Microsoft Defender for Cloud Azure-Microsoft.Security
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.Security rules that match the resource provider but no specific operation. | N | N |
| Microsoft.Security/ | Enforces the given traffic hardening rules by creating matching security rules on the given Network Security Group(s) | N | N |
| Microsoft.Security/ | Updates the Advanced Threat Protection Settings for the resource | N | N |
| Microsoft.Security/ | Gets aggregations | N | N |
| Microsoft.Security/ | Delete a security alert suppression rule | N | N |
| Microsoft.Security/ | Creates a new security alert suppression rule or update an existing rule | N | Y |
| Microsoft.Security/ | Delete Api Collections | N | N |
| Microsoft.Security/ | Create Api Collections | N | N |
| Microsoft.Security/ | Creates a new application allowlisting or updates an existing one | N | N |
| Microsoft.Security/ | Create or update a security assessment metadata | N | N |
| Microsoft.Security/ | Create or update governance assignments for security assessments | N | N |
| Microsoft.Security/ | Create or update security sub assessments on your subscription | N | N |
| Microsoft.Security/ | Create or update security assessments on your subscription | N | N |
| Microsoft.Security/ | Deletes the security assignment | N | N |
| Microsoft.Security/ | Create or update the security assignment | N | N |
| Microsoft.Security/ | Deletes the automation for the scope | N | N |
| Microsoft.Security/ | Validates the automation model for the scope | N | N |
| Microsoft.Security/ | Creates or updates the automation for the scope | N | N |
| Microsoft.Security/ | Microsoft Defender for Cloud auto-provisioning setting write, recorded in the activity log when the automatic provisioning of the monitoring agent is configured. Defense-evasion-relevant: turning auto-provisioning off stops new resources from being onboarded to Defender monitoring. Captured in first-party AzureActivity telemetry; the ARM providerOperations registry does not enumerate it. | Y | N |
| Microsoft.Security/ | Deletes the custom recommendation | N | N |
| Microsoft.Security/ | Create or update the custom recommendation | N | N |
| Microsoft.Security/ | Deletes the datascanners for the scope | N | N |
| Microsoft.Security/ | Creates or updates the datascanners for the scope | N | N |
| Microsoft.Security/ | Deletes the defenderforstoragesettings for the scope | N | N |
| Microsoft.Security/ | Creates or updates the defenderforstoragesettings for the scope | N | N |
| Microsoft.Security/ | Deletes IoT device security groups | N | N |
| Microsoft.Security/ | Creates or updates IoT device security groups | N | N |
| Microsoft.Security/ | Create or update governance rules for managing security posture | N | N |
| Microsoft.Security/ | Updates the information protection policies for the resource | N | N |
| Microsoft.Security/ | Deleate or update integration on your scope | N | N |
| Microsoft.Security/ | Create or update integration on your scope | N | N |
| Microsoft.Security/ | Deletes IoT Defender Settings | N | N |
| Microsoft.Security/ | Download manager activation file with subscription quota data | N | N |
| Microsoft.Security/ | Gets downloadable IoT Defender packages information | N | N |
| Microsoft.Security/ | Create or updates IoT Defender Settings | N | N |
| Microsoft.Security/ | Dismisses IoT aggregated alerts | N | N |
| Microsoft.Security/ | Deletes IoT security solutions | N | N |
| Microsoft.Security/ | Creates or updates IoT security solutions | N | N |
| Microsoft.Security/ | Deletes IoT Sensors | N | N |
| Microsoft.Security/ | Downloads activation file for IoT Sensors | N | N |
| Microsoft.Security/ | Downloads reset password file for IoT Sensors | N | N |
| Microsoft.Security/ | Triggers threat intelligence package update | N | N |
| Microsoft.Security/ | Create or updates IoT Sensors | N | N |
| Microsoft.Security/ | Deletes IoT site | N | N |
| Microsoft.Security/ | Creates or updates IoT site | N | N |
| Microsoft.Security/ | Activate a security alert | N | N |
| Microsoft.Security/ | Dismiss a security alert | N | N |
| Microsoft.Security/ | Resolve a security alert | N | N |
| Microsoft.Security/ | Simulate a security alert | N | N |
