Azure App Service Azure-Microsoft.Web

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Web rules that match the resource provider but no specific operation.NN
microsoft.web/apimanagementaccounts/apis/apiacls/deleteDelete Api Management Accounts APIs Apiacls.NN
microsoft.web/apimanagementaccounts/apis/apiacls/writeUpdate Api Management Accounts APIs Apiacls.NN
microsoft.web/apimanagementaccounts/apis/connections/confirmconsentcode/actionConfirm Consent Code Api Management Accounts APIs Connections.NN
microsoft.web/apimanagementaccounts/apis/connections/connectionacls/deleteDelete Api Management Accounts APIs Connections Connectionacls.NN
microsoft.web/apimanagementaccounts/apis/connections/connectionacls/writeUpdate Api Management Accounts APIs Connections Connectionacls.NN
microsoft.web/apimanagementaccounts/apis/connections/deleteDelete Api Management Accounts APIs Connections.NN
microsoft.web/apimanagementaccounts/apis/connections/getconsentlinks/actionGet Consent Links for Api Management Accounts APIs Connections.NN
microsoft.web/apimanagementaccounts/apis/connections/listconnectionkeys/actionList Connection Keys Api Management Accounts APIs Connections.NN
microsoft.web/apimanagementaccounts/apis/connections/listsecrets/actionList Secrets Api Management Accounts APIs Connections.NN
microsoft.web/apimanagementaccounts/apis/connections/writeUpdate Api Management Accounts APIs Connections.NN
microsoft.web/apimanagementaccounts/apis/deleteDelete Api Management Accounts APIs.NN
microsoft.web/apimanagementaccounts/apis/localizeddefinitions/deleteDelete Api Management Accounts APIs Localized Definitions.NN
microsoft.web/apimanagementaccounts/apis/localizeddefinitions/writeUpdate Api Management Accounts APIs Localized Definitions.NN
microsoft.web/apimanagementaccounts/apis/writeUpdate Api Management Accounts APIs.NN
Microsoft.Web/certificates/DeleteDelete an existing certificate.NN
Microsoft.Web/certificates/WriteAdd a new certificate or update an existing one.NN
Microsoft.Web/connectionGateways/Associate/ActionAssociates with a Connection Gateway.NN
Microsoft.Web/connectionGateways/DeleteDeletes a Connection Gateway.NN
Microsoft.Web/connectionGateways/Join/ActionJoins a Connection Gateway.NN
Microsoft.Web/connectionGateways/ListStatus/ActionLists status of a Connection Gateway.NN
Microsoft.Web/connectionGateways/Move/ActionMoves a Connection Gateway.NN
Microsoft.Web/connectionGateways/WriteCreates or updates a Connection Gateway.NN
Microsoft.Web/connections/accessPolicies/DeleteDeletes Connection Access Policies.NN
Microsoft.Web/connections/accessPolicies/WriteAdd or Update Connection Access Policies.NN
microsoft.web/connections/confirmconsentcode/actionConfirm Connections Consent Code.NN
Microsoft.Web/connections/DeleteDeletes a Connection.YN
microsoft.web/connections/dynamicInvoke/actionDynamic Invoke a Connection.NN
Microsoft.Web/connections/Join/ActionJoins a Connection.NN
microsoft.web/connections/listConnectionKeys/actionLists API Connections Keys.NN
microsoft.web/connections/listconsentlinks/actionList Consent Links for Connections.NN
Microsoft.Web/connections/Move/ActionMoves a Connection.NN
microsoft.web/connections/revokeConnectionKeys/actionRevokes API Connections Keys.NN
Microsoft.Web/connections/WriteCreates or updates a Connection.NN
Microsoft.Web/connectorGateways/actionPerforms an action on an Connector GatewayNN
Microsoft.Web/connectorGateways/connections/accessPolicies/actionPerforms an action on a Connector Gateway Connection Access PolicyNN
Microsoft.Web/connectorGateways/connections/accessPolicies/deleteDeletes an existing Connector Gateway Connection Access PolicyNN
Microsoft.Web/connectorGateways/connections/accessPolicies/writeCreates a new Connector Gateway Connection Access Policy or updates an existing oneNN
Microsoft.Web/connectorGateways/connections/actionPerform an action on an Connector Gateway ConnectionNN
Microsoft.Web/connectorGateways/connections/deleteDelete an existing Connector Gateway ConnectionNN
Microsoft.Web/connectorGateways/connections/writeCreates a new Connector Gateway Connection or updates an existing oneNN
Microsoft.Web/connectorGateways/customConnectors/actionPerforms an action on a Connector Gateway Custom ConnectorNN
Microsoft.Web/connectorGateways/customConnectors/deleteDeletes an existing Connector Gateway Custom ConnectorNN
Microsoft.Web/connectorGateways/customConnectors/writeCreates a new Connector Gateway Custom Connector or updates an existing oneNN
Microsoft.Web/connectorGateways/deleteDeletes an existing Connector GatewayNN
Microsoft.Web/connectorGateways/mcpserverconfigs/actionPerform an action on an Connector Gateway MCP Server ConfigNN
Microsoft.Web/connectorGateways/mcpserverconfigs/deleteDelete an existing Connector Gateway MCP Server ConfigNN
Microsoft.Web/connectorGateways/mcpserverconfigs/writeCreate a new Connector Gateway MCP Server Config or update an existing oneNN
Microsoft.Web/connectorGateways/triggerconfigs/actionPerform an action on an Connector Gateway Trigger ConfigNN
Microsoft.Web/connectorGateways/triggerconfigs/deleteDelete an existing Connector Gateway Trigger ConfigNN
Microsoft.Web/connectorGateways/triggerconfigs/writeCreate a new Connector Gateway Trigger Config or update an existing oneNN
Microsoft.Web/connectorGateways/writeCreates a new Connector Gateway or updates an existing oneNN
Microsoft.Web/containerApps/deleteDelete a Container AppNN
Microsoft.Web/containerApps/listsecrets/actionList a Container App SecretsNN
Microsoft.Web/containerApps/revisions/activate/actionActivate a Container App RevisionNN
Microsoft.Web/containerApps/revisions/deactivate/actionDeactivate a Container App RevisionNN
Microsoft.Web/containerApps/revisions/deactivate/restart/actionRestart a Container App RevisionNN
Microsoft.Web/containerApps/sourcecontrols/deleteDelete a Container App Source ControlNN
Microsoft.Web/containerApps/sourcecontrols/writeCreate or Update a Container App Source ControlNN
Microsoft.Web/containerApps/writeCreate a Container App or update an existing oneNN
Microsoft.Web/customApis/DeleteDeletes a Custom API.YN
Microsoft.Web/customApis/extractApiDefinitionFromWsdl/ActionExtracts API definition from a WSDL.NN
Microsoft.Web/customApis/Join/ActionJoins a Custom API.NN
Microsoft.Web/customApis/listWsdlInterfaces/ActionLists WSDL interfaces for a Custom API.NN
Microsoft.Web/customApis/Move/ActionMoves a Custom API.NN
Microsoft.Web/customApis/WriteCreates or updates a Custom API.NN
Microsoft.Web/freeTrialStaticWebApps/deleteDeletes a free trial static web app.NN
Microsoft.Web/freeTrialStaticWebApps/upgrade/actionUpgrades a free trial static web app.NN
Microsoft.Web/freeTrialStaticWebApps/writeCreates or updates a free trial static web app.NN
Microsoft.Web/hostingEnvironments/configurations/networking/WriteUpdate networking configuration of an App Service Environment.NN
microsoft.web/hostingenvironments/configurations/writeUpdate Hosting Environment Configurations.NN
Microsoft.Web/hostingEnvironments/DeleteDelete an App Service EnvironmentNN
Microsoft.Web/hostingEnvironments/eventGridFilters/deleteDelete Event Grid Filter on hosting environment.NN
Microsoft.Web/hostingEnvironments/eventGridFilters/writePut Event Grid Filter on hosting environment.NN
Microsoft.Web/hostingEnvironments/Join/ActionJoins an App Service EnvironmentNN
Microsoft.Web/hostingEnvironments/multiRolePools/WriteCreate a new FrontEnd Pool in an App Service Environment or update an existing oneNN
Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/DeleteDelete Private Endpoint Connection ProxiesNN
Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/validate/actionValidate Private Endpoint Connection ProxiesNN
Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/WriteCreate or Update Private Endpoint Connection ProxiesNN
Microsoft.Web/hostingEnvironments/privateEndpointConnections/DeleteDelete a private endpoint connection.NN
Microsoft.Web/hostingEnvironments/privateEndpointConnections/WriteApprove or Reject a private endpoint connection.NN
Microsoft.Web/hostingEnvironments/PrivateEndpointConnectionsApproval/actionApprove Private Endpoint ConnectionsNN
microsoft.web/hostingenvironments/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resourceNN
Microsoft.Web/hostingEnvironments/reboot/ActionReboot all machines in an App Service EnvironmentNN
microsoft.web/hostingenvironments/resume/actionResume Hosting Environments.NN
microsoft.web/hostingenvironments/suspend/actionSuspend Hosting Environments.NN
Microsoft.Web/hostingEnvironments/testUpgradeAvailableNotification/ActionSend test upgrade notification for an App Service EnvironmentNN
Microsoft.Web/hostingEnvironments/upgrade/ActionUpgrades an App Service EnvironmentNN
Microsoft.Web/hostingEnvironments/workerPools/WriteCreate a new Worker Pool in an App Service Environment or update an existing oneNN
Microsoft.Web/hostingEnvironments/WriteCreate a new App Service Environment or update existing oneNN
Microsoft.Web/kubeEnvironments/deleteDelete a Kubernetes EnvironmentNN
Microsoft.Web/kubeEnvironments/join/actionJoins a Kubernetes EnvironmentNN
Microsoft.Web/kubeEnvironments/writeCreate a Kubernetes Environment or update an existing oneNN
microsoft.web/locations/deleteVirtualNetworkOrSubnets/actionVnet or subnet deletion notification for Locations.NN
microsoft.web/locations/extractapidefinitionfromwsdl/actionExtract Api Definition from WSDL for Locations.NN
Microsoft.Web/locations/GetNetworkPolicies/actionRead Network Intent PoliciesNN
microsoft.web/locations/listwsdlinterfaces/actionList WSDL Interfaces for Locations.NN
Microsoft.Web/locations/managedapis/Join/ActionJoins a Managed API.NN
Microsoft.Web/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/actionNotify Network Security Perimeter Updates.NN
Microsoft.Web/locations/previewstaticsiteworkflowfile/actionPreview Static Site Workflow FileNN
microsoft.web/locations/validateDeleteVirtualNetworkOrSubnets/actionValidates deleting Vnet or subnet for LocationsNN
microsoft.web/publishingusers/writeUpdate Publishing Users.NN
microsoft.web/register/actionRegister Microsoft.Web resource provider for the subscription.YN
Microsoft.Web/serverfarms/DeleteDelete an existing App Service PlanYN
Microsoft.Web/serverfarms/eventGridFilters/deleteDelete Event Grid Filter on server farm.NN
Microsoft.Web/serverfarms/eventGridFilters/writePut Event Grid Filter on server farm.NN
microsoft.web/serverfarms/firstpartyapps/keyvaultsettings/writeCreate or Update App Service Plan Key Vault first party settingsNN
microsoft.web/serverfarms/firstpartyapps/settings/deleteDelete App Service Plans First Party Apps SettingsNN
microsoft.web/serverfarms/firstpartyapps/settings/writeUpdate App Service Plans First Party Apps SettingsNN
microsoft.web/serverfarms/hybridconnectionnamespaces/relays/deleteDelete App Service Plans Hybrid Connection Namespaces Relays.NN
Microsoft.Web/serverfarms/Join/ActionJoins an App Service PlanNN
microsoft.web/serverfarms/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resourceNN
Microsoft.Web/serverfarms/restartSites/ActionRestart all Web Apps in an App Service PlanNN
Microsoft.Web/serverfarms/startSites/ActionStart all Apps in an App Service PlanNN
Microsoft.Web/serverfarms/stopSites/ActionStop all Apps in an App Service PlanNN
microsoft.web/serverfarms/virtualnetworkconnections/gateways/writeUpdate App Service Plans Virtual Network Connections Gateways.NN
microsoft.web/serverfarms/virtualnetworkconnections/routes/deleteDelete App Service Plans Virtual Network Connections Routes.NN
microsoft.web/serverfarms/virtualnetworkconnections/routes/writeUpdate App Service Plans Virtual Network Connections Routes.NN
microsoft.web/serverfarms/workers/reboot/actionReboot App Service Plans Workers.NN
Microsoft.Web/serverfarms/WriteCreate a new App Service Plan or update an existing oneYN
Microsoft.Web/sites/applySlotConfig/ActionApply web app slot configuration from target slot to the current web appNN
