Azure SQL Azure-Microsoft.Sql
any: Azure SQL (catch-all)
#Description
Catch-all for Azure-Microsoft.Sql rules that match the resource provider but no specific operation.
Microsoft.Sql/checkNameAvailability/action
#Description
Verify whether given server name is available for provisioning worldwide for a given subscription.
Microsoft.Sql/instancePools/delete
#Description
Deletes an instance pool
Microsoft.Sql/instancePools/write
#Description
Creates or updates an instance pool
Microsoft.Sql/locations/deletedServers/recover/action
#Description
Recover a deleted server
Microsoft.Sql/locations/deleteVirtualNetworkOrSubnets/action
#Description
Deletes Virtual network rules associated to a virtual network or subnet
Microsoft.Sql/locations/instanceFailoverGroups/delete
#Description
Deletes an existing instance failover group.
Microsoft.Sql/locations/instanceFailoverGroups/failover/action
#Description
Executes planned failover in an existing instance failover group.
Microsoft.Sql/locations/instanceFailoverGroups/forceFailoverAllowDataLoss/action
#Description
Executes forced failover in an existing instance failover group.
Microsoft.Sql/locations/instanceFailoverGroups/write
#Description
Creates an instance failover group with the specified parameters or updates the properties or tags for the specified instance failover group.
Microsoft.Sql/locations/longTermRetentionManagedInstances/longTermRetentionDatabases/longTermRetentionManagedInstanceBackups/delete
#Description
Deletes an LTR backup for a managed instance database
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/changeAccessTier/action
#Description
Change long term retention backup access tier operation.
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/copy/action
#Description
Copy a long term retention backup
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/delete
#Description
Deletes a long term retention backup
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/lockTimeBasedImmutability/action
#Description
Lock time based immutability of an existing long term retention backup.
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/removeLegalHoldImmutability/action
#Description
Remove legal hold immutability of an existing long term retention backup.
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/removeTimeBasedImmutability/action
#Description
Remove time based immutability of an existing long term retention backup.
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/setLegalHoldImmutability/action
#Description
Set legal hold immutability of an existing long term retention backup.
Microsoft.Sql/locations/longTermRetentionServers/longTermRetentionDatabases/longTermRetentionBackups/update/action
#Description
Update a long term retention backup
Microsoft.Sql/locations/managedDatabaseRestoreAzureAsyncOperation/completeRestore/action
#Description
Completes managed database restore operation
Microsoft.Sql/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action
#Description
Notify of NSP Update
Microsoft.Sql/locations/serverTrustGroups/delete
#Description
Deletes the existing SQL Server Trust Group
Microsoft.Sql/locations/serverTrustGroups/write
#Description
Creates a Server Trust Group with the specified parameters
Microsoft.Sql/managedInstances/administrators/delete
#Description
Deletes an existing administrator of managed instance.
Microsoft.Sql/managedInstances/administrators/write
#Description
Creates or updates managed instance administrator with the specified parameters.
Microsoft.Sql/managedInstances/advancedThreatProtectionSettings/write
#Description
Change the managed instance Advanced Threat Protection settings for a given managed instance
Microsoft.Sql/managedInstances/azureADOnlyAuthentications/delete
#Description
Deletes a specific managed server Azure Active Directory only authentication object
Microsoft.Sql/managedInstances/azureADOnlyAuthentications/write
#Description
Adds or updates a specific managed server Azure Active Directory only authentication object
Microsoft.Sql/managedInstances/crossSubscriptionPITR/action
#Description
Determine if user is allowed to do cross subscription PITR operations
Microsoft.Sql/managedInstances/databases/advancedThreatProtectionSettings/write
#Description
Change the database Advanced Threat Protection settings for a given managed database
Microsoft.Sql/managedInstances/databases/backupLongTermRetentionPolicies/delete
#Description
Updates a long term retention policy for a managed database
Microsoft.Sql/managedInstances/databases/backupLongTermRetentionPolicies/write
#Description
Updates a long term retention policy for a managed database
Microsoft.Sql/managedInstances/databases/backupShortTermRetentionPolicies/write
#Description
Updates a short term retention policy for a managed database
Microsoft.Sql/managedInstances/databases/cancelMove/action
#Description
Cancels Managed Instance database move.
Microsoft.Sql/managedInstances/databases/completeMove/action
#Description
Completes Managed Instance database move.