| Microsoft.Security/ | Deletes the just-in-time network access policy | N | N |
| Microsoft.Security/ | Initiates a just-in-time network access policy request | N | N |
| Microsoft.Security/ | Creates a new just-in-time network access policy or updates an existing one | N | N |
| Microsoft.Security/ | Deletes a security solution | N | N |
| Microsoft.Security/ | Creates a new security solution or updates an existing one | N | N |
| Microsoft.Security/ | Activate a security recommendation | N | N |
| Microsoft.Security/ | Dismiss a security recommendation | N | N |
| Microsoft.Security/ | Resolve a security recommendation | N | N |
| Microsoft.Security/ | Start a security recommendation | N | N |
| Microsoft.Security/ | Updates the security policy | N | N |
| Microsoft.Security/ | Updates batch of pricing settings for the scope | N | N |
| Microsoft.Security/ | Deletes the pricing settings for the scope | N | N |
| Microsoft.Security/ | Deletes the security operators for the scope | N | N |
| Microsoft.Security/ | Updates the security operators for the scope | N | N |
| Microsoft.Security/ | Updates the pricing settings for the scope | N | N |
| Microsoft.Security/ | Deletes a Microsoft Security Private Link. | N | N |
| Microsoft.Security/ | Deletes a Microsoft Security Private Endpoint Connection Proxy (NRP only). | N | N |
| Microsoft.Security/ | Updates the properties of the Microsoft Security Private Endpoint Connection Proxy (NRP only). | N | N |
| Microsoft.Security/ | Validates a Microsoft Security Private Endpoint Connection Proxy object before creation (NRP only). | N | N |
| Microsoft.Security/ | Creates or updates a Microsoft Security Private Endpoint Connection Proxy (NRP only). | N | N |
| Microsoft.Security/ | Deletes a Microsoft Security Private Endpoint Connection. | N | N |
| Microsoft.Security/ | Approves or rejects a Microsoft Security Private Endpoint Connection. | N | N |
| Microsoft.Security/ | Creates or updates a Microsoft Security Private Link. | N | N |
| Microsoft.Security/ | Registers the subscription for Azure Security Center | N | N |
| Microsoft.Security/ | Deletes the security connector | N | N |
| Microsoft.Security/ | Creates or updates a monitored Azure DevOps repository resource. | N | N |
| Microsoft.Security/ | Creates or updates a monitored Azure DevOps project resource. | N | N |
| Microsoft.Security/ | Creates or updates monitored Azure DevOps organization details. | N | N |
| Microsoft.Security/ | Deletes a DevOps Connector. | N | N |
| Microsoft.Security/ | Creates a GitHub issue for the specified repository and assessment. | N | N |
| Microsoft.Security/ | Gets nested subgroups of given GitLab Group which are onboarded to the connector. | N | N |
| Microsoft.Security/ | Returns a list of all Azure DevOps organizations accessible by the user token consumed by the connector. | N | N |
| Microsoft.Security/ | Returns a list of all GitHub owners accessible by the user token consumed by the connector. | N | N |
| Microsoft.Security/ | Returns a list of all GitLab groups accessible by the user token consumed by the connector. | N | N |
| Microsoft.Security/ | Creates or updates a DevOps Configuration. | N | N |
| Microsoft.Security/ | Updates the security connector | N | N |
| Microsoft.Security/ | Deletes the security contact | N | N |
| Microsoft.Security/ | Updates the security contact | N | N |
| Microsoft.Security/ | Deletes the securityoperators for the scope | N | N |
| Microsoft.Security/ | Creates or updates the securityoperators for the scope | N | N |
| Microsoft.Security/ | Deletes a security solution | N | N |
| Microsoft.Security/ | Creates a new security solution or updates an existing one | N | N |
| Microsoft.Security/ | Deletes the security standard | N | N |
| Microsoft.Security/ | Create or update the security standard | N | N |
| Microsoft.Security/ | Updates tenant level sensitivity settings | N | N |
| Microsoft.Security/ | Remove a server vulnerability assessments solution from a resource | N | N |
| Microsoft.Security/ | Create or update a server vulnerability assessments solution on resource | N | N |
| Microsoft.Security/ | Remove server vulnerability assessments settings from a given subscription | N | N |