Microsoft.Web/sites/backup/ActionCreate a new web app backupNN
microsoft.web/sites/backup/writeUpdate Web Apps Backup.NN
microsoft.web/sites/backups/actionDiscovers an existing app backup that can be restored from a blob in Azure storage.NN
microsoft.web/sites/backups/deleteDelete Web Apps Backups.NN
microsoft.web/sites/backups/list/actionList Web Apps Backups.NN
microsoft.web/sites/backups/restore/actionRestore Web Apps Backups.NN
microsoft.web/sites/backups/writeUpdate Web Apps Backups.NN
Microsoft.Web/sites/basicPublishingCredentialsPolicies/WriteList which publishing methods are allowed for a Web AppNN
microsoft.web/sites/config/deleteDelete Web Apps Config.NN
Microsoft.Web/sites/config/list/ActionList Web App's security sensitive settings, such as publishing credentials, app settings and connection stringsNN
microsoft.web/sites/config/snapshots/listsecrets/actionWeb Apps List Secrets From Snapshot.NN
microsoft.web/sites/config/web/appsettings/deleteDelete Web Apps App SettingNN
microsoft.web/sites/config/web/appsettings/writeCreate or Update Web App Single App settingNN
microsoft.web/sites/config/web/connectionstrings/deleteDelete Web App single connection stringNN
microsoft.web/sites/config/web/connectionstrings/writeGet Web App single App setting.NN
Microsoft.Web/sites/config/WriteUpdate Web App's configuration settingsNN
microsoft.web/sites/containerlogs/actionGet Zipped Container Logs for Web App.NN
microsoft.web/sites/containerlogs/download/actionDownload Web Apps Container Logs.NN
microsoft.web/sites/continuouswebjobs/deleteDelete Web Apps Continuous Web Jobs.NN
microsoft.web/sites/continuouswebjobs/start/actionStart Web Apps Continuous Web Jobs.NN
microsoft.web/sites/continuouswebjobs/stop/actionStop Web Apps Continuous Web Jobs.NN
Microsoft.Web/sites/DeleteDelete an existing Web AppYN
microsoft.web/sites/deployments/deleteDelete Web Apps Deployments.NN
microsoft.web/sites/deployments/writeUpdate Web Apps Deployments.NN
microsoft.web/sites/deployWorkflowArtifacts/actionCreate the artifacts in a Logic App.NN
microsoft.web/sites/diagnostics/analyses/execute/ActionRun Web Apps Diagnostics Analysis.NN
microsoft.web/sites/diagnostics/detectors/execute/ActionRun Web Apps Diagnostics Detector.NN
microsoft.web/sites/domainownershipidentifiers/deleteDelete Web Apps Domain Ownership Identifiers.NN
microsoft.web/sites/domainownershipidentifiers/writeUpdate Web Apps Domain Ownership Identifiers.NN
Microsoft.Web/sites/eventGridFilters/deleteDelete Event Grid Filter on web app.NN
Microsoft.Web/sites/eventGridFilters/writePut Event Grid Filter on web app.NN
microsoft.web/sites/extensions/api/actionInvoke App Service Extensions APIs.NN
microsoft.web/sites/extensions/deleteDelete Web Apps Site Extensions.NN
microsoft.web/sites/extensions/writeUpdate Web Apps Site Extensions.NN
microsoft.web/sites/functions/actionFunctions Web Apps.NN
microsoft.web/sites/functions/deleteDelete Web Apps Functions.NN
microsoft.web/sites/functions/keys/deleteDelete Function keys.NN
microsoft.web/sites/functions/keys/writeUpdate Function keys.NN
microsoft.web/sites/functions/listkeys/actionList Function keys.NN
microsoft.web/sites/functions/listsecrets/actionList Function secrets.NN
microsoft.web/sites/functions/writeUpdate Web Apps Functions.NN
microsoft.web/sites/host/functionkeys/deleteDelete Functions Host Function keys.NN
microsoft.web/sites/host/functionkeys/writeUpdate Functions Host Function keys.NN
microsoft.web/sites/host/listkeys/actionList Functions Host keys.NN
microsoft.web/sites/host/listsyncstatus/actionList Sync Function Triggers Status.NN
microsoft.web/sites/host/sync/actionSync Function Triggers.NN
microsoft.web/sites/host/systemkeys/deleteDelete Functions Host System keys.NN
microsoft.web/sites/host/systemkeys/writeUpdate Functions Host System keys.NN
microsoft.web/sites/hostnamebindings/deleteDelete Web Apps Hostname Bindings.NN
microsoft.web/sites/hostnamebindings/writeUpdate Web Apps Hostname Bindings.NN
Microsoft.Web/sites/hostruntime/host/actionPerform Function App runtime action like sync triggers, add functions, invoke functions, delete functions etc.NY
microsoft.web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/actionGet Web Apps Hostruntime Workflow Trigger Uri.NN
microsoft.web/sites/hostruntime/webhooks/api/workflows/triggers/run/actionRun Web Apps Hostruntime Workflow Trigger.NN
microsoft.web/sites/hybridconnection/deleteDelete Web Apps Hybrid Connection.NN
microsoft.web/sites/hybridconnection/writeUpdate Web Apps Hybrid Connection.NN
microsoft.web/sites/hybridconnectionnamespaces/relays/deleteDelete Web Apps Hybrid Connection Namespaces Relays.NN
microsoft.web/sites/hybridconnectionnamespaces/relays/listkeys/actionList Keys Web Apps Hybrid Connection Namespaces Relays.NN
microsoft.web/sites/hybridconnectionnamespaces/relays/writeUpdate Web Apps Hybrid Connection Namespaces Relays.NN
microsoft.web/sites/instances/deployments/deleteDelete Web Apps Instances Deployments.NN
microsoft.web/sites/instances/processes/deleteDelete Web Apps Instances Processes.NN
microsoft.web/sites/instances/processes/stop/actionStop Web Apps Instances Processes.NN
Microsoft.Web/Sites/joinPerimeter/actionDetermines if a user is allowed to associate an Azure Web App with a Network Security Perimeter.NN
microsoft.web/sites/listbackups/actionList Web App backups.NN
microsoft.web/sites/listsyncfunctiontriggerstatus/actionList Sync Function Trigger Status.NN
microsoft.web/sites/listworkflowsconnections/actionList logic app's connections by its ID in a Logic App.NN
microsoft.web/sites/migratemysql/actionMigrate MySQL Web Apps.NN
microsoft.web/sites/networkConfig/deleteDelete App Service Network Configuration.NN
microsoft.web/sites/networkConfig/writeUpdate App Service Network Configuration.NN
Microsoft.Web/Sites/networkSecurityPerimeterAssociationProxies/deleteDelete Web App Network Security Perimeter Association Proxies.NN
Microsoft.Web/Sites/networkSecurityPerimeterAssociationProxies/writeCreate or Update Web App Network Security Perimeter Association Proxies.NN
Microsoft.Web/Sites/networkSecurityPerimeterConfigurations/actionReconcile Web App Network Security Perimeter Configurations.NN
microsoft.web/sites/networktrace/actionNetwork Trace Web Apps.NN
microsoft.web/sites/newpassword/actionNewpassword Web Apps.NN
microsoft.web/sites/premieraddons/deleteDelete Web Apps Premier Addons.NN
microsoft.web/sites/premieraddons/writeUpdate Web Apps Premier Addons.NN
Microsoft.Web/sites/privateEndpointConnectionProxies/DeleteDelete Private Endpoint Connection ProxiesNN
Microsoft.Web/sites/privateEndpointConnectionProxies/validate/actionValidate Private Endpoint Connection ProxiesNN
Microsoft.Web/sites/privateEndpointConnectionProxies/WriteCreate or Update Private Endpoint Connection ProxiesNN
Microsoft.Web/sites/privateEndpointConnections/DeleteDelete a Private Endpoint Connection.NN
Microsoft.Web/sites/privateEndpointConnections/WriteApprove or Reject a private endpoint connection.NN
Microsoft.Web/sites/PrivateEndpointConnectionsApproval/actionApprove Private Endpoint ConnectionsNN
microsoft.web/sites/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resourceNN
microsoft.web/sites/publiccertificates/deleteDelete Web Apps Public Certificates.NN
microsoft.web/sites/publiccertificates/writeUpdate Web Apps Public Certificates.NN
Microsoft.Web/sites/publish/ActionPublish a Web AppNN
Microsoft.Web/sites/publishxml/ActionGet publishing profile xml for a Web AppNN
microsoft.web/sites/recommendations/disable/actionDisable Web Apps Recommendations.NN
microsoft.web/sites/recover/actionRecover Web Apps.NN
Microsoft.Web/sites/resetSlotConfig/ActionReset web app configurationNN
Microsoft.Web/sites/restart/ActionRestart a Web AppNN
microsoft.web/sites/restore/writeRestore Web Apps.NN
microsoft.web/sites/restorefrombackupblob/actionRestore Web App From Backup Blob.NN
microsoft.web/sites/restorefromdeletedapp/actionRestore Web Apps From Deleted App.NN
microsoft.web/sites/restoresnapshot/actionRestore Web Apps Snapshots.NN
Microsoft.Web/sites/sitecontainers/DeleteDelete Sitecontainers of an existing Web AppNN
Microsoft.Web/sites/sitecontainers/WriteCreate new Sitecontainers or update existing ones for a Web AppNN
microsoft.web/sites/siteextensions/deleteDelete Web Apps Site Extensions.NN
microsoft.web/sites/siteextensions/writeUpdate Web Apps Site Extensions.NN
microsoft.web/sites/slotcopy/actionCopy content from deployment slot.NN
Microsoft.Web/sites/slots/applySlotConfig/ActionApply web app slot configuration from target slot to the current slot.NN
Microsoft.Web/sites/slots/backup/ActionCreate new Web App Slot backup.NN
microsoft.web/sites/slots/backup/writeUpdate Web Apps Slots Backup.NN
microsoft.web/sites/slots/backups/actionDiscover Web Apps Slots Backups.NN
microsoft.web/sites/slots/backups/deleteDelete Web Apps Slots Backups.NN
microsoft.web/sites/slots/backups/list/actionList Web Apps Slots Backups.NN
microsoft.web/sites/slots/backups/restore/actionRestore Web Apps Slots Backups.NN
Microsoft.Web/sites/slots/basicPublishingCredentialsPolicies/WriteList which publishing credentials are allowed for a Web App SlotNN
microsoft.web/sites/slots/config/appsettings/writeCreate or Update Web App Slot's Single App settingNN
microsoft.web/sites/slots/config/deleteDelete Web Apps Slots Config.NN
Microsoft.Web/sites/slots/config/list/ActionList Web App Slot's security sensitive settings, such as publishing credentials, app settings and connection stringsNN
microsoft.web/sites/slots/config/snapshots/listsecrets/actionWeb Apps List Slot Secrets From Snapshot.NN
microsoft.web/sites/slots/config/validateupgradepath/actionValidate upgrade path for Web App.NN
microsoft.web/sites/slots/config/web/appsettings/deleteDelete Web App Slot's App SettingNN
microsoft.web/sites/slots/config/web/connectionstrings/deleteDelete Web App slot's single connection stringNN
microsoft.web/sites/slots/config/web/connectionstrings/writeCreate or Update Web App Slot's single sonnection stringNN
Microsoft.Web/sites/slots/config/WriteUpdate Web App Slot's configuration settingsNN
microsoft.web/sites/slots/containerlogs/actionGet Zipped Container Logs for Web App Slot.NN
microsoft.web/sites/slots/containerlogs/download/actionDownload Web Apps Slots Container Logs.NN
microsoft.web/sites/slots/continuouswebjobs/deleteDelete Web Apps Slots Continuous Web Jobs.NN
microsoft.web/sites/slots/continuouswebjobs/start/actionStart Web Apps Slots Continuous Web Jobs.NN
microsoft.web/sites/slots/continuouswebjobs/stop/actionStop Web Apps Slots Continuous Web Jobs.NN
Microsoft.Web/sites/slots/DeleteDelete an existing Web App SlotNN
microsoft.web/sites/slots/deployments/deleteDelete Web Apps Slots Deployments.NN
microsoft.web/sites/slots/deployments/writeUpdate Web Apps Slots Deployments.NN
microsoft.web/sites/slots/deployWorkflowArtifacts/actionCreate the artifacts in a deployment slot in a Logic App.NN
microsoft.web/sites/slots/diagnostics/analyses/execute/ActionRun Web Apps Slots Diagnostics Analysis.NN
microsoft.web/sites/slots/diagnostics/detectors/execute/ActionRun Web Apps Slots Diagnostics Detector.NN
microsoft.web/sites/slots/domainownershipidentifiers/deleteDelete Web App Slots Domain Ownership Identifiers.NN
microsoft.web/sites/slots/domainownershipidentifiers/writeUpdate Web App Slots Domain Ownership Identifiers.NN
microsoft.web/sites/slots/extensions/api/actionInvoke App Service Slots Extensions APIs.NN
microsoft.web/sites/slots/extensions/writeUpdate Web Apps Slots Extensions.NN
microsoft.web/sites/slots/functions/keys/deleteDelete Function keys.NN
microsoft.web/sites/slots/functions/keys/writeUpdate Function keys.NN
microsoft.web/sites/slots/functions/listkeys/actionList Function keys.NN
microsoft.web/sites/slots/functions/listsecrets/actionList Secrets Web Apps Slots Functions.NN
microsoft.web/sites/slots/host/functionkeys/deleteDelete Functions Host Function keys.NN
