Azure App Service Azure-Microsoft.Web
any: Azure App Service (catch-all)
#Description
Catch-all for Azure-Microsoft.Web rules that match the resource provider but no specific operation.
References #
microsoft.web/apimanagementaccounts/apis/apiacls/delete
#Description
Delete Api Management Accounts APIs Apiacls.
References #
microsoft.web/apimanagementaccounts/apis/apiacls/write
#Description
Update Api Management Accounts APIs Apiacls.
References #
microsoft.web/apimanagementaccounts/apis/connections/confirmconsentcode/action
#Description
Confirm Consent Code Api Management Accounts APIs Connections.
References #
microsoft.web/apimanagementaccounts/apis/connections/connectionacls/delete
#Description
Delete Api Management Accounts APIs Connections Connectionacls.
References #
microsoft.web/apimanagementaccounts/apis/connections/connectionacls/write
#Description
Update Api Management Accounts APIs Connections Connectionacls.
References #
microsoft.web/apimanagementaccounts/apis/connections/delete
#Description
Delete Api Management Accounts APIs Connections.
References #
microsoft.web/apimanagementaccounts/apis/connections/getconsentlinks/action
#Description
Get Consent Links for Api Management Accounts APIs Connections.
References #
microsoft.web/apimanagementaccounts/apis/connections/listconnectionkeys/action
#Description
List Connection Keys Api Management Accounts APIs Connections.
References #
microsoft.web/apimanagementaccounts/apis/connections/listsecrets/action
#Description
List Secrets Api Management Accounts APIs Connections.
References #
microsoft.web/apimanagementaccounts/apis/connections/write
#Description
Update Api Management Accounts APIs Connections.
References #
microsoft.web/apimanagementaccounts/apis/delete
#Description
Delete Api Management Accounts APIs.
References #
microsoft.web/apimanagementaccounts/apis/localizeddefinitions/delete
#Description
Delete Api Management Accounts APIs Localized Definitions.
References #
microsoft.web/apimanagementaccounts/apis/localizeddefinitions/write
#Description
Update Api Management Accounts APIs Localized Definitions.
References #
microsoft.web/apimanagementaccounts/apis/write
#Description
Update Api Management Accounts APIs.
References #
Microsoft.Web/certificates/Write
#Description
Add a new certificate or update an existing one.
References #
Microsoft.Web/connectionGateways/Associate/Action
#Description
Associates with a Connection Gateway.
References #
Microsoft.Web/connectionGateways/ListStatus/Action
#Description
Lists status of a Connection Gateway.
References #
Microsoft.Web/connectionGateways/Write
#Description
Creates or updates a Connection Gateway.
References #
Microsoft.Web/connections/accessPolicies/Delete
#Description
Deletes Connection Access Policies.
References #
Microsoft.Web/connections/accessPolicies/Write
#Description
Add or Update Connection Access Policies.
References #
microsoft.web/connections/confirmconsentcode/action
#Description
Confirm Connections Consent Code.
References #
Microsoft.Web/connections/Delete
#Description
Deletes a Connection.
Example Resource Log Record #
{
"TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
"SourceSystem": "Azure",
"CallerIpAddress": "37.142.150.162",
"CategoryValue": "Administrative",
"CorrelationId": "af709074-16dd-47b6-bf04-f159bc0a0fb1",
"Authorization": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
"action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
"action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"OperationNameValue": "MICROSOFT.WEB/CONNECTIONS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/connections/azuresentinel-Create-ReslientIncident",
"message": "Microsoft.Web/connections/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "efcc6aed-66df-4275-af35-d193fa592064",
"eventSubmissionTimestamp": "2021-04-28T14:44:00.7229035Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "azuresentinel-create-reslientincident",
"resourceGroup": "BTPOC",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/connections/azuresentinel-Create-ReslientIncident",
"message": "Microsoft.Web/connections/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "efcc6aed-66df-4275-af35-d193fa592064",
"eventSubmissionTimestamp": "2021-04-28T14:44:00.7229035Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "azuresentinel-create-reslientincident",
"resourceGroup": "BTPOC",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"activityStatusValue": "Success"
},
"Caller": "AdeleV@M365x816222.OnMicrosoft.com",
"EventDataId": "efcc6aed-66df-4275-af35-d193fa592064",
"EventSubmissionTimestamp": "4/28/2021, 2:44:00.722 PM",
"HTTPRequest": {
"clientIpAddress": "37.142.150.162"
},
"ResourceGroup": "BTPOC",
"ResourceProviderValue": "MICROSOFT.WEB",
"ActivityStatusValue": "Success",
"Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"TimeGenerated": "4/28/2021, 2:44:00.722 PM",
"SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"Type": "AzureActivity"
}
References #
microsoft.web/connections/listConnectionKeys/action
#Description
Lists API Connections Keys.
References #
microsoft.web/connections/listconsentlinks/action
#Description
List Consent Links for Connections.
References #
microsoft.web/connections/revokeConnectionKeys/action
#Description
Revokes API Connections Keys.
