Azure Resource Manager Azure-Microsoft.Resources

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Resources rules that match the resource provider but no specific operation.NN
Microsoft.Resources/calculateTemplateHash/actionCalculate the hash of provided template.NN
Microsoft.Resources/checkResourceName/actionCheck the resource name for validity.NN
Microsoft.Resources/checkZonePeers/actionCheck Zone PeersNN
Microsoft.Resources/dataBoundaries/writeOpt-in to Data BoundaryNN
Microsoft.Resources/deployments/cancel/actionCancels a deployment.NN
Microsoft.Resources/deployments/deleteDeletes a deployment.NN
Microsoft.Resources/deployments/exportTemplate/actionExport template for a deploymentNN
Microsoft.Resources/deployments/operationstatuses/readGets or lists deployment operation statuses.NN
Microsoft.Resources/deployments/validate/actionValidates a deployment.YN
Microsoft.Resources/deployments/whatIf/actionPredicts template deployment changes.NN
Microsoft.Resources/deployments/writeCreates or updates an deployment.YY
Microsoft.Resources/deploymentScripts/deleteDeletes a deployment scriptNN
Microsoft.Resources/deploymentScripts/writeCreates or updates a deployment scriptNN
Microsoft.Resources/deploymentStacks/deleteDeletes a deployment stackNN
Microsoft.Resources/deploymentStacks/exportTemplate/actionExport the template for a deployment stackNN
Microsoft.Resources/deploymentStacks/manageDenySetting/actionManage the denySettings property of a deployment stack.NN
Microsoft.Resources/deploymentStacks/validate/actionValidates a deployment stack.NN
Microsoft.Resources/deploymentStacks/writeCreates or updates a deployment stackNN
Microsoft.Resources/deploymentStacksWhatIfResults/deleteDeletes a deployment stack what-if resultNN
Microsoft.Resources/deploymentStacksWhatIfResults/whatIf/actionProvides property-level detail for the changes predicted by the deployment stack what-if result.NN
Microsoft.Resources/deploymentStacksWhatIfResults/writeCreates or updates a deployment stack what-if result, which will predict changes to the specified deployment stackNN
Microsoft.Resources/links/deleteDeletes a resource link.NN
Microsoft.Resources/links/writeCreates or updates a resource link.NN
Microsoft.Resources/marketplace/purchase/actionPurchases a resource from the marketplace.NN
Microsoft.Resources/moboBrokers/deleteDeletes a mobo brokerNN
Microsoft.Resources/moboBrokers/writeCreates or updates a mobo brokerNN
Microsoft.Resources/populateRegionalMoveTargetResource/actionPopulate Regional Move Target ResourceNN
Microsoft.Resources/relayRegionalMoveRequest/actionRelay Regional Move RequestNN
Microsoft.Resources/subscriptions/resourceGroups/deleteDeletes a resource group and all its resources.YY
Microsoft.Resources/subscriptions/resourcegroups/deployments/writeCreates or updates an deployment.NN
Microsoft.Resources/subscriptions/resourceGroups/moveResources/actionMoves resources from one resource group to another.NN
Microsoft.Resources/subscriptions/resourceGroups/validateMoveResources/actionValidate move of resources from one resource group to another.NN
Microsoft.Resources/subscriptions/resourceGroups/writeCreates or updates a resource group.YY
Microsoft.Resources/subscriptions/tagNames/deleteDeletes a subscription tag.NN
Microsoft.Resources/subscriptions/tagNames/tagValues/deleteDeletes a subscription tag value.NN
Microsoft.Resources/subscriptions/tagNames/tagValues/writeAdds a subscription tag value.NN
Microsoft.Resources/subscriptions/tagNames/writeAdds a subscription tag.NN
Microsoft.Resources/tags/deleteRemoves all the tags on a resource.NN
Microsoft.Resources/tags/writeUpdates the tags on a resource by replacing or merging existing tags with a new set of tags, or removing existing tags.NN
Microsoft.Resources/templateSpecs/deleteDeletes a template specYN
Microsoft.Resources/templateSpecs/versions/deleteDeletes a template spec versionNN
Microsoft.Resources/templateSpecs/versions/writeCreates or updates a template spec versionNN
Microsoft.Resources/templateSpecs/writeCreates or updates a template specYN

any: Azure Resource Manager (catch-all)

#
Namespace
Microsoft.Resources

Description

Catch-all for Azure-Microsoft.Resources rules that match the resource provider but no specific operation.