microsoft.web/sites/slots/host/functionkeys/writeUpdate Functions Host Function keys.NN
microsoft.web/sites/slots/host/listkeys/actionList Functions Host keys.NN
microsoft.web/sites/slots/host/sync/actionSync Function Triggers.NN
microsoft.web/sites/slots/host/systemkeys/deleteDelete Functions Host System keys.NN
microsoft.web/sites/slots/host/systemkeys/writeUpdate Functions Host System keys.NN
microsoft.web/sites/slots/hostnamebindings/deleteDelete Web Apps Slots Hostname Bindings.NN
microsoft.web/sites/slots/hostnamebindings/writeUpdate Web Apps Slots Hostname Bindings.NN
microsoft.web/sites/slots/hybridconnection/deleteDelete Web Apps Slots Hybrid Connection.NN
microsoft.web/sites/slots/hybridconnection/writeUpdate Web Apps Slots Hybrid Connection.NN
microsoft.web/sites/slots/hybridconnectionnamespaces/relays/deleteDelete Web Apps Slots Hybrid Connection Namespaces Relays.NN
microsoft.web/sites/slots/hybridconnectionnamespaces/relays/writeUpdate Web Apps Slots Hybrid Connection Namespaces Relays.NN
microsoft.web/sites/slots/instances/processes/deleteDelete Web Apps Slots Instances Processes.NN
microsoft.web/sites/slots/instances/processes/stop/actionStop Web Apps Slots Instances Processes.NN
microsoft.web/sites/slots/listbackups/actionList Web App Slot backups.NN
microsoft.web/sites/slots/listsyncfunctiontriggerstatus/actionList Sync Function Trigger Status for deployment slot.NN
microsoft.web/sites/slots/listworkflowsconnections/actionList logic app's connections by its ID in a deployment slot in a Logic App.NN
microsoft.web/sites/slots/networkConfig/deleteDelete App Service Slots Network Configuration.NN
microsoft.web/sites/slots/networkConfig/writeUpdate App Service Slots Network Configuration.NN
microsoft.web/sites/slots/networktrace/actionNetwork Trace Web Apps Slots.NN
microsoft.web/sites/slots/newpassword/actionNewpassword Web Apps Slots.NN
microsoft.web/sites/slots/premieraddons/deleteDelete Web Apps Slots Premier Addons.NN
microsoft.web/sites/slots/premieraddons/writeUpdate Web Apps Slots Premier Addons.NN
microsoft.web/sites/slots/providers/Microsoft.Insights/diagnosticSettings/writeCreates or updates the diagnostic setting for the resourceNN
microsoft.web/sites/slots/publiccertificates/deleteDelete Web Apps Slots Public Certificates.NN
microsoft.web/sites/slots/publiccertificates/writeCreate or Update Web Apps Slots Public Certificates.NN
Microsoft.Web/sites/slots/publish/ActionPublish a Web App SlotNN
Microsoft.Web/sites/slots/publishxml/ActionGet publishing profile xml for Web App SlotNN
microsoft.web/sites/slots/recover/actionRecover Web Apps Slots.NN
Microsoft.Web/sites/slots/resetSlotConfig/ActionReset web app slot configurationNN
Microsoft.Web/sites/slots/restart/ActionRestart a Web App SlotNN
microsoft.web/sites/slots/restore/writeRestore Web Apps Slots.NN
microsoft.web/sites/slots/restorefrombackupblob/actionRestore Web Apps Slot From Backup Blob.NN
microsoft.web/sites/slots/restorefromdeletedapp/actionRestore Web App Slots From Deleted App.NN
microsoft.web/sites/slots/restoresnapshot/actionRestore Web Apps Slots Snapshots.NN
Microsoft.Web/sites/slots/sitecontainers/DeleteDelete Sitecontainers of an existing Web App's SlotNN
Microsoft.Web/sites/slots/sitecontainers/WriteCreate new or update existing Sitecontainers of a Web App's SlotNN
microsoft.web/sites/slots/siteextensions/deleteDelete Web Apps Slots Site Extensions.NN
microsoft.web/sites/slots/siteextensions/writeUpdate Web Apps Slots Site Extensions.NN
microsoft.web/sites/slots/slotcopy/actionCopy content from one deployment slot to another.NN
Microsoft.Web/sites/slots/slotsdiffs/ActionGet differences in configuration between web app and slotsNN
Microsoft.Web/sites/slots/slotsswap/ActionSwap Web App deployment slotsNN
Microsoft.Web/sites/slots/sourcecontrols/DeleteDelete Web App Slot's source control configuration settingsNN
Microsoft.Web/sites/slots/sourcecontrols/WriteUpdate Web App Slot's source control configuration settingsNN
Microsoft.Web/sites/slots/start/ActionStart a Web App SlotNN
Microsoft.Web/sites/slots/startDevSession/ActionStart Dev Session for Web App SlotNN
Microsoft.Web/sites/slots/stop/ActionStop a Web App SlotNN
microsoft.web/sites/slots/sync/actionSync Web Apps Slots.NN
microsoft.web/sites/slots/syncfunctiontriggers/actionSync Function Triggers for deployment slot.NN
microsoft.web/sites/slots/triggeredwebjobs/deleteDelete Web Apps Slots Triggered WebJobs.NN
microsoft.web/sites/slots/triggeredwebjobs/run/actionRun Web Apps Slots Triggered WebJobs.NN
microsoft.web/sites/slots/virtualnetworkconnections/deleteDelete Web Apps Slots Virtual Network Connections.NN
microsoft.web/sites/slots/virtualnetworkconnections/gateways/writeUpdate Web Apps Slots Virtual Network Connections Gateways.NN
microsoft.web/sites/slots/virtualnetworkconnections/writeUpdate Web Apps Slots Virtual Network Connections.NN
Microsoft.Web/sites/slots/WriteCreate a new Web App Slot or update an existing oneNN
Microsoft.Web/sites/slotsdiffs/ActionGet differences in configuration between web app and slotsNN
Microsoft.Web/sites/slotsswap/ActionSwap Web App deployment slotsNN
Microsoft.Web/sites/sourcecontrols/DeleteDelete Web App's source control configuration settingsNN
Microsoft.Web/sites/sourcecontrols/WriteUpdate Web App's source control configuration settingsNN
Microsoft.Web/sites/start/ActionStart a Web AppNN
Microsoft.Web/sites/startDevSession/ActionStart Dev Session for a Web AppNN
Microsoft.Web/sites/stop/ActionStop a Web AppNN
microsoft.web/sites/sync/actionSync Web Apps.NN
microsoft.web/sites/syncfunctiontriggers/actionSync Function Triggers.NN
microsoft.web/sites/triggeredwebjobs/deleteDelete Web Apps Triggered WebJobs.NN
microsoft.web/sites/triggeredwebjobs/run/actionRun Web Apps Triggered WebJobs.NN
microsoft.web/sites/virtualnetworkconnections/deleteDelete Web Apps Virtual Network Connections.NN
microsoft.web/sites/virtualnetworkconnections/gateways/writeUpdate Web Apps Virtual Network Connections Gateways.NN
microsoft.web/sites/virtualnetworkconnections/writeUpdate Web Apps Virtual Network Connections.NN
Microsoft.Web/sites/WriteCreate a new Web App or update an existing oneNN
microsoft.web/sourcecontrols/writeUpdate Source Controls.NN
Microsoft.Web/staticSites/authproviders/listusers/ActionList the users for a Static SiteNN
Microsoft.Web/staticSites/authproviders/users/DeleteDelete a user for a Static SiteNN
Microsoft.Web/staticSites/authproviders/users/WriteUpdate a user for a Static SiteNN
Microsoft.Web/staticSites/builds/config/WriteCreate or update app settings for a Static Site BuildNN
Microsoft.Web/staticSites/builds/databaseConnections/DeleteDelete a Database Connection from a Static Site BuildNN
Microsoft.Web/staticSites/builds/databaseConnections/show/actionShow details for a Database Connection for a Static Site BuildNN
Microsoft.Web/staticSites/builds/databaseConnections/WriteCreate or Update a Database Connection with a Static Site BuildNN
Microsoft.Web/staticSites/builds/DeleteDelete a build for a Static SiteNN
Microsoft.Web/staticSites/builds/linkedBackends/DeleteUnlink a Backend from a Static Site BuildNN
Microsoft.Web/staticSites/builds/linkedBackends/validate/actionValidate a Linked Backend for a Static Site BuildNN
Microsoft.Web/staticSites/builds/linkedBackends/WriteRegister a Linked Backend with a Static Site BuildNN
Microsoft.Web/staticSites/builds/listappsettings/ActionList app settings for a Static Site BuildNN
Microsoft.Web/staticSites/builds/listfunctionappsettings/ActionList function app settings for a Static Site BuildNN
Microsoft.Web/staticSites/builds/showDatabaseConnections/actionShow details for Database Connections for a Static Site BuildNN
Microsoft.Web/staticSites/builds/userProvidedFunctionApps/DeleteDetach a User Provided Function App from a Static Site BuildNN
Microsoft.Web/staticSites/builds/userProvidedFunctionApps/WriteRegister a User Provided Function App with a Static Site BuildNN
Microsoft.Web/staticSites/builds/zipdeploy/actionDeploy a Static Site Build from zipped contentNN
Microsoft.Web/staticSites/config/WriteCreate or update app settings for a Static SiteNN
Microsoft.Web/staticSites/createinvitation/actionCreates invitiation link for static site user for a set of rolesNN
Microsoft.Web/staticSites/customdomains/DeleteDelete a custom domain for a Static SiteNN
Microsoft.Web/staticSites/customdomains/validate/ActionValidate a custom domain can be added to a Static SiteNN
Microsoft.Web/staticSites/customdomains/WriteCreate a custom domain for a Static SiteNN
Microsoft.Web/staticSites/databaseConnections/DeleteDelete a Database Connection from a Static SiteNN
Microsoft.Web/staticSites/databaseConnections/show/actionShow details for a Database Connection for a Static SiteNN
Microsoft.Web/staticSites/databaseConnections/WriteCreate or Update a Database Connection with a Static SiteNN
Microsoft.Web/staticSites/DeleteDelete an existing Static SiteYN
Microsoft.Web/staticSites/detach/ActionDetach a Static Site from the currently linked repositoryNN
Microsoft.Web/staticSites/getuser/ActionGet a user's information for a Static SiteNN
Microsoft.Web/staticSites/linkedBackends/DeleteUnlink a Backend from a Static SiteNN
Microsoft.Web/staticSites/linkedBackends/validate/actionValidate a Linked Backend for a Static SiteNN
Microsoft.Web/staticSites/linkedBackends/WriteRegister a Linked Backend with a Static SiteNN
Microsoft.Web/staticSites/listappsettings/ActionList app settings for a Static SiteNN
Microsoft.Web/staticSites/listConfiguredRoles/actionLists the roles configured for the static site.NN
Microsoft.Web/staticSites/listfunctionappsettings/ActionList function app settings for a Static SiteNN
Microsoft.Web/staticSites/listsecrets/actionList the secrets for a Static SiteNN
Microsoft.Web/staticSites/networkConfigs/DeleteDisconnects a network configuration from a Static SiteNN
Microsoft.Web/staticSites/networkConfigs/WriteUpdates network configuration for a Static SiteNN
Microsoft.Web/staticSites/privateEndpointConnectionProxies/DeleteDelete Private Endpoint Connection Proxies for a Static SiteNN
Microsoft.Web/staticSites/privateEndpointConnectionProxies/validate/actionValidate Private Endpoint Connection Proxies for a Static SiteNN
Microsoft.Web/staticSites/privateEndpointConnectionProxies/WriteCreate or Update Private Endpoint Connection Proxies for a Static SiteNN
Microsoft.Web/staticSites/privateEndpointConnections/DeleteDelete a Private Endpoint Connection for a Static SiteNN
Microsoft.Web/staticSites/privateEndpointConnections/WriteApprove or Reject Private Endpoint Connection for a Static SiteNN
Microsoft.Web/staticSites/publish/actionCheck publish access to static web appNN
Microsoft.Web/staticSites/resetapikey/ActionReset the api key for a Static SiteNN
Microsoft.Web/staticSites/showDatabaseConnections/actionShow details for Database Connections for a Static SiteNN
Microsoft.Web/staticSites/userProvidedFunctionApps/DeleteDetach a User Provided Function App from a Static SiteNN
Microsoft.Web/staticSites/userProvidedFunctionApps/WriteRegister a User Provided Function App with a Static SiteNN
Microsoft.Web/staticSites/validateCustomDomainOwnership/actionValidate the custom domain ownership for a static siteNN
Microsoft.Web/staticSites/WriteCreate a new Static Site or update an existing oneYN
Microsoft.Web/staticSites/zipdeploy/actionDeploy a Static Site from zipped contentNN
microsoft.web/unregister/actionUnregister Microsoft.Web resource provider for the subscription.NN
microsoft.web/validate/actionValidate .NN
microsoft.web/verifyhostingenvironmentvnet/actionVerify Hosting Environment Vnet.NN
Microsoft.Web/workerApps/deleteDelete a Worker AppNN
Microsoft.Web/workerApps/writeCreate a Worker App or update an existing oneNN
Microsoft.Web/deletedSites/restore/actionRestore Deleted Web AppNN
Microsoft.Web/locations/deletedSites/restore/actionRestore Deleted Web App at locationNN