| Microsoft.Security/ | Create or update server vulnerability assessments settings on a given subscription | N | N |
| Microsoft.Security/ | Updates the settings for the scope | N | N |
| Microsoft.Security/ | Add a list of rules result to the baseline. | N | N |
| Microsoft.Security/ | Remove the rule result from the baseline. | N | N |
| Microsoft.Security/ | Change the rule baseline result. | N | N |
| Microsoft.Security/ | Delete SQL Vulnerability Assessment settings. | N | N |
| Microsoft.Security/ | Create or update SQL Vulnerability Assessment settings. | N | N |
| Microsoft.Security/ | Deletes the standard assignment | N | N |
| Microsoft.Security/ | Create or update the standard assignment | N | N |
| Microsoft.Security/ | Deletes the security standard | N | N |
| Microsoft.Security/ | Create or update the security standard | N | N |
| Microsoft.Security/ | Unregisters the subscription from Azure Security Center | N | N |
| Microsoft.Security/ | Deletes a web application firewall | N | N |
| Microsoft.Security/ | Creates a new web application firewall or updates an existing one | N | N |
| Microsoft.Security/ | Change workspace settings reconnection settings | N | N |
| Microsoft.Security/ | Deletes the workspace settings | N | N |
| Microsoft.Security/ | Updates the workspace settings | N | N |
any: Microsoft Defender for Cloud (catch-all)
#Description
Catch-all for Azure-Microsoft.Security rules that match the resource provider but no specific operation.
Microsoft.Security/adaptiveNetworkHardenings/enforce/action
#Description
Enforces the given traffic hardening rules by creating matching security rules on the given Network Security Group(s)
Microsoft.Security/advancedThreatProtectionSettings/write
#Description
Updates the Advanced Threat Protection Settings for the resource
Microsoft.Security/aggregations/action
#Description
Gets aggregations
Microsoft.Security/alertsSuppressionRules/delete
#Description
Delete a security alert suppression rule
Microsoft.Security/alertsSuppressionRules/write
#Description
Creates a new security alert suppression rule or update an existing rule
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 1 rule | panther |
resultType (panther rule field) | in | Success | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1562, T1562.001Panther #
T1562
Microsoft.Security/apiCollections/delete
#Description
Delete Api Collections
Microsoft.Security/apiCollections/write
#Description
Create Api Collections
Microsoft.Security/applicationWhitelistings/write
#Description
Creates a new application allowlisting or updates an existing one
Microsoft.Security/assessmentMetadata/write
#Description
Create or update a security assessment metadata
Microsoft.Security/assessments/governanceAssignments/write
#Description
Create or update governance assignments for security assessments
Microsoft.Security/assessments/subAssessments/write
#Description
Create or update security sub assessments on your subscription
Microsoft.Security/assessments/write
#Description
Create or update security assessments on your subscription
Microsoft.Security/assignments/delete
#Description
Deletes the security assignment
Microsoft.Security/assignments/write
#Description
Create or update the security assignment
Microsoft.Security/automations/delete
#Description
Deletes the automation for the scope
Microsoft.Security/automations/validate/action
#Description
Validates the automation model for the scope
Microsoft.Security/automations/write
#Description
Creates or updates the automation for the scope
Microsoft.Security/autoProvisioningSettings/write
#Description
Microsoft Defender for Cloud auto-provisioning setting write, recorded in the activity log when the automatic provisioning of the monitoring agent is configured. Defense-evasion-relevant: turning auto-provisioning off stops new resources from being onboarded to Defender monitoring. Captured in first-party AzureActivity telemetry; the ARM providerOperations registry does not enumerate it.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Security/autoProvisioningSettings/default",
"action": "Microsoft.Security/autoProvisioningSettings/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Security/autoProvisioningSettings/default",