References #

Microsoft.Resources/calculateTemplateHash/action

#
Namespace
Microsoft.Resources

Description

Calculate the hash of provided template.

References #

Microsoft.Resources/checkResourceName/action

#
Namespace
Microsoft.Resources

Description

Check the resource name for validity.

References #

Microsoft.Resources/checkZonePeers/action

#
Namespace
Microsoft.Resources

Description

Check Zone Peers

References #

Microsoft.Resources/dataBoundaries/write

#
Namespace
Microsoft.Resources

Description

Opt-in to Data Boundary

References #

Microsoft.Resources/deployments/cancel/action

#
Namespace
Microsoft.Resources

Description

Cancels a deployment.

References #

Microsoft.Resources/deployments/delete

#
Namespace
Microsoft.Resources

Description

Deletes a deployment.

References #

Microsoft.Resources/deployments/exportTemplate/action

#
Namespace
Microsoft.Resources

Description

Export template for a deployment

References #

Microsoft.Resources/deployments/operationstatuses/read

#
Namespace
Microsoft.Resources

Description

Gets or lists deployment operation statuses.

References #

Microsoft.Resources/deployments/validate/action

#
Namespace
Microsoft.Resources

Description

Validates a deployment.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "action": "Microsoft.Resources/deployments/validate/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "action": "Microsoft.Resources/deployments/validate/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "e376a701-e2c0-42b5-88d8-08f5ab6eadc0",
  "EventDataId": "616073e7-cfb7-28c0-7274-2341b6daa048",
  "EventSubmissionTimestamp": "2026-06-29T19:03:25.7433608Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.RESOURCES/DEPLOYMENTS/VALIDATE/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "message": "Microsoft.Resources/deployments/validate/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "616073e7-cfb7-28c0-7274-2341b6daa048",
    "eventSubmissionTimestamp": "2026-06-29T19:03:25.7433608Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcdeploy3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "message": "Microsoft.Resources/deployments/validate/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "616073e7-cfb7-28c0-7274-2341b6daa048",
    "eventSubmissionTimestamp": "2026-06-29T19:03:25.7433608Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcdeploy3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.RESOURCES",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:03:25.7433608Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.resources/deployments/zcdeploy3"
}

References #

Microsoft.Resources/deployments/whatIf/action

#
Namespace
Microsoft.Resources

Description

Predicts template deployment changes.

References #

Microsoft.Resources/deployments/write

#
Namespace
Microsoft.Resources

Description

Creates or updates an deployment.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "action": "Microsoft.Resources/deployments/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "action": "Microsoft.Resources/deployments/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "3063388a-5c40-4da9-8fb6-6c1dabc4edf9",
  "EventDataId": "44701c29-2e40-2d60-efbd-28ee6caf0ac7",
  "EventSubmissionTimestamp": "2026-06-29T19:03:26.3230097Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.RESOURCES/DEPLOYMENTS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "message": "Microsoft.Resources/deployments/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "44701c29-2e40-2d60-efbd-28ee6caf0ac7",
    "eventSubmissionTimestamp": "2026-06-29T19:03:26.3230097Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcdeploy3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/zcdeploy3",
    "message": "Microsoft.Resources/deployments/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "44701c29-2e40-2d60-efbd-28ee6caf0ac7",
    "eventSubmissionTimestamp": "2026-06-29T19:03:26.3230097Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcdeploy3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.RESOURCES",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:03:26.3230097Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.resources/deployments/zcdeploy3"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure_ad::operation_name_value (kusto rule field)inmicrosoft.compute/virtualmachines/write4 ruleskusto
azure_ad::operation_name_value (kusto rule field)inmicrosoft.resources/deployments/write4 ruleskusto
ActivityStatusValue (kusto rule field)starts_withAccept2 ruleskusto
Properties (kusto rule field)containsvmsize2 ruleskusto
vmSize (kusto rule field)cross_field_comparetoken2 ruleskusto
anomalies (kusto rule field)gt01 rulekusto
baseline (kusto rule field)gt01 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Microsoft.Resources/deploymentScripts/delete

#
Namespace
Microsoft.Resources

Description

Deletes a deployment script

References #

Microsoft.Resources/deploymentScripts/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a deployment script

References #

Microsoft.Resources/deploymentStacks/delete

#
Namespace
Microsoft.Resources

Description

Deletes a deployment stack

References #

Microsoft.Resources/deploymentStacks/exportTemplate/action

#
Namespace
Microsoft.Resources

Description

Export the template for a deployment stack

References #

Microsoft.Resources/deploymentStacks/manageDenySetting/action

#
Namespace
Microsoft.Resources

Description

Manage the denySettings property of a deployment stack.