any: Azure App Service (catch-all)

#
Namespace
Microsoft.Web

Description

Catch-all for Azure-Microsoft.Web rules that match the resource provider but no specific operation.

References #

microsoft.web/apimanagementaccounts/apis/apiacls/delete

#
Namespace
Microsoft.Web

Description

Delete Api Management Accounts APIs Apiacls.

References #

microsoft.web/apimanagementaccounts/apis/apiacls/write

#
Namespace
Microsoft.Web

Description

Update Api Management Accounts APIs Apiacls.

References #

microsoft.web/apimanagementaccounts/apis/connections/confirmconsentcode/action

#
Namespace
Microsoft.Web

Description

Confirm Consent Code Api Management Accounts APIs Connections.

References #

microsoft.web/apimanagementaccounts/apis/connections/connectionacls/delete

#
Namespace
Microsoft.Web

Description

Delete Api Management Accounts APIs Connections Connectionacls.

References #

microsoft.web/apimanagementaccounts/apis/connections/connectionacls/write

#
Namespace
Microsoft.Web

Description

Update Api Management Accounts APIs Connections Connectionacls.

References #

microsoft.web/apimanagementaccounts/apis/connections/delete

#
Namespace
Microsoft.Web

Description

Delete Api Management Accounts APIs Connections.

References #

microsoft.web/apimanagementaccounts/apis/connections/getconsentlinks/action

#
Namespace
Microsoft.Web

microsoft.web/apimanagementaccounts/apis/connections/listconnectionkeys/action

#
Namespace
Microsoft.Web

Description

List Connection Keys Api Management Accounts APIs Connections.

References #

microsoft.web/apimanagementaccounts/apis/connections/listsecrets/action

#
Namespace
Microsoft.Web

Description

List Secrets Api Management Accounts APIs Connections.

References #

microsoft.web/apimanagementaccounts/apis/connections/write

#
Namespace
Microsoft.Web

Description

Update Api Management Accounts APIs Connections.

References #

microsoft.web/apimanagementaccounts/apis/delete

#
Namespace
Microsoft.Web

Description

Delete Api Management Accounts APIs.

References #

microsoft.web/apimanagementaccounts/apis/localizeddefinitions/delete

#
Namespace
Microsoft.Web

Description

Delete Api Management Accounts APIs Localized Definitions.

References #

microsoft.web/apimanagementaccounts/apis/localizeddefinitions/write

#
Namespace
Microsoft.Web

Description

Update Api Management Accounts APIs Localized Definitions.

References #

microsoft.web/apimanagementaccounts/apis/write

#
Namespace
Microsoft.Web

Description

Update Api Management Accounts APIs.

References #

Microsoft.Web/certificates/Delete

#
Namespace
Microsoft.Web

Description

Delete an existing certificate.

References #

Microsoft.Web/certificates/Write

#
Namespace
Microsoft.Web

Description

Add a new certificate or update an existing one.

References #

Microsoft.Web/connectionGateways/Associate/Action

#
Namespace
Microsoft.Web

Description

Associates with a Connection Gateway.