"action": "Microsoft.Security/autoProvisioningSettings/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783177024",
"nbf": "1783177024",
"exp": "1783192084",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "I73cB--4LUynbk58Lw4JAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
"xms_idrel": "6 1",
"xms_sub_fct": "3 14",
"xms_tcdt": "1768616282",
"correlationid": "f21875c2-5497-47ed-9025-96927b445a2d"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783177024",
"nbf": "1783177024",
"exp": "1783192084",
"aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "I73cB--4LUynbk58Lw4JAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
"xms_idrel": "6 1",
"xms_sub_fct": "3 14",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"correlationid": "f21875c2-5497-47ed-9025-96927b445a2d"
},
"CorrelationId": "f21875c2-5497-47ed-9025-96927b445a2d",
"EventDataId": "a71c3c98-d314-8c96-66eb-56ade8011247",
"EventSubmissionTimestamp": "2026-07-04T15:08:04.1210226Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.SECURITY/AUTOPROVISIONINGSETTINGS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Security/autoProvisioningSettings/default",
"message": "Microsoft.Security/autoProvisioningSettings/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "a71c3c98-d314-8c96-66eb-56ade8011247",
"eventSubmissionTimestamp": "2026-07-04T15:08:04.1210226Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "default",
"resourceProviderValue": "MICROSOFT.SECURITY",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Security/autoProvisioningSettings/default",
"message": "Microsoft.Security/autoProvisioningSettings/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "a71c3c98-d314-8c96-66eb-56ade8011247",
"eventSubmissionTimestamp": "2026-07-04T15:08:04.1210226Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "default",
"resourceProviderValue": "MICROSOFT.SECURITY",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"ResourceProviderValue": "MICROSOFT.SECURITY",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Security/customRecommendations/delete
#Description
Deletes the custom recommendation
Microsoft.Security/customRecommendations/write
#Description
Create or update the custom recommendation
Microsoft.Security/datascanners/delete
#Description
Deletes the datascanners for the scope
Microsoft.Security/datascanners/write
#Description
Creates or updates the datascanners for the scope
Microsoft.Security/defenderforstoragesettings/delete
#Description
Deletes the defenderforstoragesettings for the scope
Microsoft.Security/defenderforstoragesettings/write
#Description
Creates or updates the defenderforstoragesettings for the scope
Microsoft.Security/deviceSecurityGroups/delete
#Description
Deletes IoT device security groups
Microsoft.Security/deviceSecurityGroups/write
#Description
Creates or updates IoT device security groups
Microsoft.Security/governanceRules/write
#Description
Create or update governance rules for managing security posture
Microsoft.Security/informationProtectionPolicies/write
#Description
Updates the information protection policies for the resource
Microsoft.Security/integration/delete
#Description
Deleate or update integration on your scope
Microsoft.Security/integration/write
#Description
Create or update integration on your scope
Microsoft.Security/iotDefenderSettings/delete
#Description
Deletes IoT Defender Settings
Microsoft.Security/iotDefenderSettings/DownloadManagerActivation/action
#Description
Download manager activation file with subscription quota data
Microsoft.Security/iotDefenderSettings/PackageDownloads/action
#Description
Gets downloadable IoT Defender packages information
Microsoft.Security/iotDefenderSettings/write
#Description
Create or updates IoT Defender Settings
Microsoft.Security/iotSecuritySolutions/analyticsModels/aggregatedAlerts/dismiss/action
#Description
Dismisses IoT aggregated alerts
Microsoft.Security/iotSecuritySolutions/delete
#Description
Deletes IoT security solutions
Microsoft.Security/iotSecuritySolutions/write
#Description
Creates or updates IoT security solutions
Microsoft.Security/iotSensors/delete
#Description
Deletes IoT Sensors
Microsoft.Security/iotSensors/DownloadActivation/action
#Description
Downloads activation file for IoT Sensors