References #
Microsoft.Web/connectorGateways/action
#Description
Performs an action on an Connector Gateway
References #
Microsoft.Web/connectorGateways/connections/accessPolicies/action
#Description
Performs an action on a Connector Gateway Connection Access Policy
References #
Microsoft.Web/connectorGateways/connections/accessPolicies/delete
#Description
Deletes an existing Connector Gateway Connection Access Policy
References #
Microsoft.Web/connectorGateways/connections/accessPolicies/write
#Description
Creates a new Connector Gateway Connection Access Policy or updates an existing one
References #
Microsoft.Web/connectorGateways/connections/action
#Description
Perform an action on an Connector Gateway Connection
References #
Microsoft.Web/connectorGateways/connections/delete
#Description
Delete an existing Connector Gateway Connection
References #
Microsoft.Web/connectorGateways/connections/write
#Description
Creates a new Connector Gateway Connection or updates an existing one
References #
Microsoft.Web/connectorGateways/customConnectors/action
#Description
Performs an action on a Connector Gateway Custom Connector
References #
Microsoft.Web/connectorGateways/customConnectors/delete
#Description
Deletes an existing Connector Gateway Custom Connector
References #
Microsoft.Web/connectorGateways/customConnectors/write
#Description
Creates a new Connector Gateway Custom Connector or updates an existing one
References #
Microsoft.Web/connectorGateways/mcpserverconfigs/action
#Description
Perform an action on an Connector Gateway MCP Server Config
References #
Microsoft.Web/connectorGateways/mcpserverconfigs/delete
#Description
Delete an existing Connector Gateway MCP Server Config
References #
Microsoft.Web/connectorGateways/mcpserverconfigs/write
#Description
Create a new Connector Gateway MCP Server Config or update an existing one
References #
Microsoft.Web/connectorGateways/triggerconfigs/action
#Description
Perform an action on an Connector Gateway Trigger Config
References #
Microsoft.Web/connectorGateways/triggerconfigs/write
#Description
Create a new Connector Gateway Trigger Config or update an existing one
References #
Microsoft.Web/connectorGateways/write
#Description
Creates a new Connector Gateway or updates an existing one
References #
Microsoft.Web/containerApps/revisions/activate/action
#Description
Activate a Container App Revision
References #
Microsoft.Web/containerApps/revisions/deactivate/action
#Description
Deactivate a Container App Revision
References #
Microsoft.Web/containerApps/revisions/deactivate/restart/action
#Description
Restart a Container App Revision
References #
Microsoft.Web/containerApps/sourcecontrols/delete
#Description
Delete a Container App Source Control
References #
Microsoft.Web/containerApps/sourcecontrols/write
#Description
Create or Update a Container App Source Control
References #
Microsoft.Web/containerApps/write
#Description
Create a Container App or update an existing one
References #
Microsoft.Web/customApis/Delete
#Description
Deletes a Custom API.
Example Resource Log Record #
{
"TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
"SourceSystem": "Azure",
"CallerIpAddress": "37.142.150.162",
"CategoryValue": "Administrative",
"CorrelationId": "af709074-16dd-47b6-bf04-f159bc0a0fb1",
"Authorization": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
"action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
"action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"OperationNameValue": "MICROSOFT.WEB/CUSTOMAPIS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/customApis/Resilent",
"message": "Microsoft.Web/customApis/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "a2594dff-d22d-42c1-b1e7-37184a3f0683",
"eventSubmissionTimestamp": "2021-04-28T14:44:00.317969Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "resilent",
"resourceGroup": "BTPOC",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/customApis/Resilent",
"message": "Microsoft.Web/customApis/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "a2594dff-d22d-42c1-b1e7-37184a3f0683",
"eventSubmissionTimestamp": "2021-04-28T14:44:00.3179690Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "resilent",
"resourceGroup": "BTPOC",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"activityStatusValue": "Success"
},
"Caller": "AdeleV@M365x816222.OnMicrosoft.com",
"EventDataId": "a2594dff-d22d-42c1-b1e7-37184a3f0683",
"EventSubmissionTimestamp": "4/28/2021, 2:44:00.317 PM",
"HTTPRequest": {
"clientIpAddress": "37.142.150.162"
},
"ResourceGroup": "BTPOC",
"ResourceProviderValue": "MICROSOFT.WEB",
"ActivityStatusValue": "Success",
"Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"TimeGenerated": "4/28/2021, 2:44:00.317 PM",
"SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"Type": "AzureActivity"
}
References #
Microsoft.Web/customApis/extractApiDefinitionFromWsdl/Action
#Description
Extracts API definition from a WSDL.
References #
Microsoft.Web/customApis/listWsdlInterfaces/Action
#Description
Lists WSDL interfaces for a Custom API.
References #
Microsoft.Web/freeTrialStaticWebApps/delete
#Description
Deletes a free trial static web app.
References #
Microsoft.Web/freeTrialStaticWebApps/upgrade/action
#Description
Upgrades a free trial static web app.
References #
Microsoft.Web/freeTrialStaticWebApps/write
#Description
Creates or updates a free trial static web app.
References #
Microsoft.Web/hostingEnvironments/configurations/networking/Write
#Description
Update networking configuration of an App Service Environment.
References #
microsoft.web/hostingenvironments/configurations/write
#Description
Update Hosting Environment Configurations.
References #
Microsoft.Web/hostingEnvironments/eventGridFilters/delete
#Description
Delete Event Grid Filter on hosting environment.
References #
Microsoft.Web/hostingEnvironments/eventGridFilters/write
#Description
Put Event Grid Filter on hosting environment.
References #
Microsoft.Web/hostingEnvironments/Join/Action
#Description
Joins an App Service Environment
References #
Microsoft.Web/hostingEnvironments/multiRolePools/Write
#Description
Create a new FrontEnd Pool in an App Service Environment or update an existing one
References #
Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/Delete
#Description
Delete Private Endpoint Connection Proxies
References #
Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/validate/action
#Description
Validate Private Endpoint Connection Proxies
References #
Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/Write
#Description
Create or Update Private Endpoint Connection Proxies
References #
Microsoft.Web/hostingEnvironments/privateEndpointConnections/Delete
#Description
Delete a private endpoint connection.