References #

Microsoft.Web/connectionGateways/Delete

#
Namespace
Microsoft.Web

Description

Deletes a Connection Gateway.

References #

Microsoft.Web/connectionGateways/Join/Action

#
Namespace
Microsoft.Web

Description

Joins a Connection Gateway.

References #

Microsoft.Web/connectionGateways/ListStatus/Action

#
Namespace
Microsoft.Web

Description

Lists status of a Connection Gateway.

References #

Microsoft.Web/connectionGateways/Move/Action

#
Namespace
Microsoft.Web

Description

Moves a Connection Gateway.

References #

Microsoft.Web/connectionGateways/Write

#
Namespace
Microsoft.Web

Description

Creates or updates a Connection Gateway.

References #

Microsoft.Web/connections/accessPolicies/Delete

#
Namespace
Microsoft.Web

Description

Deletes Connection Access Policies.

References #

Microsoft.Web/connections/accessPolicies/Write

#
Namespace
Microsoft.Web

Description

Add or Update Connection Access Policies.

References #

microsoft.web/connections/confirmconsentcode/action

#
Namespace
Microsoft.Web

Description

Confirm Connections Consent Code.

References #

Microsoft.Web/connections/Delete

#
Namespace
Microsoft.Web

Description

Deletes a Connection.

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "af709074-16dd-47b6-bf04-f159bc0a0fb1",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
    "action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
    "action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "OperationNameValue": "MICROSOFT.WEB/CONNECTIONS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/connections/azuresentinel-Create-ReslientIncident",
    "message": "Microsoft.Web/connections/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "efcc6aed-66df-4275-af35-d193fa592064",
    "eventSubmissionTimestamp": "2021-04-28T14:44:00.7229035Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "azuresentinel-create-reslientincident",
    "resourceGroup": "BTPOC",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/connections/azuresentinel-Create-ReslientIncident",
    "message": "Microsoft.Web/connections/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "efcc6aed-66df-4275-af35-d193fa592064",
    "eventSubmissionTimestamp": "2021-04-28T14:44:00.7229035Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "azuresentinel-create-reslientincident",
    "resourceGroup": "BTPOC",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "activityStatusValue": "Success"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "efcc6aed-66df-4275-af35-d193fa592064",
  "EventSubmissionTimestamp": "4/28/2021, 2:44:00.722 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "BTPOC",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "ActivityStatusValue": "Success",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:44:00.722 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

References #

microsoft.web/connections/dynamicInvoke/action

#
Namespace
Microsoft.Web

Description

Dynamic Invoke a Connection.

References #

Microsoft.Web/connections/Join/Action

#
Namespace
Microsoft.Web

Description

Joins a Connection.

References #

microsoft.web/connections/listConnectionKeys/action

#
Namespace
Microsoft.Web

Description

Lists API Connections Keys.

References #

microsoft.web/connections/listconsentlinks/action

#
Namespace
Microsoft.Web

Microsoft.Web/connections/Move/Action

#
Namespace
Microsoft.Web

Description

Moves a Connection.

References #

microsoft.web/connections/revokeConnectionKeys/action

#
Namespace
Microsoft.Web

Description

Revokes API Connections Keys.

References #

Microsoft.Web/connections/Write

#
Namespace
Microsoft.Web

Description

Creates or updates a Connection.

References #

Microsoft.Web/connectorGateways/action

#
Namespace
Microsoft.Web

Description

Performs an action on an Connector Gateway

References #

Microsoft.Web/connectorGateways/connections/accessPolicies/action

#
Namespace
Microsoft.Web

Description

Performs an action on a Connector Gateway Connection Access Policy

References #

Microsoft.Web/connectorGateways/connections/accessPolicies/delete

#
Namespace
Microsoft.Web

Description

Deletes an existing Connector Gateway Connection Access Policy

References #

Microsoft.Web/connectorGateways/connections/accessPolicies/write

#
Namespace
Microsoft.Web

Description

Creates a new Connector Gateway Connection Access Policy or updates an existing one

References #

Microsoft.Web/connectorGateways/connections/action

#
Namespace
Microsoft.Web

Description

Perform an action on an Connector Gateway Connection

References #

Microsoft.Web/connectorGateways/connections/delete

#
Namespace
Microsoft.Web

Description

Delete an existing Connector Gateway Connection

References #

Microsoft.Web/connectorGateways/connections/write

#
Namespace
Microsoft.Web

Description

Creates a new Connector Gateway Connection or updates an existing one

References #

Microsoft.Web/connectorGateways/customConnectors/action

#
Namespace
Microsoft.Web

Description

Performs an action on a Connector Gateway Custom Connector

References #

Microsoft.Web/connectorGateways/customConnectors/delete

#
Namespace
Microsoft.Web

Description

Deletes an existing Connector Gateway Custom Connector

References #

Microsoft.Web/connectorGateways/customConnectors/write

#
Namespace
Microsoft.Web

Description

Creates a new Connector Gateway Custom Connector or updates an existing one

References #

Microsoft.Web/connectorGateways/delete

#
Namespace
Microsoft.Web

Description

Deletes an existing Connector Gateway

References #

Microsoft.Web/connectorGateways/mcpserverconfigs/action

#
Namespace
Microsoft.Web

Description

Perform an action on an Connector Gateway MCP Server Config

References #

Microsoft.Web/connectorGateways/mcpserverconfigs/delete

#
Namespace
Microsoft.Web

Description

Delete an existing Connector Gateway MCP Server Config

References #

Microsoft.Web/connectorGateways/mcpserverconfigs/write

#
Namespace
Microsoft.Web

Description

Create a new Connector Gateway MCP Server Config or update an existing one

References #

Microsoft.Web/connectorGateways/triggerconfigs/action

#
Namespace
Microsoft.Web

Description

Perform an action on an Connector Gateway Trigger Config

References #

Microsoft.Web/connectorGateways/triggerconfigs/delete

#
Namespace
Microsoft.Web

Description

Delete an existing Connector Gateway Trigger Config

References #

Microsoft.Web/connectorGateways/triggerconfigs/write

#
Namespace
Microsoft.Web

Description

Create a new Connector Gateway Trigger Config or update an existing one

References #

Microsoft.Web/connectorGateways/write

#
Namespace
Microsoft.Web

Description

Creates a new Connector Gateway or updates an existing one

References #

Microsoft.Web/containerApps/delete

#
Namespace
Microsoft.Web

Description

Delete a Container App

References #

Microsoft.Web/containerApps/listsecrets/action

#
Namespace
Microsoft.Web

Description

List a Container App Secrets

References #

Microsoft.Web/containerApps/revisions/activate/action

#
Namespace
Microsoft.Web

Description

Activate a Container App Revision

References #

Microsoft.Web/containerApps/revisions/deactivate/action

#
Namespace
Microsoft.Web

Description

Deactivate a Container App Revision

References #

Microsoft.Web/containerApps/revisions/deactivate/restart/action

#
Namespace
Microsoft.Web

Description

Restart a Container App Revision

References #

Microsoft.Web/containerApps/sourcecontrols/delete

#
Namespace
Microsoft.Web

Description

Delete a Container App Source Control

References #

Microsoft.Web/containerApps/sourcecontrols/write

#
Namespace
Microsoft.Web

Description

Create or Update a Container App Source Control

References #

Microsoft.Web/containerApps/write

#
Namespace
Microsoft.Web

Description

Create a Container App or update an existing one

References #

Microsoft.Web/customApis/Delete

#
Namespace
Microsoft.Web

Description

Deletes a Custom API.

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "af709074-16dd-47b6-bf04-f159bc0a0fb1",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
    "action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/BTPOC",
    "action": "Microsoft.Resources/subscriptions/resourceGroups/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "OperationNameValue": "MICROSOFT.WEB/CUSTOMAPIS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/customApis/Resilent",
    "message": "Microsoft.Web/customApis/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "a2594dff-d22d-42c1-b1e7-37184a3f0683",
    "eventSubmissionTimestamp": "2021-04-28T14:44:00.317969Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "resilent",
    "resourceGroup": "BTPOC",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourcegroups/BTPOC/providers/Microsoft.Web/customApis/Resilent",
    "message": "Microsoft.Web/customApis/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "a2594dff-d22d-42c1-b1e7-37184a3f0683",
    "eventSubmissionTimestamp": "2021-04-28T14:44:00.3179690Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "resilent",
    "resourceGroup": "BTPOC",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "activityStatusValue": "Success"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "a2594dff-d22d-42c1-b1e7-37184a3f0683",
  "EventSubmissionTimestamp": "4/28/2021, 2:44:00.317 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "BTPOC",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "ActivityStatusValue": "Success",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:44:00.317 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

References #

Microsoft.Web/customApis/extractApiDefinitionFromWsdl/Action

#
Namespace
Microsoft.Web

Description

Extracts API definition from a WSDL.

References #

Microsoft.Web/customApis/Join/Action

#
Namespace
Microsoft.Web

Description

Joins a Custom API.

References #

Microsoft.Web/customApis/listWsdlInterfaces/Action

#
Namespace
Microsoft.Web

Description

Lists WSDL interfaces for a Custom API.

References #

Microsoft.Web/customApis/Move/Action

#
Namespace
Microsoft.Web

Description

Moves a Custom API.

References #

Microsoft.Web/customApis/Write

#
Namespace
Microsoft.Web

Description

Creates or updates a Custom API.

References #

Microsoft.Web/freeTrialStaticWebApps/delete

#
Namespace
Microsoft.Web

Description

Deletes a free trial static web app.

References #

Microsoft.Web/freeTrialStaticWebApps/upgrade/action

#
Namespace
Microsoft.Web

Description

Upgrades a free trial static web app.

References #

Microsoft.Web/freeTrialStaticWebApps/write

#
Namespace
Microsoft.Web

Description

Creates or updates a free trial static web app.

References #

Microsoft.Web/hostingEnvironments/configurations/networking/Write

#
Namespace
Microsoft.Web

Description

Update networking configuration of an App Service Environment.

References #

microsoft.web/hostingenvironments/configurations/write

#
Namespace
Microsoft.Web

Description

Update Hosting Environment Configurations.

References #

Microsoft.Web/hostingEnvironments/Delete

#
Namespace
Microsoft.Web

Description

Delete an App Service Environment

References #

Microsoft.Web/hostingEnvironments/eventGridFilters/delete

#
Namespace
Microsoft.Web

Description

Delete Event Grid Filter on hosting environment.

References #

Microsoft.Web/hostingEnvironments/eventGridFilters/write

#
Namespace
Microsoft.Web

Description

Put Event Grid Filter on hosting environment.