Microsoft.Security/iotSensors/DownloadResetPassword/action
#Description
Downloads reset password file for IoT Sensors
Microsoft.Security/iotSensors/TriggerTiPackageUpdate/action
#Description
Triggers threat intelligence package update
Microsoft.Security/iotSensors/write
#Description
Create or updates IoT Sensors
Microsoft.Security/iotSite/delete
#Description
Deletes IoT site
Microsoft.Security/iotSite/write
#Description
Creates or updates IoT site
Microsoft.Security/locations/alerts/activate/action
#Description
Activate a security alert
Microsoft.Security/locations/alerts/dismiss/action
#Description
Dismiss a security alert
Microsoft.Security/locations/alerts/resolve/action
#Description
Resolve a security alert
Microsoft.Security/locations/alerts/simulate/action
#Description
Simulate a security alert
Microsoft.Security/locations/jitNetworkAccessPolicies/delete
#Description
Deletes the just-in-time network access policy
Microsoft.Security/locations/jitNetworkAccessPolicies/initiate/action
#Description
Initiates a just-in-time network access policy request
Microsoft.Security/locations/jitNetworkAccessPolicies/write
#Description
Creates a new just-in-time network access policy or updates an existing one
Microsoft.Security/locations/securitySolutions/delete
#Description
Deletes a security solution
Microsoft.Security/locations/securitySolutions/write
#Description
Creates a new security solution or updates an existing one
Microsoft.Security/locations/tasks/activate/action
#Description
Activate a security recommendation
Microsoft.Security/locations/tasks/dismiss/action
#Description
Dismiss a security recommendation
Microsoft.Security/locations/tasks/resolve/action
#Description
Resolve a security recommendation
Microsoft.Security/locations/tasks/start/action
#Description
Start a security recommendation
Microsoft.Security/policies/write
#Description
Updates the security policy
Microsoft.Security/pricings/action
#Description
Updates batch of pricing settings for the scope
Microsoft.Security/pricings/delete
#Description
Deletes the pricing settings for the scope
Microsoft.Security/pricings/securityoperators/delete
#Description
Deletes the security operators for the scope
Microsoft.Security/pricings/securityoperators/write
#Description
Updates the security operators for the scope
Microsoft.Security/pricings/write
#Description
Updates the pricing settings for the scope
Microsoft.Security/privateLinks/delete
#Description
Deletes a Microsoft Security Private Link.
Microsoft.Security/privateLinks/privateEndpointConnectionProxies/delete
#Description
Deletes a Microsoft Security Private Endpoint Connection Proxy (NRP only).
Microsoft.Security/privateLinks/privateEndpointConnectionProxies/updatePrivateEndpointProperties/action
#Description
Updates the properties of the Microsoft Security Private Endpoint Connection Proxy (NRP only).
Microsoft.Security/privateLinks/privateEndpointConnectionProxies/validate/action
#Description
Validates a Microsoft Security Private Endpoint Connection Proxy object before creation (NRP only).
Microsoft.Security/privateLinks/privateEndpointConnectionProxies/write
#Description
Creates or updates a Microsoft Security Private Endpoint Connection Proxy (NRP only).
Microsoft.Security/privateLinks/privateEndpointConnections/delete
#Description
Deletes a Microsoft Security Private Endpoint Connection.
Microsoft.Security/privateLinks/privateEndpointConnections/write
#Description
Approves or rejects a Microsoft Security Private Endpoint Connection.
Microsoft.Security/privateLinks/write
#Description
Creates or updates a Microsoft Security Private Link.
Microsoft.Security/register/action
#Description
Registers the subscription for Azure Security Center
Microsoft.Security/securityConnectors/delete
#Description
Deletes the security connector
Microsoft.Security/securityConnectors/devops/azureDevOpsOrgs/projects/repos/write
#Description
Creates or updates a monitored Azure DevOps repository resource.
Microsoft.Security/securityConnectors/devops/azureDevOpsOrgs/projects/write
#Description
Creates or updates a monitored Azure DevOps project resource.
Microsoft.Security/securityConnectors/devops/azureDevOpsOrgs/write
#Description
Creates or updates monitored Azure DevOps organization details.