References #

Microsoft.Resources/deploymentStacks/validate/action

#
Namespace
Microsoft.Resources

Description

Validates a deployment stack.

References #

Microsoft.Resources/deploymentStacks/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a deployment stack

References #

Microsoft.Resources/deploymentStacksWhatIfResults/delete

#
Namespace
Microsoft.Resources

Description

Deletes a deployment stack what-if result

References #

Microsoft.Resources/deploymentStacksWhatIfResults/whatIf/action

#
Namespace
Microsoft.Resources

Description

Provides property-level detail for the changes predicted by the deployment stack what-if result.

References #

Microsoft.Resources/deploymentStacksWhatIfResults/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a deployment stack what-if result, which will predict changes to the specified deployment stack

References #

Microsoft.Resources/links/delete

#
Namespace
Microsoft.Resources

Microsoft.Resources/links/write

#
Namespace
Microsoft.Resources

Microsoft.Resources/marketplace/purchase/action

#
Namespace
Microsoft.Resources

Description

Purchases a resource from the marketplace.

References #

Microsoft.Resources/moboBrokers/delete

#
Namespace
Microsoft.Resources

Description

Deletes a mobo broker

References #

Microsoft.Resources/moboBrokers/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a mobo broker

References #

Microsoft.Resources/populateRegionalMoveTargetResource/action

#
Namespace
Microsoft.Resources

Description

Populate Regional Move Target Resource

References #

Microsoft.Resources/relayRegionalMoveRequest/action

#
Namespace
Microsoft.Resources

Description

Relay Regional Move Request

References #

Microsoft.Resources/subscriptions/resourceGroups/delete

#
Namespace
Microsoft.Resources

Description

Deletes a resource group and all its resources.

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "84fcb0a6-91db-4f09-a74e-97d1d41f2c6f",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
    "action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
    "action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "OperationNameValue": "MICROSOFT.RESOURCES/SUBSCRIPTIONS/RESOURCEGROUPS/DELETE",
  "Properties": {
    "statusCode": "Accepted",
    "serviceRequestId": null,
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
    "message": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "a16b075b-6bc3-4b66-8745-6b7a36adb050",
    "eventSubmissionTimestamp": "2021-04-28T14:43:48.5341324Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resourceGroup": "EY_DEMO",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Properties_d": {
    "statusCode": "Accepted",
    "serviceRequestId": null,
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/EY_Demo",
    "message": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "a16b075b-6bc3-4b66-8745-6b7a36adb050",
    "eventSubmissionTimestamp": "2021-04-28T14:43:48.5341324Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resourceGroup": "EY_DEMO",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "a16b075b-6bc3-4b66-8745-6b7a36adb050",
  "EventSubmissionTimestamp": "4/28/2021, 2:43:48.534 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "EY_DEMO",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatusValue": "Accepted",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:43:48.534 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

  • Azure Resource Group Deleted source medium: Detects when an Azure Resource Group is deleted. Resource group deletion removes all resources within the group and may indicate mass destruction or legitimate cleanup.T1485

References #

Microsoft.Resources/subscriptions/resourcegroups/deployments/write

#
Namespace
Microsoft.Resources

Description

Creates or updates an deployment.

References #

Microsoft.Resources/subscriptions/resourceGroups/moveResources/action

#
Namespace
Microsoft.Resources

Description

Moves resources from one resource group to another.

References #

Microsoft.Resources/subscriptions/resourceGroups/validateMoveResources/action

#
Namespace
Microsoft.Resources

Description

Validate move of resources from one resource group to another.