References #

Microsoft.Web/hostingEnvironments/Join/Action

#
Namespace
Microsoft.Web

Description

Joins an App Service Environment

References #

Microsoft.Web/hostingEnvironments/multiRolePools/Write

#
Namespace
Microsoft.Web

Description

Create a new FrontEnd Pool in an App Service Environment or update an existing one

References #

Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/Delete

#
Namespace
Microsoft.Web

Description

Delete Private Endpoint Connection Proxies

References #

Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Web

Description

Validate Private Endpoint Connection Proxies

References #

Microsoft.Web/hostingEnvironments/privateEndpointConnectionProxies/Write

#
Namespace
Microsoft.Web

Description

Create or Update Private Endpoint Connection Proxies

References #

Microsoft.Web/hostingEnvironments/privateEndpointConnections/Delete

#
Namespace
Microsoft.Web

Description

Delete a private endpoint connection.

References #

Microsoft.Web/hostingEnvironments/privateEndpointConnections/Write

#
Namespace
Microsoft.Web

Description

Approve or Reject a private endpoint connection.

References #

Microsoft.Web/hostingEnvironments/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Web

Description

Approve Private Endpoint Connections

References #

microsoft.web/hostingenvironments/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Web

Description

Creates or updates the diagnostic setting for the resource

References #

Microsoft.Web/hostingEnvironments/reboot/Action

#
Namespace
Microsoft.Web

Description

Reboot all machines in an App Service Environment

References #

microsoft.web/hostingenvironments/resume/action

#
Namespace
Microsoft.Web

Description

Resume Hosting Environments.

References #

microsoft.web/hostingenvironments/suspend/action

#
Namespace
Microsoft.Web

Description

Suspend Hosting Environments.

References #

Microsoft.Web/hostingEnvironments/testUpgradeAvailableNotification/Action

#
Namespace
Microsoft.Web

Description

Send test upgrade notification for an App Service Environment

References #

Microsoft.Web/hostingEnvironments/upgrade/Action

#
Namespace
Microsoft.Web

Description

Upgrades an App Service Environment

References #

Microsoft.Web/hostingEnvironments/workerPools/Write

#
Namespace
Microsoft.Web

Description

Create a new Worker Pool in an App Service Environment or update an existing one

References #

Microsoft.Web/hostingEnvironments/Write

#
Namespace
Microsoft.Web

Description

Create a new App Service Environment or update existing one

References #

Microsoft.Web/kubeEnvironments/delete

#
Namespace
Microsoft.Web

Description

Delete a Kubernetes Environment

References #

Microsoft.Web/kubeEnvironments/join/action

#
Namespace
Microsoft.Web

Description

Joins a Kubernetes Environment

References #

Microsoft.Web/kubeEnvironments/write

#
Namespace
Microsoft.Web

Description

Create a Kubernetes Environment or update an existing one

References #

microsoft.web/locations/deleteVirtualNetworkOrSubnets/action

#
Namespace
Microsoft.Web

Description

Vnet or subnet deletion notification for Locations.

References #

microsoft.web/locations/extractapidefinitionfromwsdl/action

#
Namespace
Microsoft.Web

Description

Extract Api Definition from WSDL for Locations.

References #

Microsoft.Web/locations/GetNetworkPolicies/action

#
Namespace
Microsoft.Web

Description

Read Network Intent Policies

References #

microsoft.web/locations/listwsdlinterfaces/action

#
Namespace
Microsoft.Web

Description

List WSDL Interfaces for Locations.

References #

Microsoft.Web/locations/managedapis/Join/Action

#
Namespace
Microsoft.Web

Description

Joins a Managed API.

References #

Microsoft.Web/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action

#
Namespace
Microsoft.Web

Description

Notify Network Security Perimeter Updates.

References #

Microsoft.Web/locations/previewstaticsiteworkflowfile/action

#
Namespace
Microsoft.Web

Description

Preview Static Site Workflow File

References #

microsoft.web/locations/validateDeleteVirtualNetworkOrSubnets/action

#
Namespace
Microsoft.Web

Description

Validates deleting Vnet or subnet for Locations

References #

microsoft.web/publishingusers/write

#
Namespace
Microsoft.Web

Description

Update Publishing Users.

References #

microsoft.web/register/action

#
Namespace
Microsoft.Web

Description

Register Microsoft.Web resource provider for the subscription.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Web/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Web/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "d77d1270-e142-4ecf-982c-41db1e56da41",
  "EventDataId": "217bc897-a511-f786-858b-5cb7901df517",
  "EventSubmissionTimestamp": "2026-07-02T17:17:03.7333834Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.WEB/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Web",
    "message": "Microsoft.Web/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "217bc897-a511-f786-858b-5cb7901df517",
    "eventSubmissionTimestamp": "2026-07-02T17:17:03.7333834Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Web",
    "message": "Microsoft.Web/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "217bc897-a511-f786-858b-5cb7901df517",
    "eventSubmissionTimestamp": "2026-07-02T17:17:03.7333834Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceProviderValue": "MICROSOFT.WEB",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Web/serverfarms/Delete

#
Namespace
Microsoft.Web

Description

Delete an existing App Service Plan

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
    "action": "Microsoft.Web/serverfarms/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
    "action": "Microsoft.Web/serverfarms/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "df3bdc41-70ab-4f0f-a039-d3f45be1a25b",
  "EventDataId": "f407f2ee-37e4-eb64-5a10-d91f560a8e8d",
  "EventSubmissionTimestamp": "2026-07-02T17:28:47.3967714Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.WEB/SERVERFARMS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/serverFarms/dwh92eef0appplan",
    "message": "Microsoft.Web/serverFarms/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "f407f2ee-37e4-eb64-5a10-d91f560a8e8d",
    "eventSubmissionTimestamp": "2026-07-02T17:28:47.3967714Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0appplan",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/serverFarms/dwh92eef0appplan",
    "message": "Microsoft.Web/serverFarms/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "f407f2ee-37e4-eb64-5a10-d91f560a8e8d",
    "eventSubmissionTimestamp": "2026-07-02T17:28:47.3967714Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0appplan",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Web/serverfarms/eventGridFilters/delete

#
Namespace
Microsoft.Web

Description

Delete Event Grid Filter on server farm.

References #

Microsoft.Web/serverfarms/eventGridFilters/write

#
Namespace
Microsoft.Web

Description

Put Event Grid Filter on server farm.

References #

microsoft.web/serverfarms/firstpartyapps/keyvaultsettings/write

#
Namespace
Microsoft.Web

Description

Create or Update App Service Plan Key Vault first party settings

References #

microsoft.web/serverfarms/firstpartyapps/settings/delete

#
Namespace
Microsoft.Web

Description

Delete App Service Plans First Party Apps Settings

References #

microsoft.web/serverfarms/firstpartyapps/settings/write

#
Namespace
Microsoft.Web

Description

Update App Service Plans First Party Apps Settings

References #

microsoft.web/serverfarms/hybridconnectionnamespaces/relays/delete

#
Namespace
Microsoft.Web

Description

Delete App Service Plans Hybrid Connection Namespaces Relays.

References #

Microsoft.Web/serverfarms/Join/Action

#
Namespace
Microsoft.Web

Description

Joins an App Service Plan

References #

microsoft.web/serverfarms/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Web

Description

Creates or updates the diagnostic setting for the resource

References #

Microsoft.Web/serverfarms/restartSites/Action

#
Namespace
Microsoft.Web

Description

Restart all Web Apps in an App Service Plan

References #

Microsoft.Web/serverfarms/startSites/Action

#
Namespace
Microsoft.Web

Description

Start all Apps in an App Service Plan

References #

Microsoft.Web/serverfarms/stopSites/Action

#
Namespace
Microsoft.Web

Description

Stop all Apps in an App Service Plan

References #

microsoft.web/serverfarms/virtualnetworkconnections/gateways/write

#
Namespace
Microsoft.Web

Description

Update App Service Plans Virtual Network Connections Gateways.

References #

microsoft.web/serverfarms/virtualnetworkconnections/routes/delete

#
Namespace
Microsoft.Web

Description

Delete App Service Plans Virtual Network Connections Routes.

References #

microsoft.web/serverfarms/virtualnetworkconnections/routes/write

#
Namespace
Microsoft.Web

Description

Update App Service Plans Virtual Network Connections Routes.

References #

microsoft.web/serverfarms/workers/reboot/action

#
Namespace
Microsoft.Web

Description

Reboot App Service Plans Workers.

References #

Microsoft.Web/serverfarms/Write

#
Namespace
Microsoft.Web

Description

Create a new App Service Plan or update an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
    "action": "Microsoft.Web/serverfarms/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
    "action": "Microsoft.Web/serverfarms/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "9e625b44-bb76-4761-a3a4-dfa50496b39d",
  "EventDataId": "8349aaa6-78a7-1791-5191-76f35484f791",
  "EventSubmissionTimestamp": "2026-07-02T17:18:43.8626993Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.WEB/SERVERFARMS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
    "message": "Microsoft.Web/serverfarms/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8349aaa6-78a7-1791-5191-76f35484f791",
    "eventSubmissionTimestamp": "2026-07-02T17:18:43.8626993Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0appplan",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/serverfarms/dwh92eef0appplan",
    "message": "Microsoft.Web/serverfarms/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "8349aaa6-78a7-1791-5191-76f35484f791",
    "eventSubmissionTimestamp": "2026-07-02T17:18:43.8626993Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0appplan",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Web/sites/applySlotConfig/Action

#
Namespace
Microsoft.Web

Description

Apply web app slot configuration from target slot to the current web app

References #

Microsoft.Web/sites/backup/Action

#
Namespace
Microsoft.Web

Description

Create a new web app backup

References #

microsoft.web/sites/backup/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Backup.

References #

microsoft.web/sites/backups/action

#
Namespace
Microsoft.Web

Description

Discovers an existing app backup that can be restored from a blob in Azure storage.

References #

microsoft.web/sites/backups/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Backups.

References #

microsoft.web/sites/backups/list/action

#
Namespace
Microsoft.Web

Description

List Web Apps Backups.

References #

microsoft.web/sites/backups/restore/action

#
Namespace
Microsoft.Web

Description

Restore Web Apps Backups.

References #

microsoft.web/sites/backups/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Backups.

References #

Microsoft.Web/sites/basicPublishingCredentialsPolicies/Write

#
Namespace
Microsoft.Web

Description

List which publishing methods are allowed for a Web App

References #

microsoft.web/sites/config/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Config.

References #

Microsoft.Web/sites/config/list/Action

#
Namespace
Microsoft.Web

Description

List Web App's security sensitive settings, such as publishing credentials, app settings and connection strings

References #

microsoft.web/sites/config/snapshots/listsecrets/action

#
Namespace
Microsoft.Web

Description

Web Apps List Secrets From Snapshot.

