4/28/2021, 2:43:48.534 PM",
"SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"Type": "AzureActivity"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1489, T1490, T1529, T1562, T1562.001Panther #
T1485
References #
Microsoft.Resources/subscriptions/resourcegroups/deployments/write
#Description
Creates or updates an deployment.
References #
Microsoft.Resources/subscriptions/resourceGroups/moveResources/action
#Description
Moves resources from one resource group to another.
References #
Microsoft.Resources/subscriptions/resourceGroups/validateMoveResources/action
#Description
Validate move of resources from one resource group to another.
References #
Microsoft.Resources/subscriptions/resourceGroups/write
#Description
Creates or updates a resource group.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
"action": "Microsoft.Resources/subscriptions/resourcegroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
"action": "Microsoft.Resources/subscriptions/resourcegroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783008141",
"nbf": "1783008141",
"exp": "1783012267",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "joig862JV0W_vEH8aP97AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 8",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783008141",
"nbf": "1783008141",
"exp": "1783012267",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "joig862JV0W_vEH8aP97AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 8",
"xms_tcdt": "1768616282"
},
"CorrelationId": "c6a1ce19-3429-4043-9811-4e99eaafa16e",
"EventDataId": "8b7e0725-0aba-dfce-dd5d-3795571a99f0",
"EventSubmissionTimestamp": "2026-07-02T16:41:07.7012536Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.RESOURCES/SUBSCRIPTIONS/RESOURCEGROUPS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"responseBody": {
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen",
"name": "rg-logcapture-gen",
"type": "Microsoft.Resources/resourceGroups",
"location": "westus2",
"tags": {
"dwharn": "7000408c",
"purpose": "capture"
},
"properties": {
"provisioningState": "Succeeded"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
"message": "Microsoft.Resources/subscriptions/resourcegroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "8b7e0725-0aba-dfce-dd5d-3795571a99f0",
"eventSubmissionTimestamp": "2026-07-02T16:41:07.7012536Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceGroup": "rg-logcapture-gen",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"responseBody": {
"id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen",
"name": "rg-logcapture-gen",
"type": "Microsoft.Resources/resourceGroups",
"location": "westus2",
"tags": {
"dwharn": "7000408c",
"purpose": "capture"
},
"properties": {
"provisioningState": "Succeeded"
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
"message": "Microsoft.Resources/subscriptions/resourcegroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "8b7e0725-0aba-dfce-dd5d-3795571a99f0",
"eventSubmissionTimestamp": "2026-07-02T16:41:07.7012536Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceGroup": "rg-logcapture-gen",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure_ad::operation_name_value (kusto rule field) | in | microsoft.compute/virtualmachines/write | 1 rule | kusto |
azure_ad::operation_name_value (kusto rule field) | in | microsoft.resources/deployments/write | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1496↳ also matches Microsoft.Resources/deployments/write
References #
Microsoft.Resources/subscriptions/tagNames/delete
#Description
Deletes a subscription tag.
References #
Microsoft.Resources/subscriptions/tagNames/tagValues/delete
#Description
Deletes a subscription tag value.
References #
Microsoft.Resources/subscriptions/tagNames/tagValues/write
#Description
Adds a subscription tag value.
References #
Microsoft.Resources/templateSpecs/delete
#Description
Deletes a template spec
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"action": "Microsoft.Resources/templateSpecs/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"action": "Microsoft.Resources/templateSpecs/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "ab35ee1b-36fc-4260-a030-b1930c94689b",
"EventDataId": "0360c1f5-c990-997d-867e-150f9f8206b2",
"EventSubmissionTimestamp": "2026-07-02T18:29:08.5643434Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.RESOURCES/TEMPLATESPECS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"message": "Microsoft.Resources/templateSpecs/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "0360c1f5-c990-997d-867e-150f9f8206b2",
"eventSubmissionTimestamp": "2026-07-02T18:29:08.5643434Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220aftemplatespecs",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"message": "Microsoft.Resources/templateSpecs/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "0360c1f5-c990-997d-867e-150f9f8206b2",
"eventSubmissionTimestamp": "2026-07-02T18:29:08.5643434Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220aftemplatespecs",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.RESOURCES",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Resources/templateSpecs/versions/delete
#Description
Deletes a template spec version
References #
Microsoft.Resources/templateSpecs/versions/write
#Description
Creates or updates a template spec version
References #
Microsoft.Resources/templateSpecs/write
#Description
Creates or updates a template spec
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"action": "Microsoft.Resources/templateSpecs/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"action": "Microsoft.Resources/templateSpecs/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "a6142e4c-c1b4-4e05-9c4e-c003a162fe44",
"EventDataId": "7da56b06-f5ec-8273-ac7a-42b60b818691",
"EventSubmissionTimestamp": "2026-07-02T18:28:36.4218368Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.RESOURCES/TEMPLATESPECS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"message": "Microsoft.Resources/templateSpecs/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "7da56b06-f5ec-8273-ac7a-42b60b818691",
"eventSubmissionTimestamp": "2026-07-02T18:28:36.4218368Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220aftemplatespecs",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
"message": "Microsoft.Resources/templateSpecs/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "7da56b06-f5ec-8273-ac7a-42b60b818691",
"eventSubmissionTimestamp": "2026-07-02T18:28:36.4218368Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220aftemplatespecs",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.RESOURCES",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.RESOURCES",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}