References #
Microsoft.Web/hostingEnvironments/privateEndpointConnections/Write
#Description
Approve or Reject a private endpoint connection.
References #
Microsoft.Web/hostingEnvironments/PrivateEndpointConnectionsApproval/action
#Description
Approve Private Endpoint Connections
References #
microsoft.web/hostingenvironments/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
References #
Microsoft.Web/hostingEnvironments/reboot/Action
#Description
Reboot all machines in an App Service Environment
References #
microsoft.web/hostingenvironments/suspend/action
#Description
Suspend Hosting Environments.
References #
Microsoft.Web/hostingEnvironments/testUpgradeAvailableNotification/Action
#Description
Send test upgrade notification for an App Service Environment
References #
Microsoft.Web/hostingEnvironments/upgrade/Action
#Description
Upgrades an App Service Environment
References #
Microsoft.Web/hostingEnvironments/workerPools/Write
#Description
Create a new Worker Pool in an App Service Environment or update an existing one
References #
Microsoft.Web/hostingEnvironments/Write
#Description
Create a new App Service Environment or update existing one
References #
Microsoft.Web/kubeEnvironments/write
#Description
Create a Kubernetes Environment or update an existing one
References #
microsoft.web/locations/deleteVirtualNetworkOrSubnets/action
#Description
Vnet or subnet deletion notification for Locations.
References #
microsoft.web/locations/extractapidefinitionfromwsdl/action
#Description
Extract Api Definition from WSDL for Locations.
References #
Microsoft.Web/locations/GetNetworkPolicies/action
#Description
Read Network Intent Policies
References #
microsoft.web/locations/listwsdlinterfaces/action
#Description
List WSDL Interfaces for Locations.
References #
Microsoft.Web/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action
#Description
Notify Network Security Perimeter Updates.
References #
microsoft.web/locations/validateDeleteVirtualNetworkOrSubnets/action
#Description
Validates deleting Vnet or subnet for Locations
References #
microsoft.web/register/action
#Description
Register Microsoft.Web resource provider for the subscription.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.Web/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.Web/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "d77d1270-e142-4ecf-982c-41db1e56da41",
"EventDataId": "217bc897-a511-f786-858b-5cb7901df517",
"EventSubmissionTimestamp": "2026-07-02T17:17:03.7333834Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.WEB/REGISTER/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Web",
"message": "Microsoft.Web/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "217bc897-a511-f786-858b-5cb7901df517",
"eventSubmissionTimestamp": "2026-07-02T17:17:03.7333834Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Web",
"message": "Microsoft.Web/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "217bc897-a511-f786-858b-5cb7901df517",
"eventSubmissionTimestamp": "2026-07-02T17:17:03.7333834Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"ResourceProviderValue": "MICROSOFT.WEB",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Web/serverfarms/Delete
#Description
Delete an existing App Service Plan
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
"action": "Microsoft.Web/serverfarms/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
"action": "Microsoft.Web/serverfarms/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "df3bdc41-70ab-4f0f-a039-d3f45be1a25b",
"EventDataId": "f407f2ee-37e4-eb64-5a10-d91f560a8e8d",
"EventSubmissionTimestamp": "2026-07-02T17:28:47.3967714Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.WEB/SERVERFARMS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/serverFarms/dwh92eef0appplan",
"message": "Microsoft.Web/serverFarms/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "f407f2ee-37e4-eb64-5a10-d91f560a8e8d",
"eventSubmissionTimestamp": "2026-07-02T17:28:47.3967714Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0appplan",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/serverFarms/dwh92eef0appplan",
"message": "Microsoft.Web/serverFarms/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "f407f2ee-37e4-eb64-5a10-d91f560a8e8d",
"eventSubmissionTimestamp": "2026-07-02T17:28:47.3967714Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0appplan",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.WEB",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Web/serverfarms/eventGridFilters/delete
#Description
Delete Event Grid Filter on server farm.
References #
Microsoft.Web/serverfarms/eventGridFilters/write
#Description
Put Event Grid Filter on server farm.
References #
microsoft.web/serverfarms/firstpartyapps/keyvaultsettings/write
#Description
Create or Update App Service Plan Key Vault first party settings
References #
microsoft.web/serverfarms/firstpartyapps/settings/delete
#Description
Delete App Service Plans First Party Apps Settings
References #
microsoft.web/serverfarms/firstpartyapps/settings/write
#Description
Update App Service Plans First Party Apps Settings
References #
microsoft.web/serverfarms/hybridconnectionnamespaces/relays/delete
#Description
Delete App Service Plans Hybrid Connection Namespaces Relays.
References #
microsoft.web/serverfarms/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
References #
Microsoft.Web/serverfarms/restartSites/Action
#Description
Restart all Web Apps in an App Service Plan
References #
Microsoft.Web/serverfarms/startSites/Action
#Description
Start all Apps in an App Service Plan
References #
Microsoft.Web/serverfarms/stopSites/Action
#Description
Stop all Apps in an App Service Plan
References #
microsoft.web/serverfarms/virtualnetworkconnections/gateways/write
#Description
Update App Service Plans Virtual Network Connections Gateways.
References #
microsoft.web/serverfarms/virtualnetworkconnections/routes/delete
#Description
Delete App Service Plans Virtual Network Connections Routes.
References #
microsoft.web/serverfarms/virtualnetworkconnections/routes/write
#Description
Update App Service Plans Virtual Network Connections Routes.
References #
microsoft.web/serverfarms/workers/reboot/action
#Description
Reboot App Service Plans Workers.