References #

microsoft.web/sites/config/web/appsettings/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps App Setting

References #

microsoft.web/sites/config/web/appsettings/write

#
Namespace
Microsoft.Web

Description

Create or Update Web App Single App setting

References #

microsoft.web/sites/config/web/connectionstrings/delete

#
Namespace
Microsoft.Web

Description

Delete Web App single connection string

References #

microsoft.web/sites/config/web/connectionstrings/write

#
Namespace
Microsoft.Web

Description

Get Web App single App setting.

References #

Microsoft.Web/sites/config/Write

#
Namespace
Microsoft.Web

Description

Update Web App's configuration settings

References #

microsoft.web/sites/containerlogs/action

#
Namespace
Microsoft.Web

Description

Get Zipped Container Logs for Web App.

References #

microsoft.web/sites/containerlogs/download/action

#
Namespace
Microsoft.Web

Description

Download Web Apps Container Logs.

References #

microsoft.web/sites/continuouswebjobs/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Continuous Web Jobs.

References #

microsoft.web/sites/continuouswebjobs/start/action

#
Namespace
Microsoft.Web

Description

Start Web Apps Continuous Web Jobs.

References #

microsoft.web/sites/continuouswebjobs/stop/action

#
Namespace
Microsoft.Web

Description

Stop Web Apps Continuous Web Jobs.

References #

Microsoft.Web/sites/Delete

#
Namespace
Microsoft.Web

Description

Delete an existing Web App

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "a2bba39a-d17f-404d-9919-e59039e73ad4",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new",
    "action": "Microsoft.Web/sites/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "evidence": {
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalType": "User",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "role": "Contributor"
    },
    "action": "Microsoft.Web/sites/delete",
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new"
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619619948",
    "nbf": "1619619948",
    "exp": "1619623848",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAARk47FymlkYjF8aD5qw9R6mifAuz/IGhhTRBHWebW9HOR9MgLKM4YcDn72FFfKrZz",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "thrQim_Tb0K8ZxSi9VWAAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "xms_tcdt": "1591748537",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "nbf": "1619619948",
    "exp": "1619623848",
    "aio": "ATQAy/8TAAAARk47FymlkYjF8aD5qw9R6mifAuz/IGhhTRBHWebW9HOR9MgLKM4YcDn72FFfKrZz",
    "uti": "thrQim_Tb0K8ZxSi9VWAAQ",
    "ver": "1.0",
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619619948",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "puid": "10032000C757D25F"
  },
  "OperationNameValue": "MICROSOFT.WEB/SITES/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "c5b3981e-03ba-4e01-9703-1de27cb9218f",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new",
    "message": "Microsoft.Web/sites/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "bd53ca1f-63d8-4886-9a3e-6869172bd5f2",
    "eventSubmissionTimestamp": "2021-04-28T14:31:40.3331458Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "okta-new",
    "resourceGroup": "SENTINEL-MAINRG",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventSubmissionTimestamp": "2021-04-28T14:31:40.3331458Z",
    "resourceProviderValue": "MICROSOFT.WEB",
    "activityStatusValue": "Success",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "eventCategory": "Administrative",
    "resourceGroup": "SENTINEL-MAINRG",
    "eventDataId": "bd53ca1f-63d8-4886-9a3e-6869172bd5f2",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "activitySubstatusValue": "OK",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "resource": "okta-new",
    "serviceRequestId": "c5b3981e-03ba-4e01-9703-1de27cb9218f",
    "message": "Microsoft.Web/sites/delete",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/Sentinel-MainRG/providers/Microsoft.Web/sites/Okta-new",
    "statusCode": "OK"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "bd53ca1f-63d8-4886-9a3e-6869172bd5f2",
  "EventSubmissionTimestamp": "4/28/2021, 2:31:40.333 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "SENTINEL-MAINRG",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:31:40.333 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

References #

microsoft.web/sites/deployments/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Deployments.

References #

microsoft.web/sites/deployments/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Deployments.

References #

microsoft.web/sites/deployWorkflowArtifacts/action

#
Namespace
Microsoft.Web

Description

Create the artifacts in a Logic App.

References #

microsoft.web/sites/diagnostics/analyses/execute/Action

#
Namespace
Microsoft.Web

Description

Run Web Apps Diagnostics Analysis.

References #

microsoft.web/sites/diagnostics/detectors/execute/Action

#
Namespace
Microsoft.Web

Description

Run Web Apps Diagnostics Detector.

References #

microsoft.web/sites/domainownershipidentifiers/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Domain Ownership Identifiers.

References #

microsoft.web/sites/domainownershipidentifiers/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Domain Ownership Identifiers.

References #

Microsoft.Web/sites/eventGridFilters/delete

#
Namespace
Microsoft.Web

Description

Delete Event Grid Filter on web app.

References #

Microsoft.Web/sites/eventGridFilters/write

#
Namespace
Microsoft.Web

Description

Put Event Grid Filter on web app.

References #

microsoft.web/sites/extensions/api/action

#
Namespace
Microsoft.Web

Description

Invoke App Service Extensions APIs.

References #

microsoft.web/sites/extensions/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Site Extensions.

References #

microsoft.web/sites/extensions/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Site Extensions.

References #

microsoft.web/sites/functions/action

#
Namespace
Microsoft.Web

Description

Functions Web Apps.

References #

microsoft.web/sites/functions/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Functions.

References #

microsoft.web/sites/functions/keys/delete

#
Namespace
Microsoft.Web

Description

Delete Function keys.

References #

microsoft.web/sites/functions/keys/write

#
Namespace
Microsoft.Web

Description

Update Function keys.

References #

microsoft.web/sites/functions/listkeys/action

#
Namespace
Microsoft.Web

Description

List Function keys.

References #

microsoft.web/sites/functions/listsecrets/action

#
Namespace
Microsoft.Web

Description

List Function secrets.

References #

microsoft.web/sites/functions/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Functions.

References #

microsoft.web/sites/host/functionkeys/delete

#
Namespace
Microsoft.Web

Description

Delete Functions Host Function keys.

References #

microsoft.web/sites/host/functionkeys/write

#
Namespace
Microsoft.Web

Description

Update Functions Host Function keys.

References #

microsoft.web/sites/host/listkeys/action

#
Namespace
Microsoft.Web

Description

List Functions Host keys.

References #

microsoft.web/sites/host/listsyncstatus/action

#
Namespace
Microsoft.Web

Description

List Sync Function Triggers Status.

References #

microsoft.web/sites/host/sync/action

#
Namespace
Microsoft.Web

Description

Sync Function Triggers.

References #

microsoft.web/sites/host/systemkeys/delete

#
Namespace
Microsoft.Web

Description

Delete Functions Host System keys.

References #

microsoft.web/sites/host/systemkeys/write

#
Namespace
Microsoft.Web

Description

Update Functions Host System keys.

References #

microsoft.web/sites/hostnamebindings/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Hostname Bindings.

References #

microsoft.web/sites/hostnamebindings/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Hostname Bindings.

References #

Microsoft.Web/sites/hostruntime/host/action

#
Namespace
Microsoft.Web

Description

Perform Function App runtime action like sync triggers, add functions, invoke functions, delete functions etc.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Serverless Script Execution source informational: Detects when serverless resources execute PowerShell or Python scripts through Azure Automation runbook jobs or Azure Function Apps. Adversaries may abuse access to serverless resources to execute commands with inherited permissions from managed identities, RunAs accounts, or hybrid worker groups.T1059, T1651

References #

microsoft.web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/action

#
Namespace
Microsoft.Web

Description

Get Web Apps Hostruntime Workflow Trigger Uri.

References #

microsoft.web/sites/hostruntime/webhooks/api/workflows/triggers/run/action

#
Namespace
Microsoft.Web

Description

Run Web Apps Hostruntime Workflow Trigger.

References #

microsoft.web/sites/hybridconnection/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Hybrid Connection.

References #

microsoft.web/sites/hybridconnection/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Hybrid Connection.

References #

microsoft.web/sites/hybridconnectionnamespaces/relays/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Hybrid Connection Namespaces Relays.

References #

microsoft.web/sites/hybridconnectionnamespaces/relays/listkeys/action

#
Namespace
Microsoft.Web

Description

List Keys Web Apps Hybrid Connection Namespaces Relays.

References #

microsoft.web/sites/hybridconnectionnamespaces/relays/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Hybrid Connection Namespaces Relays.

References #

microsoft.web/sites/instances/deployments/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Instances Deployments.

References #

microsoft.web/sites/instances/processes/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Instances Processes.

References #

microsoft.web/sites/instances/processes/stop/action

#
Namespace
Microsoft.Web

Description

Stop Web Apps Instances Processes.

References #

Microsoft.Web/Sites/joinPerimeter/action

#
Namespace
Microsoft.Web

Description

Determines if a user is allowed to associate an Azure Web App with a Network Security Perimeter.

References #

microsoft.web/sites/listbackups/action

#
Namespace
Microsoft.Web

Description

List Web App backups.

References #

microsoft.web/sites/listsyncfunctiontriggerstatus/action

#
Namespace
Microsoft.Web

Description

List Sync Function Trigger Status.

References #

microsoft.web/sites/listworkflowsconnections/action

#
Namespace
Microsoft.Web

Description

List logic app's connections by its ID in a Logic App.

References #

microsoft.web/sites/migratemysql/action

#
Namespace
Microsoft.Web

Description

Migrate MySQL Web Apps.

References #

microsoft.web/sites/networkConfig/delete

#
Namespace
Microsoft.Web

Description

Delete App Service Network Configuration.

References #

microsoft.web/sites/networkConfig/write

#
Namespace
Microsoft.Web

Description

Update App Service Network Configuration.

References #

Microsoft.Web/Sites/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.Web

Description

Delete Web App Network Security Perimeter Association Proxies.

References #

Microsoft.Web/Sites/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.Web

Description

Create or Update Web App Network Security Perimeter Association Proxies.

References #

Microsoft.Web/Sites/networkSecurityPerimeterConfigurations/action

#
Namespace
Microsoft.Web

Description

Reconcile Web App Network Security Perimeter Configurations.

References #

microsoft.web/sites/networktrace/action

#
Namespace
Microsoft.Web

Description

Network Trace Web Apps.

References #

microsoft.web/sites/newpassword/action

#
Namespace
Microsoft.Web

Description

Newpassword Web Apps.

References #

microsoft.web/sites/premieraddons/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Premier Addons.

References #

microsoft.web/sites/premieraddons/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Premier Addons.