Microsoft.Sql/managedInstances/databases/completeRestore/action
#Description
Completes managed database restore operation
Microsoft.Sql/managedInstances/databases/currentSensitivityLabels/write
#Description
Batch update sensitivity labels
Microsoft.Sql/managedInstances/databases/delete
#Description
Deletes an existing managed database
Microsoft.Sql/managedInstances/databases/ledgerDigestUploads/disable/action
#Description
Disable uploading ledger digests
Microsoft.Sql/managedInstances/databases/ledgerDigestUploads/write
#Description
Enable uploading ledger digests
Microsoft.Sql/managedInstances/databases/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
Microsoft.Sql/managedInstances/databases/readBackups/action
#Description
Determine if user is allowed to read backups
Microsoft.Sql/managedInstances/databases/recommendedSensitivityLabels/write
#Description
Batch update recommended sensitivity labels
Microsoft.Sql/managedInstances/databases/reevaluateInaccessibleDatabaseState/action
#Description
Reevaluates the inaccessibility state of a managed database.
Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/delete
#Description
Delete the sensitivity label of a given column
Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/disable/action
#Description
Disable sensitivity recommendations on a given column
Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/enable/action
#Description
Enable sensitivity recommendations on a given column
Microsoft.Sql/managedInstances/databases/schemas/tables/columns/sensitivityLabels/write
#Description
Create or update the sensitivity label of a given column
Microsoft.Sql/managedInstances/databases/securityAlertPolicies/write
#Description
Change the database threat detection policy for a given managed database
Microsoft.Sql/managedInstances/databases/startMove/action
#Description
Starts Managed Instance database move.
Microsoft.Sql/managedInstances/databases/transparentDataEncryption/write
#Description
Change the database Transparent Data Encryption for a given managed database
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/delete
#Description
Remove the vulnerability assessment for a given database
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/rules/baselines/delete
#Description
Remove the vulnerability assessment rule baseline for a given database
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/rules/baselines/write
#Description
Change the vulnerability assessment rule baseline for a given database
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/scans/export/action
#Description
Convert an existing scan result to a human readable format. If already exists nothing happens
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/scans/initiateScan/action
#Description
Execute vulnerability assessment database scan.
Microsoft.Sql/managedInstances/databases/vulnerabilityAssessments/write
#Description
Change the vulnerability assessment for a given database
Microsoft.Sql/managedInstances/databases/write
#Description
Creates a new database or updates an existing database.
Microsoft.Sql/managedInstances/delete
#Description
Deletes an existing managed instance.
Microsoft.Sql/managedInstances/distributedAvailabilityGroups/delete
#Description
Deletes a distributed availability group.
Microsoft.Sql/managedInstances/distributedAvailabilityGroups/failover/action
#Description
Performs requested failover type in this distributed availability group.
Microsoft.Sql/managedInstances/distributedAvailabilityGroups/setRole/action
#Description
Set Role for Azure SQL Managed Instance Link to Primary or Secondary.
Microsoft.Sql/managedInstances/distributedAvailabilityGroups/write
#Description
Creates distributed availability groups with a specified parameters.
Microsoft.Sql/managedInstances/dnsAliases/acquire/action
#Description
Acquire Azure SQL Managed Instance Dns Alias from another Managed Instance.
Microsoft.Sql/managedInstances/dnsAliases/delete
#Description
Deletes an existing Azure SQL Managed Instance Dns Alias.
Microsoft.Sql/managedInstances/dnsAliases/write
#Description
Creates an Azure SQL Managed Instance Dns Alias with the specified parameters or updates the properties for the specified Azure SQL Managed Instance Dns Alias.
Microsoft.Sql/managedInstances/dtc/write
#Description
Updates Azure SQL Managed Instance's DTC properties for the specified instance.
Microsoft.Sql/managedInstances/encryptionProtector/revalidate/action
#Description
Update the properties for the specified Server Encryption Protector.
Microsoft.Sql/managedInstances/encryptionProtector/write
#Description
Update the properties for the specified Server Encryption Protector.
Microsoft.Sql/managedInstances/failover/action
#Description
Customer initiated managed instance failover.
Microsoft.Sql/managedInstances/hybridCertificate/action
#Description
Creates or updates hybrid certificate with a specified parameters.
Microsoft.Sql/managedInstances/hybridLink/delete
#Description
Deletes a hybrid link with a specified distributed availability group.
Microsoft.Sql/managedInstances/hybridLink/write
#Description
Creates or updates hybrid link with a specified parameters.
Microsoft.Sql/managedInstances/joinServerTrustGroup/action
#Description
Determine if a user is allowed to join Managed Server into a Server Trust Group
Microsoft.Sql/managedInstances/keys/delete
#Description
Deletes an existing Azure SQL Managed Instance key.
Microsoft.Sql/managedInstances/keys/write
#Description
Creates a key with the specified parameters or update the properties or tags for the specified managed instance key.
Microsoft.Sql/managedInstances/operations/cancel/action
#Description
Cancels Azure SQL Managed Instance pending asynchronous operation that is not finished yet.
Microsoft.Sql/managedInstances/privateEndpointConnectionProxies/delete
#Description
Deletes an existing private endpoint connection proxy
Microsoft.Sql/managedInstances/privateEndpointConnectionProxies/validate/action
#Description
Validates a private endpoint connection create call from NRP side
Microsoft.Sql/managedInstances/privateEndpointConnectionProxies/write
#Description
Creates a private endpoint connection proxy with the specified parameters or updates the properties or tags for the specified private endpoint connection proxy.
Microsoft.Sql/managedInstances/privateEndpointConnections/delete
#Description
Deletes an existing private endpoint connection
Microsoft.Sql/managedInstances/privateEndpointConnections/write
#Description
Approves or rejects an existing private endpoint connection
Microsoft.Sql/managedInstances/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
Microsoft.Sql/managedInstances/reevaluateInaccessibleDatabaseState/action
#Description
Reevaluates the inaccessibility state of all managed databases.
Microsoft.Sql/managedInstances/refreshExternalGovernanceStatus/action
#Description
Refreshes external governance enablement status
Microsoft.Sql/managedInstances/restorableDroppedDatabases/backupShortTermRetentionPolicies/write
#Description
Updates a short term retention policy for a dropped managed database
Microsoft.Sql/managedInstances/securityAlertPolicies/write
#Description
Change the managed server threat detection policy for a given managed server
Microsoft.Sql/managedInstances/serverConfigurationOptions/write
#Description
Updates Azure SQL Managed Instance's Server Configuration Option properties for the specified instance.
Microsoft.Sql/managedInstances/serverTrustCertificates/delete
#Description
Delete server trust certificate with a given name
Microsoft.Sql/managedInstances/serverTrustCertificates/write
#Description
Creates or updates server trust certificate with specified parameters.
Microsoft.Sql/managedInstances/start/action
#Description
Starts a given Azure SQL Managed Instance.
Microsoft.Sql/managedInstances/startStopSchedules/delete
#Description
Deletes Azure SQL Managed Instance's Start-Stop schedule.
Microsoft.Sql/managedInstances/startStopSchedules/write
#Description
Creates Azure SQL Managed Instance's Start-Stop schedule with the specified parameters or updates the properties of the schedule for the specified instance.
Microsoft.Sql/managedInstances/stop/action
#Description
Stops a given Azure SQL Managed Instance.
Microsoft.Sql/managedInstances/tdeCertificates/action
#Description
Create/Update TDE certificate
Microsoft.Sql/managedInstances/validateAzureKeyVaultEncryptionKey/action
#Description
Validates customer managed key.
Microsoft.Sql/managedInstances/vulnerabilityAssessments/delete
#Description
Remove the vulnerability assessment for a given managed instance
Microsoft.Sql/managedInstances/vulnerabilityAssessments/write
#Description
Change the vulnerability assessment for a given managed instance
Microsoft.Sql/managedInstances/write
#Description
Creates a managed instance with the specified parameters or update the properties or tags for the specified managed instance.
Microsoft.Sql/privateEndpointConnectionsApproval/action
#Description
Determines if user is allowed to approve a private endpoint connection
Microsoft.Sql/register/action
#Description
Registers the subscription for the Microsoft SQL Database resource provider and enables the creation of Microsoft SQL Databases.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.Sql/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.Sql/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "b0313290-4aa5-4db0-9330-8bbc7608a90a",
"EventDataId": "857d5773-1634-be86-6fdb-030e810e348a",
"EventSubmissionTimestamp": "2026-07-02T17:29:58.4203095Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.SQL/REGISTER/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Sql",
"message": "Microsoft.Sql/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "857d5773-1634-be86-6fdb-030e810e348a",
"eventSubmissionTimestamp": "2026-07-02T17:29:58.4203095Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Sql",
"message": "Microsoft.Sql/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "857d5773-1634-be86-6fdb-030e810e348a",
"eventSubmissionTimestamp": "2026-07-02T17:29:58.4203095Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"ResourceProviderValue": "MICROSOFT.SQL",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Sql/servers/administrators/delete
#Description
Deletes a specific Azure Active Directory administrator object
Microsoft.Sql/servers/administrators/write
#Description
Adds or updates a specific Azure Active Directory administrator object
Microsoft.Sql/servers/advancedThreatProtectionSettings/write
#Description
Change the server Advanced Threat Protection settings for a given server
Microsoft.Sql/servers/advisors/recommendedActions/write
#Description
Apply the recommended action on the server
Microsoft.Sql/servers/advisors/write
#Description
Updates auto-execute status of an advisor on server level.
Microsoft.Sql/servers/auditingSettings/write
#Description
Change the server blob auditing for a given server
Microsoft.Sql/servers/automaticTuning/write
#Description
Updates automatic tuning settings for the server and returns updated settings
Microsoft.Sql/servers/azureADOnlyAuthentications/delete
#Description
Deletes a specific server Azure Active Directory only authentication object
Microsoft.Sql/servers/azureADOnlyAuthentications/write
#Description
Adds or updates a specific server Azure Active Directory only authentication object
Microsoft.Sql/servers/communicationLinks/delete
#Description
Deletes an existing server communication link.
Microsoft.Sql/servers/communicationLinks/write
#Description
Create or update a server communication link.
Microsoft.Sql/servers/connectionPolicies/write
#Description
Create or update a server connection policy.
Microsoft.Sql/servers/databases/advancedThreatProtectionSettings/write
#Description
Change the database Advanced Threat Protection settings for a given database
Microsoft.Sql/servers/databases/advisors/recommendedActions/write
#Description
Apply the recommended action on the database
Microsoft.Sql/servers/databases/advisors/write
#Description
Update auto-execute status of an advisor on database level.
Microsoft.Sql/servers/databases/auditingSettings/write
#Description
Change the blob auditing policy for a given database
Microsoft.Sql/servers/databases/automaticTuning/write
#Description
Updates automatic tuning settings for a database and returns updated settings
Microsoft.Sql/servers/databases/backupLongTermRetentionPolicies/write
#Description
Sets a long term retention policy for a database
Microsoft.Sql/servers/databases/backupShortTermRetentionPolicies/write
#Description
Updates a short term retention policy for a database
Microsoft.Sql/servers/databases/currentSensitivityLabels/write
#Description
Batch update sensitivity labels
Microsoft.Sql/servers/databases/dataMaskingPolicies/rules/write
#Description
Change data masking policy rule for a given database
Microsoft.Sql/servers/databases/dataMaskingPolicies/write
#Description
Change data masking policy for a given database
Microsoft.Sql/servers/databases/delete
#Description
Deletes an existing database.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"action": "Microsoft.Sql/servers/databases/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"action": "Microsoft.Sql/servers/databases/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "64a126ff-58fa-4fbf-b5b2-d8e22cf41f11",
"EventDataId": "98fee98d-ffcf-3a5b-a3e5-5414e870fffb",
"EventSubmissionTimestamp": "2026-07-03T02:21:12.9305555Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.SQL/SERVERS/DATABASES/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"message": "Microsoft.Sql/servers/databases/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "98fee98d-ffcf-3a5b-a3e5-5414e870fffb",
"eventSubmissionTimestamp": "2026-07-03T02:21:12.9305555Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh36bcb1sql/dwhdb",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"message": "Microsoft.Sql/servers/databases/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "98fee98d-ffcf-3a5b-a3e5-5414e870fffb",
"eventSubmissionTimestamp": "2026-07-03T02:21:12.9305555Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh36bcb1sql/dwhdb",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.SQL",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Sql/servers/databases/encryptionProtector/revalidate/action
#Description
Revalidate the database encryption protector
Microsoft.Sql/servers/databases/encryptionProtector/revert/action
#Description
Revertthe database encryption protector
Microsoft.Sql/servers/databases/export/action
#Description
Export Azure SQL Database
Microsoft.Sql/servers/databases/extendedAuditingSettings/write
#Description
Change the extended blob auditing policy for a given database
Microsoft.Sql/servers/databases/extensions/write
#Description
Performs a database extension operation.
Microsoft.Sql/servers/databases/failover/action
#Description
Customer initiated database failover.
Microsoft.Sql/servers/databases/geoBackupPolicies/write
#Description
Create or update a database geobackup policy
Microsoft.Sql/servers/databases/getCurrentAvailabilityZone/action
#Description
Get the current availability zone of a database.
Microsoft.Sql/servers/databases/import/action
#Description
Import Azure SQL Database
Microsoft.Sql/servers/databases/ledgerDigestUploads/disable/action
#Description
Disable uploading ledger digests
Microsoft.Sql/servers/databases/ledgerDigestUploads/write
#Description
Enable uploading ledger digests
Microsoft.Sql/servers/databases/maintenanceWindows/write
#Description
Sets maintenance windows settings for a selected database.
Microsoft.Sql/servers/databases/move/action
#Description
Change the name of an existing database.
Microsoft.Sql/servers/databases/operations/cancel/action
#Description
Cancels Azure SQL Database pending asynchronous operation that is not finished yet.
Microsoft.Sql/servers/databases/pause/action
#Description
Pause Azure SQL Datawarehouse Database
Microsoft.Sql/servers/databases/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
Microsoft.Sql/servers/databases/queryStore/write
#Description
Updates Query Store setting for the database
Microsoft.Sql/servers/databases/recommendedSensitivityLabels/write
#Description
Batch update recommended sensitivity labels
Microsoft.Sql/servers/databases/replicationLinks/delete
#Description
Execute deletion of an existing replication link.
Microsoft.Sql/servers/databases/replicationLinks/failover/action
#Description
Execute planned failover of an existing replication link.
Microsoft.Sql/servers/databases/replicationLinks/forceFailoverAllowDataLoss/action
#Description
Execute forced failover of an existing replication link.
Microsoft.Sql/servers/databases/replicationLinks/unlink/action
#Description
Terminate the replication relationship forcefully or after synchronizing with the partner
Microsoft.Sql/servers/databases/replicationLinks/updateReplicationMode/action
#Description
Update replication mode for link to synchronous or asynchronous mode
Microsoft.Sql/servers/databases/replicationLinks/write
#Description
Updates the replication link type
Microsoft.Sql/servers/databases/restorePoints/action
#Description
Creates a new restore point
Microsoft.Sql/servers/databases/restorePoints/delete
#Description
Deletes a restore point for the database.
Microsoft.Sql/servers/databases/resume/action
#Description
Resume Azure SQL Datawarehouse Database
Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/delete
#Description
Delete the sensitivity label of a given column
Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/disable/action
#Description
Disable sensitivity recommendations on a given column
Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/enable/action
#Description
Enable sensitivity recommendations on a given column
Microsoft.Sql/servers/databases/schemas/tables/columns/sensitivityLabels/write
#Description
Create or update the sensitivity label of a given column
Microsoft.Sql/servers/databases/schemas/tables/recommendedIndexes/write
#Description
Apply index recommendation
Microsoft.Sql/servers/databases/securityAlertPolicies/write
#Description
Change the database threat detection policy for a given database
Microsoft.Sql/servers/databases/sqlVulnerabilityAssessments/baselines/rules/delete
#Description
Remove the sql vulnerability assessment rule baseline for a given database
Microsoft.Sql/servers/databases/sqlVulnerabilityAssessments/baselines/rules/write
#Description
Change the sql vulnerability assessment rule baseline for a given database
Microsoft.Sql/servers/databases/sqlVulnerabilityAssessments/baselines/write
#Description
Change the sql vulnerability assessment baseline set for a given database
Microsoft.Sql/servers/databases/sqlVulnerabilityAssessments/initiateScan/action
#Description
Execute vulnerability assessment database scan.
Microsoft.Sql/servers/databases/syncGroups/cancelSync/action
#Description
Cancel sync group synchronization
Microsoft.Sql/servers/databases/syncGroups/delete
#Description
Deletes an existing sync group.
Microsoft.Sql/servers/databases/syncGroups/refreshHubSchema/action
#Description
Refresh sync hub database schema
Microsoft.Sql/servers/databases/syncGroups/syncMembers/delete
#Description
Deletes an existing sync member.
Microsoft.Sql/servers/databases/syncGroups/syncMembers/refreshSchema/action
#Description
Refresh sync member schema
Microsoft.Sql/servers/databases/syncGroups/syncMembers/write
#Description
Creates a sync member with the specified parameters or update the properties for the specified sync member.
Microsoft.Sql/servers/databases/syncGroups/triggerSync/action
#Description
Trigger sync group synchronization
Microsoft.Sql/servers/databases/syncGroups/write
#Description
Creates a sync group with the specified parameters or update the properties for the specified sync group.
Microsoft.Sql/servers/databases/topQueries/queryText/action
#Description
Returns the text for selected query ID
Microsoft.Sql/servers/databases/transparentDataEncryption/resume/action
#Description
Change the database Transparent Data Encryption for a given logical database
Microsoft.Sql/servers/databases/transparentDataEncryption/suspend/action
#Description
Change the database Transparent Data Encryption for a given logical database
Microsoft.Sql/servers/databases/transparentDataEncryption/write
#Description
Change the database Transparent Data Encryption for a given logical database
Microsoft.Sql/servers/databases/upgradeDataWarehouse/action
#Description
Upgrade Azure SQL Datawarehouse Database
Microsoft.Sql/servers/databases/vulnerabilityAssessments/delete
#Description
Remove the vulnerability assessment for a given database
Microsoft.Sql/servers/databases/vulnerabilityAssessments/rules/baselines/delete
#Description
Remove the vulnerability assessment rule baseline for a given database
Microsoft.Sql/servers/databases/vulnerabilityAssessments/rules/baselines/write
#Description
Change the vulnerability assessment rule baseline for a given database
Microsoft.Sql/servers/databases/vulnerabilityAssessments/scans/export/action
#Description
Convert an existing scan result to a human readable format. If already exists nothing happens
Microsoft.Sql/servers/databases/vulnerabilityAssessments/scans/initiateScan/action
#Description
Execute vulnerability assessment database scan.
Microsoft.Sql/servers/databases/vulnerabilityAssessments/write
#Description
Change the vulnerability assessment for a given database
Microsoft.Sql/servers/databases/vulnerabilityAssessmentScans/action
#Description
Execute vulnerability assessment database scan.
Microsoft.Sql/servers/databases/vulnerabilityAssessmentSettings/write
#Description
Change the vulnerability assessment for a given database
Microsoft.Sql/servers/databases/workloadGroups/delete
#Description
Drops a specific workload group.
Microsoft.Sql/servers/databases/workloadGroups/workloadClassifiers/delete
#Description
Drops a specific workload classifier.
Microsoft.Sql/servers/databases/workloadGroups/workloadClassifiers/write
#Description
Sets the properties for a specific workload classifier.
Microsoft.Sql/servers/databases/workloadGroups/write
#Description
Sets the properties for a specific workload group.
Microsoft.Sql/servers/databases/write
#Description
Creates a database with the specified parameters or update the properties or tags for the specified database.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"action": "Microsoft.Sql/servers/databases/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"action": "Microsoft.Sql/servers/databases/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "51d2ce79-d4eb-4a3c-aa8d-3852f4a91358",
"EventDataId": "3f635de2-a6ed-b6e7-57a6-6bbd29157162",
"EventSubmissionTimestamp": "2026-07-03T02:20:55.5448991Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.SQL/SERVERS/DATABASES/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"message": "Microsoft.Sql/servers/databases/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3f635de2-a6ed-b6e7-57a6-6bbd29157162",
"eventSubmissionTimestamp": "2026-07-03T02:20:55.5448991Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh36bcb1sql/dwhdb",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh36bcb1sql/databases/dwhdb",
"message": "Microsoft.Sql/servers/databases/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3f635de2-a6ed-b6e7-57a6-6bbd29157162",
"eventSubmissionTimestamp": "2026-07-03T02:20:55.5448991Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh36bcb1sql/dwhdb",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.SQL",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Sql/servers/delete
#Description
Deletes an existing server.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "NoContent",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"action": "Microsoft.Sql/servers/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"action": "Microsoft.Sql/servers/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "1fc4dfdb-97ec-4093-b43c-e54d0f5333c0",
"EventDataId": "1ec8c703-6055-ff2d-775a-38d69518f3a0",
"EventSubmissionTimestamp": "2026-07-02T17:19:22.5554596Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.SQL/SERVERS/DELETE",
"Properties": {
"statusCode": "NoContent",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"message": "Microsoft.Sql/servers/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "1ec8c703-6055-ff2d-775a-38d69518f3a0",
"eventSubmissionTimestamp": "2026-07-02T17:19:22.5554596Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0sql",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "NoContent"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"message": "Microsoft.Sql/servers/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "1ec8c703-6055-ff2d-775a-38d69518f3a0",
"eventSubmissionTimestamp": "2026-07-02T17:19:22.5554596Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0sql",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "NoContent",
"serviceRequestId": "",
"activitySubstatusValue": "NoContent"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.SQL",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490
Microsoft.Sql/servers/devOpsAuditingSettings/write
#Description
Change the server DevOps audit policy for a given server
Microsoft.Sql/servers/disasterRecoveryConfiguration/delete
#Description
Deletes an existing disaster recovery configurations for a given server
Microsoft.Sql/servers/disasterRecoveryConfiguration/failover/action
#Description
Failover a DisasterRecoveryConfiguration
Microsoft.Sql/servers/disasterRecoveryConfiguration/forceFailoverAllowDataLoss/action
#Description
Force Failover a DisasterRecoveryConfiguration
Microsoft.Sql/servers/disasterRecoveryConfiguration/write
#Description
Change server disaster recovery configuration
Microsoft.Sql/servers/dnsAliases/acquire/action
#Description
Acquire Server Dns Alias from the current server and repoint it to another server.
Microsoft.Sql/servers/dnsAliases/delete
#Description
Deletes an existing Server Dns Alias.
Microsoft.Sql/servers/dnsAliases/write
#Description
Creates a Server Dns Alias with the specified parameters or update the properties or tags for the specified Server Dns Alias.
Microsoft.Sql/servers/elasticPoolEstimates/write
#Description
Creates new elastic pool estimate for list of databases provided
Microsoft.Sql/servers/elasticPools/advisors/recommendedActions/write
#Description
Apply the recommended action on the elastic pool
Microsoft.Sql/servers/elasticPools/advisors/write
#Description
Update auto-execute status of an advisor on elastic pool level.
Microsoft.Sql/servers/elasticPools/delete
#Description
Delete existing elastic pool
Microsoft.Sql/servers/elasticPools/failover/action
#Description
Customer initiated elastic pool failover.
Microsoft.Sql/servers/elasticPools/operations/cancel/action
#Description
Cancels Azure SQL elastic pool pending asynchronous operation that is not finished yet.
Microsoft.Sql/servers/elasticPools/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
Microsoft.Sql/servers/elasticPools/write
#Description
Create a new or change properties of existing elastic pool
Microsoft.Sql/servers/encryptionProtector/revalidate/action
#Description
Update the properties for the specified Server Encryption Protector.
Microsoft.Sql/servers/encryptionProtector/write
#Description
Update the properties for the specified Server Encryption Protector.
Microsoft.Sql/servers/extendedAuditingSettings/write
#Description
Change the extended server blob auditing for a given server
Microsoft.Sql/servers/failoverGroups/delete
#Description
Deletes an existing failover group.
Microsoft.Sql/servers/failoverGroups/failover/action
#Description
Executes planned failover in an existing failover group.
Microsoft.Sql/servers/failoverGroups/forceFailoverAllowDataLoss/action
#Description
Executes forced failover in an existing failover group.
Microsoft.Sql/servers/failoverGroups/tryPlannedBeforeForcedFailover/action
#Description
Executes try planned before forced failover in an existing failover group.
Microsoft.Sql/servers/failoverGroups/write
#Description
Creates a failover group with the specified parameters or updates the properties or tags for the specified failover group.
Microsoft.Sql/servers/firewallRules/delete
#Description
Deletes an existing server firewall rule.
Microsoft.Sql/servers/firewallRules/write
#Description
Creates a server firewall rule with the specified parameters, update the properties for the specified rule or overwrite all existing rules with new server firewall rule(s).
Microsoft.Sql/servers/import/action
#Description
Import new Azure SQL Database
Microsoft.Sql/servers/ipv6FirewallRules/delete
#Description
Deletes an existing IPv6 server firewall rule.
Microsoft.Sql/servers/ipv6FirewallRules/write
#Description
Creates a IPv6 server firewall rule with the specified parameters, update the properties for the specified rule or overwrite all existing rules with new server firewall rule(s).
Microsoft.Sql/servers/jobAgents/credentials/delete
#Description
Deletes an Azure SQL DB job credential
Microsoft.Sql/servers/jobAgents/credentials/write
#Description
Creates or updates an Azure SQL DB job credential
Microsoft.Sql/servers/jobAgents/delete
#Description
Deletes an Azure SQL DB job agent
Microsoft.Sql/servers/jobAgents/jobs/delete
#Description
Deletes an Azure SQL DB job
Microsoft.Sql/servers/jobAgents/jobs/executions/write
#Description
Creates or updates a job execution
Microsoft.Sql/servers/jobAgents/jobs/steps/delete
#Description
Delete a job step
Microsoft.Sql/servers/jobAgents/jobs/steps/write
#Description
Create or update a job step
Microsoft.Sql/servers/jobAgents/jobs/write
#Description
Creates or updates an Azure SQL DB job
Microsoft.Sql/servers/jobAgents/privateEndpoints/delete
#Description
Delete a private endpoint
Microsoft.Sql/servers/jobAgents/privateEndpoints/write
#Description
Create or update a private endpoint
Microsoft.Sql/servers/jobAgents/targetGroups/delete
#Description
Delete a target group
Microsoft.Sql/servers/jobAgents/targetGroups/write
#Description
Create or update a target group
Microsoft.Sql/servers/jobAgents/write
#Description
Creates or updates an Azure SQL DB job agent
Microsoft.Sql/servers/joinPerimeter/action
#Description
Add server to Network Security Perimeter
Microsoft.Sql/servers/keys/delete
#Description
Deletes an existing server key.
Microsoft.Sql/servers/keys/write
#Description
Creates a key with the specified parameters or update the properties or tags for the specified server key.
Microsoft.Sql/servers/networkSecurityPerimeterAssociationProxies/delete
#Description
Drop network security perimeter association
Microsoft.Sql/servers/networkSecurityPerimeterAssociationProxies/write
#Description
Create network security perimeter association
Microsoft.Sql/servers/networkSecurityPerimeterConfigurations/reconcile/action
#Description
Reconcile Network Security Perimeter
Microsoft.Sql/servers/outboundFirewallRules/delete
#Description
Delete outbound firewall rule
Microsoft.Sql/servers/outboundFirewallRules/write
#Description
Create outbound firewall rule
Microsoft.Sql/servers/privateEndpointConnectionProxies/delete
#Description
Deletes an existing private endpoint connection proxy
Microsoft.Sql/servers/privateEndpointConnectionProxies/updatePrivateEndpointProperties/action
#Description
Used by NRP to backfill properties to a private endpoint connection
Microsoft.Sql/servers/privateEndpointConnectionProxies/validate/action
#Description
Validates a private endpoint connection create call from NRP side
Microsoft.Sql/servers/privateEndpointConnectionProxies/write
#Description
Creates a private endpoint connection proxy with the specified parameters or updates the properties or tags for the specified private endpoint connection proxy.
Microsoft.Sql/servers/privateEndpointConnections/delete
#Description
Deletes an existing private endpoint connection
Microsoft.Sql/servers/privateEndpointConnections/write
#Description
Approves or rejects an existing private endpoint connection
Microsoft.Sql/servers/privateEndpointConnectionsApproval/action
#Description
Determines if user is allowed to approve a private endpoint connection
Microsoft.Sql/servers/refreshExternalGovernanceStatus/action
#Description
Refreshes external governance enablement status
Microsoft.Sql/servers/securityAlertPolicies/write
#Description
Change the server threat detection policy for a given server
Microsoft.Sql/servers/sqlVulnerabilityAssessments/baselines/rules/delete
#Description
Remove the sql vulnerability assessment rule baseline for a given database
Microsoft.Sql/servers/sqlVulnerabilityAssessments/baselines/rules/write
#Description
Change the sql vulnerability assessment rule baseline for a given database
Microsoft.Sql/servers/sqlVulnerabilityAssessments/baselines/write
#Description
Change the sql vulnerability assessment baseline set for a given system database
Microsoft.Sql/servers/sqlVulnerabilityAssessments/delete
#Description
Remove SQL Vulnerability Assessment for a given server
Microsoft.Sql/servers/sqlVulnerabilityAssessments/initiateScan/action
#Description
Execute vulnerability assessment database scan.
Microsoft.Sql/servers/sqlVulnerabilityAssessments/write
#Description
Change SQL Vulnerability Assessment for a given server
Microsoft.Sql/servers/syncAgents/delete
#Description
Deletes an existing sync agent.
Microsoft.Sql/servers/syncAgents/generateKey/action
#Description
Generate sync agent registration key
Microsoft.Sql/servers/syncAgents/write
#Description
Creates a sync agent with the specified parameters or update the properties for the specified sync agent.
Microsoft.Sql/servers/tdeCertificates/action
#Description
Create/Update TDE certificate
Microsoft.Sql/servers/virtualNetworkRules/delete
#Description
Deletes an existing Virtual Network Rule
Microsoft.Sql/servers/virtualNetworkRules/write
#Description
Creates a virtual network rule with the specified parameters or update the properties or tags for the specified virtual network rule.
Microsoft.Sql/servers/vulnerabilityAssessments/delete
#Description
Remove the vulnerability assessment for a given server
Microsoft.Sql/servers/vulnerabilityAssessments/write
#Description
Change the vulnerability assessment for a given server
Microsoft.Sql/servers/write
#Description
Creates a server with the specified parameters or update the properties or tags for the specified server.
Example Resource Log Record #
{
"ActivityStatusValue": "Failure",
"ActivitySubstatusValue": "Conflict",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"action": "Microsoft.Sql/servers/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"action": "Microsoft.Sql/servers/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "6f513c94-ce6e-4945-908a-c81f50ce164f",
"EventDataId": "d07f63f5-0c3f-69a8-5d93-4b018d98a78b",
"EventSubmissionTimestamp": "2026-07-02T17:19:21.2797016Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Error",
"OperationNameValue": "MICROSOFT.SQL/SERVERS/WRITE",
"Properties": {
"statusCode": "Conflict",
"serviceRequestId": "",
"statusMessage": {
"error": {
"code": "MissingSubscriptionRegistration",
"message": "The subscription is not registered to use namespace 'Microsoft.Sql'. See https://aka.ms/rps-not-found for how to register subscriptions.",
"details": [
{
"code": "MissingSubscriptionRegistration",
"target": "Microsoft.Sql",
"message": "The subscription is not registered to use namespace 'Microsoft.Sql'. See https://aka.ms/rps-not-found for how to register subscriptions."
}
]
}
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"message": "Microsoft.Sql/servers/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d07f63f5-0c3f-69a8-5d93-4b018d98a78b",
"eventSubmissionTimestamp": "2026-07-02T17:19:21.2797016Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0sql",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "Conflict"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Sql/servers/dwh92eef0sql",
"message": "Microsoft.Sql/servers/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "d07f63f5-0c3f-69a8-5d93-4b018d98a78b",
"eventSubmissionTimestamp": "2026-07-02T17:19:21.2797016Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0sql",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.SQL",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"statusCode": "Conflict",
"serviceRequestId": "",
"activitySubstatusValue": "Conflict",
"statusMessage": {
"error": {
"code": "MissingSubscriptionRegistration",
"message": "The subscription is not registered to use namespace 'Microsoft.Sql'. See https://aka.ms/rps-not-found for how to register subscriptions.",
"details": [
{
"code": "MissingSubscriptionRegistration",
"target": "Microsoft.Sql",
"message": "The subscription is not registered to use namespace 'Microsoft.Sql'. See https://aka.ms/rps-not-found for how to register subscriptions."
}
]
}
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.SQL",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Sql/unregister/action
#Description
Unregisters the subscription for the Azure SQL Database resource provider and disables the creation of Azure SQL Databases.
Microsoft.Sql/virtualClusters/delete
#Description
Deletes an existing virtual cluster.
Microsoft.Sql/virtualClusters/updateManagedInstanceDnsServers/action
#Description
Performs virtual cluster dns servers.
Microsoft.Sql/virtualClusters/write
#Description
Creates or updates the virtual clusters.