References #
Microsoft.Web/serverfarms/Write
#Description
Create a new App Service Plan or update an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
"action": "Microsoft.Web/serverfarms/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
"action": "Microsoft.Web/serverfarms/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "9e625b44-bb76-4761-a3a4-dfa50496b39d",
"EventDataId": "8349aaa6-78a7-1791-5191-76f35484f791",
"EventSubmissionTimestamp": "2026-07-02T17:18:43.8626993Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.WEB/SERVERFARMS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
"message": "Microsoft.Web/serverfarms/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "8349aaa6-78a7-1791-5191-76f35484f791",
"eventSubmissionTimestamp": "2026-07-02T17:18:43.8626993Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0appplan",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
"message": "Microsoft.Web/serverfarms/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "8349aaa6-78a7-1791-5191-76f35484f791",
"eventSubmissionTimestamp": "2026-07-02T17:18:43.8626993Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0appplan",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.WEB",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Web/sites/applySlotConfig/Action
#Description
Apply web app slot configuration from target slot to the current web app
References #
microsoft.web/sites/backups/action
#Description
Discovers an existing app backup that can be restored from a blob in Azure storage.
References #
Microsoft.Web/sites/basicPublishingCredentialsPolicies/Write
#Description
List which publishing methods are allowed for a Web App
References #
Microsoft.Web/sites/config/list/Action
#Description
List Web App's security sensitive settings, such as publishing credentials, app settings and connection strings
References #
microsoft.web/sites/config/snapshots/listsecrets/action
#Description
Web Apps List Secrets From Snapshot.
References #
microsoft.web/sites/config/web/appsettings/delete
#Description
Delete Web Apps App Setting
References #
microsoft.web/sites/config/web/appsettings/write
#Description
Create or Update Web App Single App setting
References #
microsoft.web/sites/config/web/connectionstrings/delete
#Description
Delete Web App single connection string
References #
microsoft.web/sites/config/web/connectionstrings/write
#Description
Get Web App single App setting.
References #
microsoft.web/sites/containerlogs/action
#Description
Get Zipped Container Logs for Web App.
References #
microsoft.web/sites/containerlogs/download/action
#Description
Download Web Apps Container Logs.
References #
microsoft.web/sites/continuouswebjobs/delete
#Description
Delete Web Apps Continuous Web Jobs.
References #
microsoft.web/sites/continuouswebjobs/start/action
#Description
Start Web Apps Continuous Web Jobs.
References #
microsoft.web/sites/continuouswebjobs/stop/action
#Description
Stop Web Apps Continuous Web Jobs.
References #
Microsoft.Web/sites/Delete
#Description
Delete an existing Web App
Example Resource Log Record #
{
"TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
"SourceSystem": "Azure",
"CallerIpAddress": "37.142.150.162",
"CategoryValue": "Administrative",
"CorrelationId": "a2bba39a-d17f-404d-9919-e59039e73ad4",
"Authorization": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new",
"action": "Microsoft.Web/sites/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Authorization_d": {
"evidence": {
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalType": "User",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"role": "Contributor"
},
"action": "Microsoft.Web/sites/delete",
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new"
},
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619619948",
"nbf": "1619619948",
"exp": "1619623848",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAARk47FymlkYjF8aD5qw9R6mifAuz/IGhhTRBHWebW9HOR9MgLKM4YcDn72FFfKrZz",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "thrQim_Tb0K8ZxSi9VWAAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"Claims_d": {
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"xms_tcdt": "1591748537",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"nbf": "1619619948",
"exp": "1619623848",
"aio": "ATQAy/8TAAAARk47FymlkYjF8aD5qw9R6mifAuz/IGhhTRBHWebW9HOR9MgLKM4YcDn72FFfKrZz",
"uti": "thrQim_Tb0K8ZxSi9VWAAQ",
"ver": "1.0",
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619619948",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"puid": "10032000C757D25F"
},
"OperationNameValue": "MICROSOFT.WEB/SITES/DELETE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "c5b3981e-03ba-4e01-9703-1de27cb9218f",
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new",
"message": "Microsoft.Web/sites/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "bd53ca1f-63d8-4886-9a3e-6869172bd5f2",
"eventSubmissionTimestamp": "2021-04-28T14:31:40.3331458Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "okta-new",
"resourceGroup": "SENTINEL-MAINRG",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventSubmissionTimestamp": "2021-04-28T14:31:40.3331458Z",
"resourceProviderValue": "MICROSOFT.WEB",
"activityStatusValue": "Success",
"subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"eventCategory": "Administrative",
"resourceGroup": "SENTINEL-MAINRG",
"eventDataId": "bd53ca1f-63d8-4886-9a3e-6869172bd5f2",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"activitySubstatusValue": "OK",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"resource": "okta-new",
"serviceRequestId": "c5b3981e-03ba-4e01-9703-1de27cb9218f",
"message": "Microsoft.Web/sites/delete",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new",
"statusCode": "OK"
},
"Caller": "AdeleV@M365x816222.OnMicrosoft.com",
"EventDataId": "bd53ca1f-63d8-4886-9a3e-6869172bd5f2",
"EventSubmissionTimestamp": "4/28/2021, 2:31:40.333 PM",
"HTTPRequest": {
"clientIpAddress": "37.142.150.162"
},
"ResourceGroup": "SENTINEL-MAINRG",
"ResourceProviderValue": "MICROSOFT.WEB",
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"TimeGenerated": "4/28/2021, 2:31:40.333 PM",
"SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"Type": "AzureActivity"
}
References #
microsoft.web/sites/deployWorkflowArtifacts/action
#Description
Create the artifacts in a Logic App.
References #
microsoft.web/sites/diagnostics/analyses/execute/Action
#Description
Run Web Apps Diagnostics Analysis.
References #
microsoft.web/sites/diagnostics/detectors/execute/Action
#Description
Run Web Apps Diagnostics Detector.
References #
microsoft.web/sites/domainownershipidentifiers/delete
#Description
Delete Web Apps Domain Ownership Identifiers.
References #
Microsoft.Web/sites/eventGridFilters/delete
#Description
Delete Event Grid Filter on web app.
References #
microsoft.web/sites/extensions/api/action
#Description
Invoke App Service Extensions APIs.
References #
microsoft.web/sites/host/functionkeys/delete
#Description
Delete Functions Host Function keys.
References #
microsoft.web/sites/host/functionkeys/write
#Description
Update Functions Host Function keys.
References #
microsoft.web/sites/host/listsyncstatus/action
#Description
List Sync Function Triggers Status.
References #
microsoft.web/sites/host/systemkeys/delete
#Description
Delete Functions Host System keys.
References #
microsoft.web/sites/hostnamebindings/delete
#Description
Delete Web Apps Hostname Bindings.
References #
microsoft.web/sites/hostnamebindings/write
#Description
Update Web Apps Hostname Bindings.
References #
Microsoft.Web/sites/hostruntime/host/action
#Description
Perform Function App runtime action like sync triggers, add functions, invoke functions, delete functions etc.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1059, T1651
References #
microsoft.web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/action
#Description
Get Web Apps Hostruntime Workflow Trigger Uri.
References #
microsoft.web/sites/hostruntime/webhooks/api/workflows/triggers/run/action
#Description
Run Web Apps Hostruntime Workflow Trigger.
References #
microsoft.web/sites/hybridconnection/delete
#Description
Delete Web Apps Hybrid Connection.
References #
microsoft.web/sites/hybridconnection/write
#Description
Update Web Apps Hybrid Connection.
References #
microsoft.web/sites/hybridconnectionnamespaces/relays/delete
#Description
Delete Web Apps Hybrid Connection Namespaces Relays.
References #
microsoft.web/sites/hybridconnectionnamespaces/relays/listkeys/action
#Description
List Keys Web Apps Hybrid Connection Namespaces Relays.
References #
microsoft.web/sites/hybridconnectionnamespaces/relays/write
#Description
Update Web Apps Hybrid Connection Namespaces Relays.
References #
microsoft.web/sites/instances/deployments/delete
#Description
Delete Web Apps Instances Deployments.
References #
microsoft.web/sites/instances/processes/delete
#Description
Delete Web Apps Instances Processes.
References #
microsoft.web/sites/instances/processes/stop/action
#Description
Stop Web Apps Instances Processes.
References #
Microsoft.Web/Sites/joinPerimeter/action
#Description
Determines if a user is allowed to associate an Azure Web App with a Network Security Perimeter.
References #
microsoft.web/sites/listsyncfunctiontriggerstatus/action
#Description
List Sync Function Trigger Status.
References #
microsoft.web/sites/listworkflowsconnections/action
#Description
List logic app's connections by its ID in a Logic App.
References #
microsoft.web/sites/networkConfig/delete
#Description
Delete App Service Network Configuration.
References #
microsoft.web/sites/networkConfig/write
#Description
Update App Service Network Configuration.
References #
Microsoft.Web/Sites/networkSecurityPerimeterAssociationProxies/delete
#Description
Delete Web App Network Security Perimeter Association Proxies.
References #
Microsoft.Web/Sites/networkSecurityPerimeterAssociationProxies/write
#Description
Create or Update Web App Network Security Perimeter Association Proxies.
References #
Microsoft.Web/Sites/networkSecurityPerimeterConfigurations/action
#Description
Reconcile Web App Network Security Perimeter Configurations.
References #
Microsoft.Web/sites/privateEndpointConnectionProxies/Delete
#Description
Delete Private Endpoint Connection Proxies
References #
Microsoft.Web/sites/privateEndpointConnectionProxies/validate/action
#Description
Validate Private Endpoint Connection Proxies
References #
Microsoft.Web/sites/privateEndpointConnectionProxies/Write
#Description
Create or Update Private Endpoint Connection Proxies
References #
Microsoft.Web/sites/privateEndpointConnections/Write
#Description
Approve or Reject a private endpoint connection.
References #
Microsoft.Web/sites/PrivateEndpointConnectionsApproval/action
#Description
Approve Private Endpoint Connections
References #
microsoft.web/sites/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
References #
microsoft.web/sites/publiccertificates/delete
#Description
Delete Web Apps Public Certificates.
References #
microsoft.web/sites/publiccertificates/write
#Description
Update Web Apps Public Certificates.
References #
Microsoft.Web/sites/publishxml/Action
#Description
Get publishing profile xml for a Web App
References #
microsoft.web/sites/recommendations/disable/action
#Description
Disable Web Apps Recommendations.
References #
microsoft.web/sites/restorefrombackupblob/action
#Description
Restore Web App From Backup Blob.
References #
microsoft.web/sites/restorefromdeletedapp/action
#Description
Restore Web Apps From Deleted App.
References #
Microsoft.Web/sites/sitecontainers/Delete
#Description
Delete Sitecontainers of an existing Web App
References #
Microsoft.Web/sites/sitecontainers/Write
#Description
Create new Sitecontainers or update existing ones for a Web App
References #
Microsoft.Web/sites/slots/applySlotConfig/Action
#Description
Apply web app slot configuration from target slot to the current slot.
References #
microsoft.web/sites/slots/backups/restore/action
#Description
Restore Web Apps Slots Backups.
References #
Microsoft.Web/sites/slots/basicPublishingCredentialsPolicies/Write
#Description
List which publishing credentials are allowed for a Web App Slot
References #
microsoft.web/sites/slots/config/appsettings/write
#Description
Create or Update Web App Slot's Single App setting
References #
Microsoft.Web/sites/slots/config/list/Action
#Description
List Web App Slot's security sensitive settings, such as publishing credentials, app settings and connection strings
References #
microsoft.web/sites/slots/config/snapshots/listsecrets/action
#Description
Web Apps List Slot Secrets From Snapshot.
References #
microsoft.web/sites/slots/config/validateupgradepath/action
#Description
Validate upgrade path for Web App.
References #
microsoft.web/sites/slots/config/web/appsettings/delete
#Description
Delete Web App Slot's App Setting
References #
microsoft.web/sites/slots/config/web/connectionstrings/delete
#Description
Delete Web App slot's single connection string
References #
microsoft.web/sites/slots/config/web/connectionstrings/write
#Description
Create or Update Web App Slot's single sonnection string
References #
Microsoft.Web/sites/slots/config/Write
#Description
Update Web App Slot's configuration settings
References #
microsoft.web/sites/slots/containerlogs/action
#Description
Get Zipped Container Logs for Web App Slot.
References #
microsoft.web/sites/slots/containerlogs/download/action
#Description
Download Web Apps Slots Container Logs.
References #
microsoft.web/sites/slots/continuouswebjobs/delete
#Description
Delete Web Apps Slots Continuous Web Jobs.
References #
microsoft.web/sites/slots/continuouswebjobs/start/action
#Description
Start Web Apps Slots Continuous Web Jobs.
References #
microsoft.web/sites/slots/continuouswebjobs/stop/action
#Description
Stop Web Apps Slots Continuous Web Jobs.
References #
microsoft.web/sites/slots/deployments/delete
#Description
Delete Web Apps Slots Deployments.
References #
microsoft.web/sites/slots/deployments/write
#Description
Update Web Apps Slots Deployments.
References #
microsoft.web/sites/slots/deployWorkflowArtifacts/action
#Description
Create the artifacts in a deployment slot in a Logic App.
References #
microsoft.web/sites/slots/diagnostics/analyses/execute/Action
#Description
Run Web Apps Slots Diagnostics Analysis.
References #
microsoft.web/sites/slots/diagnostics/detectors/execute/Action
#Description
Run Web Apps Slots Diagnostics Detector.
References #
microsoft.web/sites/slots/domainownershipidentifiers/delete
#Description
Delete Web App Slots Domain Ownership Identifiers.
References #
microsoft.web/sites/slots/extensions/api/action
#Description
Invoke App Service Slots Extensions APIs.
References #
microsoft.web/sites/slots/functions/listsecrets/action
#Description
List Secrets Web Apps Slots Functions.
References #
microsoft.web/sites/slots/host/functionkeys/delete
#Description
Delete Functions Host Function keys.
References #
microsoft.web/sites/slots/host/functionkeys/write
#Description
Update Functions Host Function keys.
References #
microsoft.web/sites/slots/host/systemkeys/delete
#Description
Delete Functions Host System keys.
References #
microsoft.web/sites/slots/host/systemkeys/write
#Description
Update Functions Host System keys.
References #
microsoft.web/sites/slots/hostnamebindings/delete
#Description
Delete Web Apps Slots Hostname Bindings.
References #
microsoft.web/sites/slots/hostnamebindings/write
#Description
Update Web Apps Slots Hostname Bindings.
References #
microsoft.web/sites/slots/hybridconnection/delete
#Description
Delete Web Apps Slots Hybrid Connection.
References #
microsoft.web/sites/slots/hybridconnection/write
#Description
Update Web Apps Slots Hybrid Connection.
References #
microsoft.web/sites/slots/hybridconnectionnamespaces/relays/delete
#Description
Delete Web Apps Slots Hybrid Connection Namespaces Relays.
References #
microsoft.web/sites/slots/hybridconnectionnamespaces/relays/write
#Description
Update Web Apps Slots Hybrid Connection Namespaces Relays.
References #
microsoft.web/sites/slots/instances/processes/delete
#Description
Delete Web Apps Slots Instances Processes.
References #
microsoft.web/sites/slots/instances/processes/stop/action
#Description
Stop Web Apps Slots Instances Processes.
References #
microsoft.web/sites/slots/listsyncfunctiontriggerstatus/action
#Description
List Sync Function Trigger Status for deployment slot.
References #
microsoft.web/sites/slots/listworkflowsconnections/action
#Description
List logic app's connections by its ID in a deployment slot in a Logic App.
References #
microsoft.web/sites/slots/networkConfig/delete
#Description
Delete App Service Slots Network Configuration.
References #
microsoft.web/sites/slots/networkConfig/write
#Description
Update App Service Slots Network Configuration.
References #
microsoft.web/sites/slots/premieraddons/delete
#Description
Delete Web Apps Slots Premier Addons.
References #
microsoft.web/sites/slots/premieraddons/write
#Description
Update Web Apps Slots Premier Addons.
References #
microsoft.web/sites/slots/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource
References #
microsoft.web/sites/slots/publiccertificates/delete
#Description
Delete Web Apps Slots Public Certificates.
References #
microsoft.web/sites/slots/publiccertificates/write
#Description
Create or Update Web Apps Slots Public Certificates.