References #

Microsoft.Resources/subscriptions/resourceGroups/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a resource group.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
    "action": "Microsoft.Resources/subscriptions/resourcegroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
    "action": "Microsoft.Resources/subscriptions/resourcegroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783008141",
    "nbf": "1783008141",
    "exp": "1783012267",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "joig862JV0W_vEH8aP97AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 8",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783008141",
    "nbf": "1783008141",
    "exp": "1783012267",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "joig862JV0W_vEH8aP97AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 8",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "c6a1ce19-3429-4043-9811-4e99eaafa16e",
  "EventDataId": "8b7e0725-0aba-dfce-dd5d-3795571a99f0",
  "EventSubmissionTimestamp": "2026-07-02T16:41:07.7012536Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.RESOURCES/SUBSCRIPTIONS/RESOURCEGROUPS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "responseBody": {
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen",
      "name": "rg-logcapture-gen",
      "type": "Microsoft.Resources/resourceGroups",
      "location": "westus2",
      "tags": {
        "dwharn": "7000408c",
        "purpose": "capture"
      },
      "properties": {
        "provisioningState": "Succeeded"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
    "message": "Microsoft.Resources/subscriptions/resourcegroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8b7e0725-0aba-dfce-dd5d-3795571a99f0",
    "eventSubmissionTimestamp": "2026-07-02T16:41:07.7012536Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceGroup": "rg-logcapture-gen",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "responseBody": {
      "id": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen",
      "name": "rg-logcapture-gen",
      "type": "Microsoft.Resources/resourceGroups",
      "location": "westus2",
      "tags": {
        "dwharn": "7000408c",
        "purpose": "capture"
      },
      "properties": {
        "provisioningState": "Succeeded"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen",
    "message": "Microsoft.Resources/subscriptions/resourcegroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8b7e0725-0aba-dfce-dd5d-3795571a99f0",
    "eventSubmissionTimestamp": "2026-07-02T16:41:07.7012536Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceGroup": "rg-logcapture-gen",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure_ad::operation_name_value (kusto rule field)inmicrosoft.compute/virtualmachines/write1 rulekusto
azure_ad::operation_name_value (kusto rule field)inmicrosoft.resources/deployments/write1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Microsoft.Resources/subscriptions/tagNames/delete

#
Namespace
Microsoft.Resources

Description

Deletes a subscription tag.

References #

Microsoft.Resources/subscriptions/tagNames/tagValues/delete

#
Namespace
Microsoft.Resources

Description

Deletes a subscription tag value.

References #

Microsoft.Resources/subscriptions/tagNames/tagValues/write

#
Namespace
Microsoft.Resources

Description

Adds a subscription tag value.

References #

Microsoft.Resources/subscriptions/tagNames/write

#
Namespace
Microsoft.Resources

Description

Adds a subscription tag.

References #

Microsoft.Resources/tags/delete

#
Namespace
Microsoft.Resources

Description

Removes all the tags on a resource.

References #

Microsoft.Resources/tags/write

#
Namespace
Microsoft.Resources

Description

Updates the tags on a resource by replacing or merging existing tags with a new set of tags, or removing existing tags.

References #

Microsoft.Resources/templateSpecs/delete

#
Namespace
Microsoft.Resources

Description

Deletes a template spec

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "action": "Microsoft.Resources/templateSpecs/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "action": "Microsoft.Resources/templateSpecs/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "ab35ee1b-36fc-4260-a030-b1930c94689b",
  "EventDataId": "0360c1f5-c990-997d-867e-150f9f8206b2",
  "EventSubmissionTimestamp": "2026-07-02T18:29:08.5643434Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.RESOURCES/TEMPLATESPECS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "message": "Microsoft.Resources/templateSpecs/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "0360c1f5-c990-997d-867e-150f9f8206b2",
    "eventSubmissionTimestamp": "2026-07-02T18:29:08.5643434Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftemplatespecs",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "message": "Microsoft.Resources/templateSpecs/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "0360c1f5-c990-997d-867e-150f9f8206b2",
    "eventSubmissionTimestamp": "2026-07-02T18:29:08.5643434Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftemplatespecs",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.RESOURCES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Resources/templateSpecs/versions/delete

#
Namespace
Microsoft.Resources

Description

Deletes a template spec version

References #

Microsoft.Resources/templateSpecs/versions/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a template spec version

References #

Microsoft.Resources/templateSpecs/write

#
Namespace
Microsoft.Resources

Description

Creates or updates a template spec

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "action": "Microsoft.Resources/templateSpecs/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "action": "Microsoft.Resources/templateSpecs/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "a6142e4c-c1b4-4e05-9c4e-c003a162fe44",
  "EventDataId": "7da56b06-f5ec-8273-ac7a-42b60b818691",
  "EventSubmissionTimestamp": "2026-07-02T18:28:36.4218368Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.RESOURCES/TEMPLATESPECS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "message": "Microsoft.Resources/templateSpecs/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7da56b06-f5ec-8273-ac7a-42b60b818691",
    "eventSubmissionTimestamp": "2026-07-02T18:28:36.4218368Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftemplatespecs",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Resources/templateSpecs/dwh2220aftemplatespecs",
    "message": "Microsoft.Resources/templateSpecs/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "7da56b06-f5ec-8273-ac7a-42b60b818691",
    "eventSubmissionTimestamp": "2026-07-02T18:28:36.4218368Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220aftemplatespecs",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.RESOURCES",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.RESOURCES",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #