Azure Storage Azure-Microsoft.Storage

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Storage rules that match the resource provider but no specific operation.NN
Microsoft.Storage/locations/ActionsRPOperationStatuses/writeCreates or updates an ActionsRP operation statusNN
Microsoft.Storage/locations/DataManagementRPOperationStatuses/writeCreates or updates a DataManagamentRP operation statusNN
Microsoft.Storage/locations/deleteVirtualNetworkOrSubnets/actionNotifies Microsoft.Storage that virtual network or subnet is being deletedNN
Microsoft.Storage/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/actionNN
Microsoft.Storage/locations/previewActions/actionNN
Microsoft.Storage/register/actionRegisters the subscription for the storage resource provider and enables the creation of storage accounts.NN
Microsoft.Storage/storageAccounts/accountLocks/deleteNN
Microsoft.Storage/storageAccounts/accountLocks/deleteLock/actionNN
Microsoft.Storage/storageAccounts/accountLocks/writeNN
Microsoft.Storage/storageAccounts/accountMigrations/writeCustomer is able to update their storage account redundancy for increased resiliencyNN
Microsoft.Storage/storageAccounts/advancedPlatformMetrics/deleteNN
Microsoft.Storage/storageAccounts/advancedPlatformMetrics/writeNN
Microsoft.Storage/storageAccounts/blobServices/containers/clearLegalHold/actionClear blob container legal holdNN
Microsoft.Storage/storageAccounts/blobServices/containers/deleteReturns the result of deleting a containerNN
Microsoft.Storage/storageAccounts/blobServices/containers/getAcl/actionNN
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/deleteDelete blob container immutability policyNY
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/extend/actionExtend blob container immutability policyNN
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/lock/actionLock blob container immutability policyNN
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/writePut blob container immutability policyNN
Microsoft.Storage/storageAccounts/blobServices/containers/lease/actionReturns the result of leasing blob containerNN
Microsoft.Storage/storageAccounts/blobServices/containers/migrate/actionNN
Microsoft.Storage/storageAccounts/blobServices/containers/setAcl/actionNN
Microsoft.Storage/storageAccounts/blobServices/containers/setLegalHold/actionSet blob container legal holdNN
Microsoft.Storage/storageAccounts/blobServices/containers/writeReturns the result of patch blob containerNY
Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/actionReturns a user delegation key for the blob serviceNN
Microsoft.Storage/storageAccounts/blobServices/getInfo/actionNN
Microsoft.Storage/storageAccounts/blobServices/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resource.NN
Microsoft.Storage/storageAccounts/blobServices/writeReturns the result of put blob service propertiesNY
Microsoft.Storage/storageAccounts/connectors/deleteDelete a storage connector.NN
Microsoft.Storage/storageAccounts/connectors/testExistingConnection/actionTest the connection of an existing storage connector.NN
Microsoft.Storage/storageAccounts/connectors/writeCreates or updates a storage connector.NN
Microsoft.Storage/storageAccounts/consumerDataShare/actionNN
Microsoft.Storage/storageAccounts/consumerDataSharePolicies/writeNN
Microsoft.Storage/storageAccounts/dataSharePolicies/deleteNN
Microsoft.Storage/storageAccounts/dataSharePolicies/writeNN
Microsoft.Storage/storageAccounts/dataShares/deleteDelete a storage data share.NN
Microsoft.Storage/storageAccounts/dataShares/writeCreates or updates a storage data share.NN
Microsoft.Storage/storageAccounts/deleteDeletes an existing storage account.YY
Microsoft.Storage/storageAccounts/encryptionScopes/hoboConfigurations/writeNN
Microsoft.Storage/storageAccounts/encryptionScopes/writeNN
Microsoft.Storage/storageAccounts/failover/actionCustomer is able to control the failover in case of availability issuesNN
Microsoft.Storage/storageAccounts/fileServices/generateUserDelegationKey/actionReturns a user delegation key for the file serviceNN
Microsoft.Storage/storageAccounts/fileServices/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resource.NN
Microsoft.Storage/storageAccounts/fileServices/shares/deleteDelete file shareNN
Microsoft.Storage/storageAccounts/fileServices/shares/lease/actionNN
Microsoft.Storage/storageAccounts/fileServices/shares/restore/actionRestore file shareNN
Microsoft.Storage/storageAccounts/fileServices/shares/revert/actionRevert File ShareNN
Microsoft.Storage/storageAccounts/fileServices/shares/writeCreate or update file shareNY
Microsoft.Storage/storageAccounts/fileServices/writePut file service propertiesNN
Microsoft.Storage/storageAccounts/hnsonmigration/actionCustomer is able to migrate to hns account typeNN
Microsoft.Storage/storageAccounts/hoboConfigurations/writeNN
Microsoft.Storage/storageAccounts/inventoryPolicies/deleteNN
Microsoft.Storage/storageAccounts/inventoryPolicies/writeNN
Microsoft.Storage/storageAccounts/joinPerimeter/actionAccess check for joining Network Security PerimeterNN
Microsoft.Storage/storageAccounts/listAccountSas/actionReturns the Account SAS token for the specified storage account.NN
Microsoft.Storage/storageAccounts/listkeys/actionReturns the access keys for the specified storage account.YY
Microsoft.Storage/storageAccounts/listServiceSas/actionReturns the Service SAS token for the specified storage account.NN
Microsoft.Storage/storageAccounts/localUsers/deleteDelete local userNN
Microsoft.Storage/storageAccounts/localusers/listKeys/actionList local user keysNN
Microsoft.Storage/storageAccounts/localusers/regeneratePassword/actionNN
Microsoft.Storage/storageAccounts/localUsers/regenerateSharedKey/actionNN
Microsoft.Storage/storageAccounts/localusers/writeCreate or update local userNN
Microsoft.Storage/storageAccounts/managementPolicies/deleteDelete storage account management policiesNN
Microsoft.Storage/storageAccounts/managementPolicies/writePut storage account management policiesNN
Microsoft.Storage/storageAccounts/networkSecurityPerimeterAssociationProxies/deleteNN
Microsoft.Storage/storageAccounts/networkSecurityPerimeterAssociationProxies/writeNN
Microsoft.Storage/storageAccounts/networkSecurityPerimeterConfigurations/actionNN
Microsoft.Storage/storageAccounts/objectReplicationPolicies/deleteDelete object replication policyNN
Microsoft.Storage/storageAccounts/objectReplicationPolicies/restorePointMarkers/writeCreate object replication restore point markerNN
Microsoft.Storage/storageAccounts/objectReplicationPolicies/writeCreate or update object replication policyNN
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/deleteDelete Private Endpoint Connection ProxiesNN
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/updatePrivateEndpointProperties/actionUpdate storage account private endpoint propertiesNN
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/validate/actionValidate Private Endpoint Connection ProxiesNN
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/writePut Private Endpoint Connection ProxiesNN
Microsoft.Storage/storageAccounts/privateEndpointConnections/deleteDelete Private Endpoint ConnectionNN
Microsoft.Storage/storageAccounts/privateEndpointConnections/writePut Private Endpoint ConnectionNN
Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/actionApprove Private Endpoint ConnectionsNN
Microsoft.Storage/storageAccounts/privateEndpoints/move/actionNN
Microsoft.Storage/storageAccounts/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resource.NN
Microsoft.Storage/storageAccounts/queueServices/generateUserDelegationKey/actionReturns a user delegation key for the queue serviceNN
Microsoft.Storage/storageAccounts/queueServices/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resource.NN
Microsoft.Storage/storageAccounts/queueServices/queues/deleteReturns the result of deleting a queueNN
Microsoft.Storage/storageAccounts/queueServices/queues/getAcl/actionReturns the result of processing a messageNN
Microsoft.Storage/storageAccounts/queueServices/queues/setAcl/actionReturns the result of processing a messageNN
Microsoft.Storage/storageAccounts/queueServices/queues/writeReturns the result of writing a queueNN
Microsoft.Storage/storageAccounts/queueServices/writeReturns the result of setting queue service propertiesNN
Microsoft.Storage/storageAccounts/regeneratekey/actionRegenerates the access keys for the specified storage account.YY
Microsoft.Storage/storageAccounts/restoreBlobRanges/actionRestore blob ranges to the state of the specified timeNN
Microsoft.Storage/storageAccounts/restorePoints/deleteDelete object replication restore pointNN
Microsoft.Storage/storageAccounts/revokeUserDelegationKeys/actionRevokes all the user delegation keys for the specified storage account.NN
Microsoft.Storage/storageAccounts/rotateKey/actionNN
Microsoft.Storage/storageAccounts/services/diagnosticSettings/writeCreate/Update storage account diagnostic settings.NN
Microsoft.Storage/storageAccounts/storageTaskAssignments/deleteNN
Microsoft.Storage/storageAccounts/storageTaskAssignments/writeNN
Microsoft.Storage/storageAccounts/tableServices/generateUserDelegationKey/actionReturns a user delegation key for the table serviceNN
Microsoft.Storage/storageAccounts/tableServices/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resource.NN
Microsoft.Storage/storageAccounts/tableServices/tables/deleteDelete tablesNN
Microsoft.Storage/storageAccounts/tableServices/tables/getAcl/actionMerge or update table entitiesNN
Microsoft.Storage/storageAccounts/tableServices/tables/setAcl/actionMerge or update table entitiesNN
Microsoft.Storage/storageAccounts/tableServices/tables/writeCreate tablesNN
Microsoft.Storage/storageAccounts/tableServices/writeSet table service propertiesNN
Microsoft.Storage/storageAccounts/updateAccountContainerHoldingPeriod/actionNN
Microsoft.Storage/storageAccounts/updateAutoRotateUserKeys/actionNN
Microsoft.Storage/storageAccounts/updateInternalProperties/actionNN
Microsoft.Storage/storageAccounts/writeCreates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.YY
Microsoft.Storage/storageTasks/deleteDeletes an existing storage taskNN
Microsoft.Storage/storageTasks/promote/actionPromote specific version of storage task to current versionNN
Microsoft.Storage/storageTasks/writeCreates or updates storage taskNN
Microsoft.Storage/unregister/actionNN
Microsoft.Storage/contextCaches/contextCacheContainers/deleteDelete a container from a Context Cache resource.NN
Microsoft.Storage/contextCaches/contextCacheContainers/writeCreate or update a container in a Context Cache resource.NN
Microsoft.Storage/contextCaches/deleteDelete a Context Cache resource.NN
Microsoft.Storage/contextCaches/writeCreate or update a Context Cache resource.NN
Microsoft.Storage/locations/ContextCacheRPOperationStatuses/writeWrites the status of an asynchronous Context Cache operation.NN
Microsoft.Storage/storageAccounts/abortHnsOnMigration/actionCustomer is able to abort an ongoing Hns migration on the storage accountNN
Microsoft.Storage/storageAccounts/encryptionScopes/sharedIdentities/writePut shared identity for a storage account's encryption scopeNN
Microsoft.Storage/storageAccounts/sharedIdentities/writeNN

any: Azure Storage (catch-all)

#
Namespace
Microsoft.Storage

Description

Catch-all for Azure-Microsoft.Storage rules that match the resource provider but no specific operation.

Microsoft.Storage/locations/ActionsRPOperationStatuses/write

#
Namespace
Microsoft.Storage

Description

Creates or updates an ActionsRP operation status

Microsoft.Storage/locations/DataManagementRPOperationStatuses/write

#
Namespace
Microsoft.Storage

Description

Creates or updates a DataManagamentRP operation status

Microsoft.Storage/locations/deleteVirtualNetworkOrSubnets/action

#
Namespace
Microsoft.Storage

Description

Notifies Microsoft.Storage that virtual network or subnet is being deleted

Microsoft.Storage/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/locations/previewActions/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/register/action

#
Namespace
Microsoft.Storage

Description

Registers the subscription for the storage resource provider and enables the creation of storage accounts.

Microsoft.Storage/storageAccounts/accountLocks/delete

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/accountLocks/deleteLock/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/accountLocks/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/accountMigrations/write

#
Namespace
Microsoft.Storage

Description

Customer is able to update their storage account redundancy for increased resiliency

Microsoft.Storage/storageAccounts/advancedPlatformMetrics/delete

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/advancedPlatformMetrics/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/blobServices/containers/clearLegalHold/action

#
Namespace
Microsoft.Storage

Description

Clear blob container legal hold

Microsoft.Storage/storageAccounts/blobServices/containers/delete

#
Namespace
Microsoft.Storage

Description

Returns the result of deleting a container

Microsoft.Storage/storageAccounts/blobServices/containers/getAcl/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/delete

#
Namespace
Microsoft.Storage

Description

Delete blob container immutability policy

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/extend/action

#
Namespace
Microsoft.Storage

Description

Extend blob container immutability policy

Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/lock/action

#
Namespace
Microsoft.Storage

Description

Lock blob container immutability policy

Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/write

#
Namespace
Microsoft.Storage

Description

Put blob container immutability policy

Microsoft.Storage/storageAccounts/blobServices/containers/lease/action

#
Namespace
Microsoft.Storage

Description

Returns the result of leasing blob container

Microsoft.Storage/storageAccounts/blobServices/containers/migrate/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/blobServices/containers/setAcl/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/blobServices/containers/setLegalHold/action

#
Namespace
Microsoft.Storage

Description

Set blob container legal hold

Microsoft.Storage/storageAccounts/blobServices/containers/write

#
Namespace
Microsoft.Storage

Description

Returns the result of patch blob container

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded2 rulespanther
resultType (panther rule field)inSuccess2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action

#
Namespace
Microsoft.Storage

Description

Returns a user delegation key for the blob service

Microsoft.Storage/storageAccounts/blobServices/getInfo/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/blobServices/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Storage

Description

Creates or updates the diagnostic setting for the resource.

Microsoft.Storage/storageAccounts/blobServices/write

#
Namespace
Microsoft.Storage

Description

Returns the result of put blob service properties

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded4 rulespanther
resultType (panther rule field)inSuccess4 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

Microsoft.Storage/storageAccounts/connectors/delete

#
Namespace
Microsoft.Storage

Description

Delete a storage connector.

Microsoft.Storage/storageAccounts/connectors/testExistingConnection/action

#
Namespace
Microsoft.Storage

Description

Test the connection of an existing storage connector.

Microsoft.Storage/storageAccounts/connectors/write

#
Namespace
Microsoft.Storage

Description

Creates or updates a storage connector.

Microsoft.Storage/storageAccounts/consumerDataShare/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/consumerDataSharePolicies/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/dataSharePolicies/delete

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/dataSharePolicies/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/dataShares/delete

#
Namespace
Microsoft.Storage

Description

Delete a storage data share.

Microsoft.Storage/storageAccounts/dataShares/write

#
Namespace
Microsoft.Storage

Description

Creates or updates a storage data share.

Microsoft.Storage/storageAccounts/delete

#
Namespace
Microsoft.Storage

Description

Deletes an existing storage account.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "action": "Microsoft.Storage/storageAccounts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "action": "Microsoft.Storage/storageAccounts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "fc1a2604-7b0a-493d-8552-f679c469fff7",
  "EventDataId": "29fa9414-6fc7-e092-2035-d8ee6a28cfe8",
  "EventSubmissionTimestamp": "2026-06-29T18:11:31.2147942Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "message": "Microsoft.Storage/storageAccounts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "29fa9414-6fc7-e092-2035-d8ee6a28cfe8",
    "eventSubmissionTimestamp": "2026-06-29T18:11:31.2147942Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcsa25394",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "message": "Microsoft.Storage/storageAccounts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "29fa9414-6fc7-e092-2035-d8ee6a28cfe8",
    "eventSubmissionTimestamp": "2026-06-29T18:11:31.2147942Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcsa25394",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.STORAGE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:11:31.2147942Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.storage/storageaccounts/zcsa25394"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.activitylogs.identity.claims_initiated_by_user.name (elastic rule field)is_not_null2 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Storage Account Deletion by Unusual User source medium: Identifies when an Azure Storage Account is deleted. Adversaries may delete storage accounts to disrupt operations, destroy evidence, or cause denial of service. This activity could indicate an attacker attempting to cover their tracks after data exfiltration or as part of a destructive attack. Monitoring storage account deletions is critical for detecting potential impact on business operations and data availability.T1485, T1489
  • Azure Storage Account Deletions by User source high: Identifies when a single user or service principal deletes multiple Azure Storage Accounts within a short time period. This behavior may indicate an adversary attempting to cause widespread service disruption, destroy evidence, or execute a destructive attack such as ransomware. Mass deletion of storage accounts can have severe business impact and is rarely performed by legitimate administrators except during controlled decommissioning activities.T1485, T1489

Panther #

  • Azure Storage Account Deleted source high: Detects when an Azure storage account is deleted. Storage account deletion is a destructive operation that may indicate ransomware activity or malicious data destruction.T1485, T1490

Microsoft.Storage/storageAccounts/encryptionScopes/hoboConfigurations/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/encryptionScopes/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/failover/action

#
Namespace
Microsoft.Storage

Description

Customer is able to control the failover in case of availability issues

Microsoft.Storage/storageAccounts/fileServices/generateUserDelegationKey/action

#
Namespace
Microsoft.Storage

Description

Returns a user delegation key for the file service

Microsoft.Storage/storageAccounts/fileServices/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Storage

Description

Creates or updates the diagnostic setting for the resource.

Microsoft.Storage/storageAccounts/fileServices/shares/delete

#
Namespace
Microsoft.Storage

Description

Delete file share

Microsoft.Storage/storageAccounts/fileServices/shares/lease/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/fileServices/shares/restore/action

#
Namespace
Microsoft.Storage

Description

Restore file share

Microsoft.Storage/storageAccounts/fileServices/shares/revert/action

#
Namespace
Microsoft.Storage

Description

Revert File Share

Microsoft.Storage/storageAccounts/fileServices/shares/write

#
Namespace
Microsoft.Storage

Description

Create or update file share

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Storage File Share Created or Modified source informational: Detects when an Azure Storage file share is created or modified. File shares can be mounted as network drives using SMB or NFS protocols, providing persistent access to storage. Adversaries may create or modify file shares to establish data exfiltration channels or mount shares to local systems for easier data transfer. While file share operations are common in legitimate scenarios, monitoring these activities helps establish baselines and identify unusual patterns that may indicate data exfiltration.T1048, T1530

Microsoft.Storage/storageAccounts/fileServices/write

#
Namespace
Microsoft.Storage

Description

Put file service properties

Microsoft.Storage/storageAccounts/hnsonmigration/action

#
Namespace
Microsoft.Storage

Description

Customer is able to migrate to hns account type

Microsoft.Storage/storageAccounts/hoboConfigurations/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/inventoryPolicies/delete

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/inventoryPolicies/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/joinPerimeter/action

#
Namespace
Microsoft.Storage

Description

Access check for joining Network Security Perimeter

Microsoft.Storage/storageAccounts/listAccountSas/action

#
Namespace
Microsoft.Storage

Description

Returns the Account SAS token for the specified storage account.

Microsoft.Storage/storageAccounts/listkeys/action

#
Namespace
Microsoft.Storage

Description

Returns the access keys for the specified storage account.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "action": "Microsoft.Storage/storageAccounts/listKeys/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "action": "Microsoft.Storage/storageAccounts/listKeys/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "2815a35c-c303-4de7-8178-760ed598170e",
  "EventDataId": "6689e3c5-b2cf-9da5-7956-47aa7098b287",
  "EventSubmissionTimestamp": "2026-07-03T02:17:04.173868Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/LISTKEYS/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "message": "Microsoft.Storage/storageAccounts/listKeys/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6689e3c5-b2cf-9da5-7956-47aa7098b287",
    "eventSubmissionTimestamp": "2026-07-03T02:17:04.173868Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "message": "Microsoft.Storage/storageAccounts/listKeys/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6689e3c5-b2cf-9da5-7956-47aa7098b287",
    "eventSubmissionTimestamp": "2026-07-03T02:17:04.1738680Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.STORAGE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ActivityStatusValue (kusto rule field)eqsuccess2 ruleskusto
azure.activitylogs.identity.authorization.evidence.principal_type (elastic rule field)equser1 ruleelastic
count_ (kusto rule field)ge51 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Azure Storage Account Keys Accessed by Privileged User source medium: Identifies unusual high-privileged access to Azure Storage Account keys by users with Owner, Contributor, or Storage Account Contributor roles. This technique was observed in STORM-0501 ransomware campaigns where compromised identities with high-privilege Azure RBAC roles retrieved access keys to perform unauthorized operations on Storage Accounts. Microsoft recommends using Shared Access Signature (SAS) models instead of direct key access for improved security. This rule detects when a user principal with high-privilege roles accesses storage keys for the first time in 7 days.T1078, T1078.004, T1555, T1555.006

Kusto #

Panther #

  • Azure Storage Account Keys Listed source medium: Detects when Azure Storage Account access keys are listed or retrieved. This operation returns the full access keys which could grant complete control over the storage account and all its data. Adversaries may list storage account keys to gain persistent access to blob containers, file shares, queues, and tables without needing to maintain their current permissions.T1530, T1552

Microsoft.Storage/storageAccounts/listServiceSas/action

#
Namespace
Microsoft.Storage

Description

Returns the Service SAS token for the specified storage account.

Microsoft.Storage/storageAccounts/localUsers/delete

#
Namespace
Microsoft.Storage

Description

Delete local user

Microsoft.Storage/storageAccounts/localusers/listKeys/action

#
Namespace
Microsoft.Storage

Description

List local user keys

Microsoft.Storage/storageAccounts/localusers/regeneratePassword/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/localUsers/regenerateSharedKey/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/localusers/write

#
Namespace
Microsoft.Storage

Description

Create or update local user

Microsoft.Storage/storageAccounts/managementPolicies/delete

#
Namespace
Microsoft.Storage

Description

Delete storage account management policies

Microsoft.Storage/storageAccounts/managementPolicies/write

#
Namespace
Microsoft.Storage

Description

Put storage account management policies

Microsoft.Storage/storageAccounts/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/networkSecurityPerimeterConfigurations/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/objectReplicationPolicies/delete

#
Namespace
Microsoft.Storage

Description

Delete object replication policy

Microsoft.Storage/storageAccounts/objectReplicationPolicies/restorePointMarkers/write

#
Namespace
Microsoft.Storage

Description

Create object replication restore point marker

Microsoft.Storage/storageAccounts/objectReplicationPolicies/write

#
Namespace
Microsoft.Storage

Description

Create or update object replication policy

Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.Storage

Description

Delete Private Endpoint Connection Proxies

Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/updatePrivateEndpointProperties/action

#
Namespace
Microsoft.Storage

Description

Update storage account private endpoint properties

Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Storage

Description

Validate Private Endpoint Connection Proxies

Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.Storage

Description

Put Private Endpoint Connection Proxies

Microsoft.Storage/storageAccounts/privateEndpointConnections/delete

#
Namespace
Microsoft.Storage

Description

Delete Private Endpoint Connection

Microsoft.Storage/storageAccounts/privateEndpointConnections/write

#
Namespace
Microsoft.Storage

Description

Put Private Endpoint Connection

Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Storage

Description

Approve Private Endpoint Connections

Microsoft.Storage/storageAccounts/privateEndpoints/move/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Storage

Description

Creates or updates the diagnostic setting for the resource.

Microsoft.Storage/storageAccounts/queueServices/generateUserDelegationKey/action

#
Namespace
Microsoft.Storage

Description

Returns a user delegation key for the queue service

Microsoft.Storage/storageAccounts/queueServices/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Storage

Description

Creates or updates the diagnostic setting for the resource.

Microsoft.Storage/storageAccounts/queueServices/queues/delete

#
Namespace
Microsoft.Storage

Description

Returns the result of deleting a queue

Microsoft.Storage/storageAccounts/queueServices/queues/getAcl/action

#
Namespace
Microsoft.Storage

Description

Returns the result of processing a message

Microsoft.Storage/storageAccounts/queueServices/queues/setAcl/action

#
Namespace
Microsoft.Storage

Description

Returns the result of processing a message

Microsoft.Storage/storageAccounts/queueServices/queues/write

#
Namespace
Microsoft.Storage

Description

Returns the result of writing a queue

Microsoft.Storage/storageAccounts/queueServices/write

#
Namespace
Microsoft.Storage

Description

Returns the result of setting queue service properties

Microsoft.Storage/storageAccounts/regeneratekey/action

#
Namespace
Microsoft.Storage

Description

Regenerates the access keys for the specified storage account.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "action": "Microsoft.Storage/storageAccounts/regenerateKey/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "action": "Microsoft.Storage/storageAccounts/regenerateKey/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "a54f8a7e-498e-42ec-ae7b-d9b8003d523a",
  "EventDataId": "b40d0c9a-e6ca-7a5a-d07c-af344bed0ea4",
  "EventSubmissionTimestamp": "2026-07-03T02:17:05.5450383Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/REGENERATEKEY/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "message": "Microsoft.Storage/storageAccounts/regenerateKey/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b40d0c9a-e6ca-7a5a-d07c-af344bed0ea4",
    "eventSubmissionTimestamp": "2026-07-03T02:17:05.5450383Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
    "message": "Microsoft.Storage/storageAccounts/regenerateKey/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b40d0c9a-e6ca-7a5a-d07c-af344bed0ea4",
    "eventSubmissionTimestamp": "2026-07-03T02:17:05.5450383Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.STORAGE",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Storage Account Key Regenerated source low: Identifies a rotation to storage account access keys in Azure. Regenerating access keys can affect any applications or Azure services that are dependent on the storage account key. Adversaries may regenerate a key as a means of acquiring credentials to access systems and resources.T1098, T1098.001, T1552, T1552.005

Panther #

  • Azure Storage Account Key Regenerated source informational: Detects when an Azure storage account access key is regenerated. Key regeneration is a normal operational activity but may indicate an attacker attempting to maintain persistence or rotate credentials after compromise.T1098

Microsoft.Storage/storageAccounts/restoreBlobRanges/action

#
Namespace
Microsoft.Storage

Description

Restore blob ranges to the state of the specified time

Microsoft.Storage/storageAccounts/restorePoints/delete

#
Namespace
Microsoft.Storage

Description

Delete object replication restore point

Microsoft.Storage/storageAccounts/revokeUserDelegationKeys/action

#
Namespace
Microsoft.Storage

Description

Revokes all the user delegation keys for the specified storage account.

Microsoft.Storage/storageAccounts/rotateKey/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/services/diagnosticSettings/write

#
Namespace
Microsoft.Storage

Description

Create/Update storage account diagnostic settings.

Microsoft.Storage/storageAccounts/storageTaskAssignments/delete

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/storageTaskAssignments/write

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/tableServices/generateUserDelegationKey/action

#
Namespace
Microsoft.Storage

Description

Returns a user delegation key for the table service

Microsoft.Storage/storageAccounts/tableServices/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Storage

Description

Creates or updates the diagnostic setting for the resource.

Microsoft.Storage/storageAccounts/tableServices/tables/delete

#
Namespace
Microsoft.Storage

Description

Delete tables

Microsoft.Storage/storageAccounts/tableServices/tables/getAcl/action

#
Namespace
Microsoft.Storage

Description

Merge or update table entities

Microsoft.Storage/storageAccounts/tableServices/tables/setAcl/action

#
Namespace
Microsoft.Storage

Description

Merge or update table entities

Microsoft.Storage/storageAccounts/tableServices/tables/write

#
Namespace
Microsoft.Storage

Description

Create tables

Microsoft.Storage/storageAccounts/tableServices/write

#
Namespace
Microsoft.Storage

Description

Set table service properties

Microsoft.Storage/storageAccounts/updateAccountContainerHoldingPeriod/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/updateAutoRotateUserKeys/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/updateInternalProperties/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/storageAccounts/write

#
Namespace
Microsoft.Storage

Description

Creates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "action": "Microsoft.Storage/storageAccounts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "action": "Microsoft.Storage/storageAccounts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "584251ce-eb35-46eb-acec-6721a6073546",
  "EventDataId": "876eed4f-7d11-8970-4fb1-4a7700dd1893",
  "EventSubmissionTimestamp": "2026-06-29T17:50:17.1099996Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "message": "Microsoft.Storage/storageAccounts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "876eed4f-7d11-8970-4fb1-4a7700dd1893",
    "eventSubmissionTimestamp": "2026-06-29T17:50:17.1099996Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcsa25394",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
    "message": "Microsoft.Storage/storageAccounts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "876eed4f-7d11-8970-4fb1-4a7700dd1893",
    "eventSubmissionTimestamp": "2026-06-29T17:50:17.1099996Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcsa25394",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.STORAGE",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.STORAGE",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:50:17.1099996Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.storage/storageaccounts/zcsa25394"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded4 rulespanther
resultType (panther rule field)inSuccess4 rulespanther
ActivityStatusValue (kusto rule field)eqsuccess1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Storage Account Blob Public Access Enabled source medium: Identifies when Azure Storage Account Blob public access is enabled, allowing external access to blob containers. This technique was observed in cloud ransom-based campaigns where threat actors modified storage accounts to expose non-remotely accessible accounts to the internet for data exfiltration. Adversaries abuse the Microsoft.Storage/storageAccounts/write operation to modify public access settings.T1530

Kusto #

Panther #

Microsoft.Storage/storageTasks/delete

#
Namespace
Microsoft.Storage

Description

Deletes an existing storage task

Microsoft.Storage/storageTasks/promote/action

#
Namespace
Microsoft.Storage

Description

Promote specific version of storage task to current version

Microsoft.Storage/storageTasks/write

#
Namespace
Microsoft.Storage

Description

Creates or updates storage task

Microsoft.Storage/unregister/action

#
Namespace
Microsoft.Storage

Microsoft.Storage/contextCaches/contextCacheContainers/delete

#
Namespace
Microsoft.Storage

Description

Delete a container from a Context Cache resource.

Microsoft.Storage/contextCaches/contextCacheContainers/write

#
Namespace
Microsoft.Storage

Description

Create or update a container in a Context Cache resource.

Microsoft.Storage/contextCaches/delete

#
Namespace
Microsoft.Storage

Description

Delete a Context Cache resource.

Microsoft.Storage/contextCaches/write

#
Namespace
Microsoft.Storage

Description

Create or update a Context Cache resource.

Microsoft.Storage/locations/ContextCacheRPOperationStatuses/write

#
Namespace
Microsoft.Storage

Description

Writes the status of an asynchronous Context Cache operation.

Microsoft.Storage/storageAccounts/abortHnsOnMigration/action

#
Namespace
Microsoft.Storage

Description

Customer is able to abort an ongoing Hns migration on the storage account

Microsoft.Storage/storageAccounts/encryptionScopes/sharedIdentities/write

#
Namespace
Microsoft.Storage

Description

Put shared identity for a storage account's encryption scope

Microsoft.Storage/storageAccounts/sharedIdentities/write

#
Namespace
Microsoft.Storage

References #