Microsoft.Security/securityConnectors/devops/delete
#Description
Deletes a DevOps Connector.
Microsoft.Security/securityConnectors/devops/gitHubOwners/repos/issues/action
#Description
Creates a GitHub issue for the specified repository and assessment.
Microsoft.Security/securityConnectors/devops/gitLabGroups/listSubgroups/action
#Description
Gets nested subgroups of given GitLab Group which are onboarded to the connector.
Microsoft.Security/securityConnectors/devops/listAvailableAzureDevOpsOrgs/action
#Description
Returns a list of all Azure DevOps organizations accessible by the user token consumed by the connector.
Microsoft.Security/securityConnectors/devops/listAvailableGitHubOwners/action
#Description
Returns a list of all GitHub owners accessible by the user token consumed by the connector.
Microsoft.Security/securityConnectors/devops/listAvailableGitLabGroups/action
#Description
Returns a list of all GitLab groups accessible by the user token consumed by the connector.
Microsoft.Security/securityConnectors/devops/write
#Description
Creates or updates a DevOps Configuration.
Microsoft.Security/securityConnectors/write
#Description
Updates the security connector
Microsoft.Security/securityContacts/delete
#Description
Deletes the security contact
Microsoft.Security/securityContacts/write
#Description
Updates the security contact
Microsoft.Security/securityoperators/delete
#Description
Deletes the securityoperators for the scope
Microsoft.Security/securityoperators/write
#Description
Creates or updates the securityoperators for the scope
Microsoft.Security/securitySolutions/delete
#Description
Deletes a security solution
Microsoft.Security/securitySolutions/write
#Description
Creates a new security solution or updates an existing one
Microsoft.Security/securityStandards/delete
#Description
Deletes the security standard
Microsoft.Security/securityStandards/write
#Description
Create or update the security standard
Microsoft.Security/sensitivitySettings/write
#Description
Updates tenant level sensitivity settings
Microsoft.Security/serverVulnerabilityAssessments/delete
#Description
Remove a server vulnerability assessments solution from a resource
Microsoft.Security/serverVulnerabilityAssessments/write
#Description
Create or update a server vulnerability assessments solution on resource
Microsoft.Security/serverVulnerabilityAssessmentsSettings/delete
#Description
Remove server vulnerability assessments settings from a given subscription
Microsoft.Security/serverVulnerabilityAssessmentsSettings/write
#Description
Create or update server vulnerability assessments settings on a given subscription
Microsoft.Security/settings/write
#Description
Updates the settings for the scope
Microsoft.Security/sqlVulnerabilityAssessments/baselineRules/action
#Description
Add a list of rules result to the baseline.
Microsoft.Security/sqlVulnerabilityAssessments/baselineRules/delete
#Description
Remove the rule result from the baseline.
Microsoft.Security/sqlVulnerabilityAssessments/baselineRules/write
#Description
Change the rule baseline result.
Microsoft.Security/sqlVulnerabilityAssessments/delete
#Description
Delete SQL Vulnerability Assessment settings.
Microsoft.Security/sqlVulnerabilityAssessments/write
#Description
Create or update SQL Vulnerability Assessment settings.
Microsoft.Security/standardAssignments/delete
#Description
Deletes the standard assignment
Microsoft.Security/standardAssignments/write
#Description
Create or update the standard assignment
Microsoft.Security/standards/delete
#Description
Deletes the security standard
Microsoft.Security/standards/write
#Description
Create or update the security standard
Microsoft.Security/unregister/action
#Description
Unregisters the subscription from Azure Security Center
Microsoft.Security/webApplicationFirewalls/delete
#Description
Deletes a web application firewall
Microsoft.Security/webApplicationFirewalls/write
#Description
Creates a new web application firewall or updates an existing one
Microsoft.Security/workspaceSettings/connect/action
#Description
Change workspace settings reconnection settings
Microsoft.Security/workspaceSettings/delete
#Description
Deletes the workspace settings
Microsoft.Security/workspaceSettings/write
#Description
Updates the workspace settings