References #
Microsoft.Web/sites/slots/publishxml/Action
#Description
Get publishing profile xml for Web App Slot
References #
Microsoft.Web/sites/slots/resetSlotConfig/Action
#Description
Reset web app slot configuration
References #
microsoft.web/sites/slots/restorefrombackupblob/action
#Description
Restore Web Apps Slot From Backup Blob.
References #
microsoft.web/sites/slots/restorefromdeletedapp/action
#Description
Restore Web App Slots From Deleted App.
References #
microsoft.web/sites/slots/restoresnapshot/action
#Description
Restore Web Apps Slots Snapshots.
References #
Microsoft.Web/sites/slots/sitecontainers/Delete
#Description
Delete Sitecontainers of an existing Web App's Slot
References #
Microsoft.Web/sites/slots/sitecontainers/Write
#Description
Create new or update existing Sitecontainers of a Web App's Slot
References #
microsoft.web/sites/slots/siteextensions/delete
#Description
Delete Web Apps Slots Site Extensions.
References #
microsoft.web/sites/slots/siteextensions/write
#Description
Update Web Apps Slots Site Extensions.
References #
microsoft.web/sites/slots/slotcopy/action
#Description
Copy content from one deployment slot to another.
References #
Microsoft.Web/sites/slots/slotsdiffs/Action
#Description
Get differences in configuration between web app and slots
References #
Microsoft.Web/sites/slots/sourcecontrols/Delete
#Description
Delete Web App Slot's source control configuration settings
References #
Microsoft.Web/sites/slots/startDevSession/Action
#Description
Start Dev Session for Web App Slot
References #
microsoft.web/sites/slots/syncfunctiontriggers/action
#Description
Sync Function Triggers for deployment slot.
References #
microsoft.web/sites/slots/triggeredwebjobs/delete
#Description
Delete Web Apps Slots Triggered WebJobs.
References #
microsoft.web/sites/slots/triggeredwebjobs/run/action
#Description
Run Web Apps Slots Triggered WebJobs.
References #
microsoft.web/sites/slots/virtualnetworkconnections/delete
#Description
Delete Web Apps Slots Virtual Network Connections.
References #
microsoft.web/sites/slots/virtualnetworkconnections/gateways/write
#Description
Update Web Apps Slots Virtual Network Connections Gateways.
References #
microsoft.web/sites/slots/virtualnetworkconnections/write
#Description
Update Web Apps Slots Virtual Network Connections.
References #
Microsoft.Web/sites/slots/Write
#Description
Create a new Web App Slot or update an existing one
References #
Microsoft.Web/sites/slotsdiffs/Action
#Description
Get differences in configuration between web app and slots
References #
Microsoft.Web/sites/sourcecontrols/Delete
#Description
Delete Web App's source control configuration settings
References #
Microsoft.Web/sites/sourcecontrols/Write
#Description
Update Web App's source control configuration settings
References #
microsoft.web/sites/triggeredwebjobs/delete
#Description
Delete Web Apps Triggered WebJobs.
References #
microsoft.web/sites/triggeredwebjobs/run/action
#Description
Run Web Apps Triggered WebJobs.
References #
microsoft.web/sites/virtualnetworkconnections/delete
#Description
Delete Web Apps Virtual Network Connections.
References #
microsoft.web/sites/virtualnetworkconnections/gateways/write
#Description
Update Web Apps Virtual Network Connections Gateways.
References #
microsoft.web/sites/virtualnetworkconnections/write
#Description
Update Web Apps Virtual Network Connections.
References #
Microsoft.Web/staticSites/authproviders/listusers/Action
#Description
List the users for a Static Site
References #
Microsoft.Web/staticSites/authproviders/users/Delete
#Description
Delete a user for a Static Site
References #
Microsoft.Web/staticSites/authproviders/users/Write
#Description
Update a user for a Static Site
References #
Microsoft.Web/staticSites/builds/config/Write
#Description
Create or update app settings for a Static Site Build
References #
Microsoft.Web/staticSites/builds/databaseConnections/Delete
#Description
Delete a Database Connection from a Static Site Build
References #
Microsoft.Web/staticSites/builds/databaseConnections/show/action
#Description
Show details for a Database Connection for a Static Site Build
References #
Microsoft.Web/staticSites/builds/databaseConnections/Write
#Description
Create or Update a Database Connection with a Static Site Build
References #
Microsoft.Web/staticSites/builds/linkedBackends/Delete
#Description
Unlink a Backend from a Static Site Build
References #
Microsoft.Web/staticSites/builds/linkedBackends/validate/action
#Description
Validate a Linked Backend for a Static Site Build
References #
Microsoft.Web/staticSites/builds/linkedBackends/Write
#Description
Register a Linked Backend with a Static Site Build
References #
Microsoft.Web/staticSites/builds/listappsettings/Action
#Description
List app settings for a Static Site Build
References #
Microsoft.Web/staticSites/builds/listfunctionappsettings/Action
#Description
List function app settings for a Static Site Build
References #
Microsoft.Web/staticSites/builds/showDatabaseConnections/action
#Description
Show details for Database Connections for a Static Site Build
References #
Microsoft.Web/staticSites/builds/userProvidedFunctionApps/Delete
#Description
Detach a User Provided Function App from a Static Site Build
References #
Microsoft.Web/staticSites/builds/userProvidedFunctionApps/Write
#Description
Register a User Provided Function App with a Static Site Build
References #
Microsoft.Web/staticSites/builds/zipdeploy/action
#Description
Deploy a Static Site Build from zipped content
References #
Microsoft.Web/staticSites/config/Write
#Description
Create or update app settings for a Static Site
References #
Microsoft.Web/staticSites/createinvitation/action
#Description
Creates invitiation link for static site user for a set of roles
References #
Microsoft.Web/staticSites/customdomains/Delete
#Description
Delete a custom domain for a Static Site
References #
Microsoft.Web/staticSites/customdomains/validate/Action
#Description
Validate a custom domain can be added to a Static Site
References #
Microsoft.Web/staticSites/customdomains/Write
#Description
Create a custom domain for a Static Site
References #
Microsoft.Web/staticSites/databaseConnections/show/action
#Description
Show details for a Database Connection for a Static Site
References #
Microsoft.Web/staticSites/databaseConnections/Write
#Description
Create or Update a Database Connection with a Static Site
References #
Microsoft.Web/staticSites/Delete
#Description
Delete an existing Static Site
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"action": "Microsoft.Web/staticSites/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"action": "Microsoft.Web/staticSites/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "0acaaa56-0c0f-45b4-8a4e-a462fb8c04be",
"EventDataId": "40ab81cd-7f69-e4bc-327b-b7b8a3eeec8c",
"EventSubmissionTimestamp": "2026-07-03T02:16:36.6004923Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.WEB/STATICSITES/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"message": "Microsoft.Web/staticSites/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "40ab81cd-7f69-e4bc-327b-b7b8a3eeec8c",
"eventSubmissionTimestamp": "2026-07-03T02:16:36.6004923Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dstaticsite",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"message": "Microsoft.Web/staticSites/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "40ab81cd-7f69-e4bc-327b-b7b8a3eeec8c",
"eventSubmissionTimestamp": "2026-07-03T02:16:36.6004923Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dstaticsite",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.WEB",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Web/staticSites/detach/Action
#Description
Detach a Static Site from the currently linked repository
References #
Microsoft.Web/staticSites/getuser/Action
#Description
Get a user's information for a Static Site
References #
Microsoft.Web/staticSites/linkedBackends/Delete
#Description
Unlink a Backend from a Static Site
References #
Microsoft.Web/staticSites/linkedBackends/validate/action
#Description
Validate a Linked Backend for a Static Site
References #
Microsoft.Web/staticSites/linkedBackends/Write
#Description
Register a Linked Backend with a Static Site
References #
Microsoft.Web/staticSites/listappsettings/Action
#Description
List app settings for a Static Site
References #
Microsoft.Web/staticSites/listConfiguredRoles/action
#Description
Lists the roles configured for the static site.
References #
Microsoft.Web/staticSites/listfunctionappsettings/Action
#Description
List function app settings for a Static Site
References #
Microsoft.Web/staticSites/listsecrets/action
#Description
List the secrets for a Static Site
References #
Microsoft.Web/staticSites/networkConfigs/Delete
#Description
Disconnects a network configuration from a Static Site
References #
Microsoft.Web/staticSites/networkConfigs/Write
#Description
Updates network configuration for a Static Site
References #
Microsoft.Web/staticSites/privateEndpointConnectionProxies/Delete
#Description
Delete Private Endpoint Connection Proxies for a Static Site
References #
Microsoft.Web/staticSites/privateEndpointConnectionProxies/validate/action
#Description
Validate Private Endpoint Connection Proxies for a Static Site
References #
Microsoft.Web/staticSites/privateEndpointConnectionProxies/Write
#Description
Create or Update Private Endpoint Connection Proxies for a Static Site
References #
Microsoft.Web/staticSites/privateEndpointConnections/Delete
#Description
Delete a Private Endpoint Connection for a Static Site
References #
Microsoft.Web/staticSites/privateEndpointConnections/Write
#Description
Approve or Reject Private Endpoint Connection for a Static Site
References #
Microsoft.Web/staticSites/publish/action
#Description
Check publish access to static web app
References #
Microsoft.Web/staticSites/resetapikey/Action
#Description
Reset the api key for a Static Site
References #
Microsoft.Web/staticSites/showDatabaseConnections/action
#Description
Show details for Database Connections for a Static Site
References #
Microsoft.Web/staticSites/userProvidedFunctionApps/Delete
#Description
Detach a User Provided Function App from a Static Site
References #
Microsoft.Web/staticSites/userProvidedFunctionApps/Write
#Description
Register a User Provided Function App with a Static Site
References #
Microsoft.Web/staticSites/validateCustomDomainOwnership/action
#Description
Validate the custom domain ownership for a static site
References #
Microsoft.Web/staticSites/Write
#Description
Create a new Static Site or update an existing one
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"action": "Microsoft.Web/staticSites/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"action": "Microsoft.Web/staticSites/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "61ccd227-e1e5-4943-9135-05bec6b08e02",
"EventDataId": "b78ec877-ee19-082a-c9e9-04806b9cdc46",
"EventSubmissionTimestamp": "2026-07-03T02:15:31.3370071Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.WEB/STATICSITES/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"message": "Microsoft.Web/staticSites/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "b78ec877-ee19-082a-c9e9-04806b9cdc46",
"eventSubmissionTimestamp": "2026-07-03T02:15:31.3370071Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dstaticsite",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
"message": "Microsoft.Web/staticSites/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "b78ec877-ee19-082a-c9e9-04806b9cdc46",
"eventSubmissionTimestamp": "2026-07-03T02:15:31.3370071Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dstaticsite",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.WEB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.WEB",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
References #
Microsoft.Web/staticSites/zipdeploy/action
#Description
Deploy a Static Site from zipped content
References #
microsoft.web/unregister/action
#Description
Unregister Microsoft.Web resource provider for the subscription.
References #
microsoft.web/verifyhostingenvironmentvnet/action
#Description
Verify Hosting Environment Vnet.