References #

Microsoft.Web/sites/privateEndpointConnectionProxies/Delete

#
Namespace
Microsoft.Web

Description

Delete Private Endpoint Connection Proxies

References #

Microsoft.Web/sites/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Web

Description

Validate Private Endpoint Connection Proxies

References #

Microsoft.Web/sites/privateEndpointConnectionProxies/Write

#
Namespace
Microsoft.Web

Description

Create or Update Private Endpoint Connection Proxies

References #

Microsoft.Web/sites/privateEndpointConnections/Delete

#
Namespace
Microsoft.Web

Description

Delete a Private Endpoint Connection.

References #

Microsoft.Web/sites/privateEndpointConnections/Write

#
Namespace
Microsoft.Web

Description

Approve or Reject a private endpoint connection.

References #

Microsoft.Web/sites/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Web

Description

Approve Private Endpoint Connections

References #

microsoft.web/sites/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Web

Description

Creates or updates the diagnostic setting for the resource

References #

microsoft.web/sites/publiccertificates/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Public Certificates.

References #

microsoft.web/sites/publiccertificates/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Public Certificates.

References #

Microsoft.Web/sites/publish/Action

#
Namespace
Microsoft.Web

Description

Publish a Web App

References #

Microsoft.Web/sites/publishxml/Action

#
Namespace
Microsoft.Web

Description

Get publishing profile xml for a Web App

References #

microsoft.web/sites/recommendations/disable/action

#
Namespace
Microsoft.Web

Description

Disable Web Apps Recommendations.

References #

microsoft.web/sites/recover/action

#
Namespace
Microsoft.Web

Description

Recover Web Apps.

References #

Microsoft.Web/sites/resetSlotConfig/Action

#
Namespace
Microsoft.Web

Description

Reset web app configuration

References #

Microsoft.Web/sites/restart/Action

#
Namespace
Microsoft.Web

Description

Restart a Web App

References #

microsoft.web/sites/restore/write

#
Namespace
Microsoft.Web

Description

Restore Web Apps.

References #

microsoft.web/sites/restorefrombackupblob/action

#
Namespace
Microsoft.Web

Description

Restore Web App From Backup Blob.

References #

microsoft.web/sites/restorefromdeletedapp/action

#
Namespace
Microsoft.Web

Description

Restore Web Apps From Deleted App.

References #

microsoft.web/sites/restoresnapshot/action

#
Namespace
Microsoft.Web

Description

Restore Web Apps Snapshots.

References #

Microsoft.Web/sites/sitecontainers/Delete

#
Namespace
Microsoft.Web

Description

Delete Sitecontainers of an existing Web App

References #

Microsoft.Web/sites/sitecontainers/Write

#
Namespace
Microsoft.Web

Description

Create new Sitecontainers or update existing ones for a Web App

References #

microsoft.web/sites/siteextensions/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Site Extensions.

References #

microsoft.web/sites/siteextensions/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Site Extensions.

References #

microsoft.web/sites/slotcopy/action

#
Namespace
Microsoft.Web

Description

Copy content from deployment slot.

References #

Microsoft.Web/sites/slots/applySlotConfig/Action

#
Namespace
Microsoft.Web

Description

Apply web app slot configuration from target slot to the current slot.

References #

Microsoft.Web/sites/slots/backup/Action

#
Namespace
Microsoft.Web

Description

Create new Web App Slot backup.

References #

microsoft.web/sites/slots/backup/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Backup.

References #

microsoft.web/sites/slots/backups/action

#
Namespace
Microsoft.Web

Description

Discover Web Apps Slots Backups.

References #

microsoft.web/sites/slots/backups/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Backups.

References #

microsoft.web/sites/slots/backups/list/action

#
Namespace
Microsoft.Web

Description

List Web Apps Slots Backups.

References #

microsoft.web/sites/slots/backups/restore/action

#
Namespace
Microsoft.Web

Description

Restore Web Apps Slots Backups.

References #

Microsoft.Web/sites/slots/basicPublishingCredentialsPolicies/Write

#
Namespace
Microsoft.Web

Description

List which publishing credentials are allowed for a Web App Slot

References #

microsoft.web/sites/slots/config/appsettings/write

#
Namespace
Microsoft.Web

Description

Create or Update Web App Slot's Single App setting

References #

microsoft.web/sites/slots/config/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Config.

References #

Microsoft.Web/sites/slots/config/list/Action

#
Namespace
Microsoft.Web

Description

List Web App Slot's security sensitive settings, such as publishing credentials, app settings and connection strings

References #

microsoft.web/sites/slots/config/snapshots/listsecrets/action

#
Namespace
Microsoft.Web

Description

Web Apps List Slot Secrets From Snapshot.

References #

microsoft.web/sites/slots/config/validateupgradepath/action

#
Namespace
Microsoft.Web

Description

Validate upgrade path for Web App.

References #

microsoft.web/sites/slots/config/web/appsettings/delete

#
Namespace
Microsoft.Web

Description

Delete Web App Slot's App Setting

References #

microsoft.web/sites/slots/config/web/connectionstrings/delete

#
Namespace
Microsoft.Web

Description

Delete Web App slot's single connection string

References #

microsoft.web/sites/slots/config/web/connectionstrings/write

#
Namespace
Microsoft.Web

Description

Create or Update Web App Slot's single sonnection string

References #

Microsoft.Web/sites/slots/config/Write

#
Namespace
Microsoft.Web

Description

Update Web App Slot's configuration settings

References #

microsoft.web/sites/slots/containerlogs/action

#
Namespace
Microsoft.Web

Description

Get Zipped Container Logs for Web App Slot.

References #

microsoft.web/sites/slots/containerlogs/download/action

#
Namespace
Microsoft.Web

Description

Download Web Apps Slots Container Logs.

References #

microsoft.web/sites/slots/continuouswebjobs/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Continuous Web Jobs.

References #

microsoft.web/sites/slots/continuouswebjobs/start/action

#
Namespace
Microsoft.Web

Description

Start Web Apps Slots Continuous Web Jobs.

References #

microsoft.web/sites/slots/continuouswebjobs/stop/action

#
Namespace
Microsoft.Web

Description

Stop Web Apps Slots Continuous Web Jobs.

References #

Microsoft.Web/sites/slots/Delete

#
Namespace
Microsoft.Web

Description

Delete an existing Web App Slot

References #

microsoft.web/sites/slots/deployments/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Deployments.

References #

microsoft.web/sites/slots/deployments/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Deployments.

References #

microsoft.web/sites/slots/deployWorkflowArtifacts/action

#
Namespace
Microsoft.Web

Description

Create the artifacts in a deployment slot in a Logic App.

References #

microsoft.web/sites/slots/diagnostics/analyses/execute/Action

#
Namespace
Microsoft.Web

Description

Run Web Apps Slots Diagnostics Analysis.

References #

microsoft.web/sites/slots/diagnostics/detectors/execute/Action

#
Namespace
Microsoft.Web

Description

Run Web Apps Slots Diagnostics Detector.

References #

microsoft.web/sites/slots/domainownershipidentifiers/delete

#
Namespace
Microsoft.Web

Description

Delete Web App Slots Domain Ownership Identifiers.

References #

microsoft.web/sites/slots/domainownershipidentifiers/write

#
Namespace
Microsoft.Web

Description

Update Web App Slots Domain Ownership Identifiers.

References #

microsoft.web/sites/slots/extensions/api/action

#
Namespace
Microsoft.Web

Description

Invoke App Service Slots Extensions APIs.

References #

microsoft.web/sites/slots/extensions/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Extensions.

References #

microsoft.web/sites/slots/functions/keys/delete

#
Namespace
Microsoft.Web

Description

Delete Function keys.

References #

microsoft.web/sites/slots/functions/keys/write

#
Namespace
Microsoft.Web

Description

Update Function keys.

References #

microsoft.web/sites/slots/functions/listkeys/action

#
Namespace
Microsoft.Web

Description

List Function keys.

References #

microsoft.web/sites/slots/functions/listsecrets/action

#
Namespace
Microsoft.Web

Description

List Secrets Web Apps Slots Functions.

References #

microsoft.web/sites/slots/host/functionkeys/delete

#
Namespace
Microsoft.Web

Description

Delete Functions Host Function keys.

References #

microsoft.web/sites/slots/host/functionkeys/write

#
Namespace
Microsoft.Web

Description

Update Functions Host Function keys.

References #

microsoft.web/sites/slots/host/listkeys/action

#
Namespace
Microsoft.Web

Description

List Functions Host keys.

References #

microsoft.web/sites/slots/host/sync/action

#
Namespace
Microsoft.Web

Description

Sync Function Triggers.

References #

microsoft.web/sites/slots/host/systemkeys/delete

#
Namespace
Microsoft.Web

Description

Delete Functions Host System keys.

References #

microsoft.web/sites/slots/host/systemkeys/write

#
Namespace
Microsoft.Web

Description

Update Functions Host System keys.

References #

microsoft.web/sites/slots/hostnamebindings/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Hostname Bindings.

References #

microsoft.web/sites/slots/hostnamebindings/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Hostname Bindings.

References #

microsoft.web/sites/slots/hybridconnection/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Hybrid Connection.

References #

microsoft.web/sites/slots/hybridconnection/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Hybrid Connection.

References #

microsoft.web/sites/slots/hybridconnectionnamespaces/relays/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Hybrid Connection Namespaces Relays.

References #

microsoft.web/sites/slots/hybridconnectionnamespaces/relays/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Hybrid Connection Namespaces Relays.

References #

microsoft.web/sites/slots/instances/processes/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Instances Processes.

References #

microsoft.web/sites/slots/instances/processes/stop/action

#
Namespace
Microsoft.Web

Description

Stop Web Apps Slots Instances Processes.

References #

microsoft.web/sites/slots/listbackups/action

#
Namespace
Microsoft.Web

Description

List Web App Slot backups.

References #

microsoft.web/sites/slots/listsyncfunctiontriggerstatus/action

#
Namespace
Microsoft.Web

Description

List Sync Function Trigger Status for deployment slot.

References #

microsoft.web/sites/slots/listworkflowsconnections/action

#
Namespace
Microsoft.Web

Description

List logic app's connections by its ID in a deployment slot in a Logic App.

References #

microsoft.web/sites/slots/networkConfig/delete

#
Namespace
Microsoft.Web

Description

Delete App Service Slots Network Configuration.

References #

microsoft.web/sites/slots/networkConfig/write

#
Namespace
Microsoft.Web

Description

Update App Service Slots Network Configuration.

References #

microsoft.web/sites/slots/networktrace/action

#
Namespace
Microsoft.Web

Description

Network Trace Web Apps Slots.

References #

microsoft.web/sites/slots/newpassword/action

#
Namespace
Microsoft.Web

Description

Newpassword Web Apps Slots.

References #

microsoft.web/sites/slots/premieraddons/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Premier Addons.

References #

microsoft.web/sites/slots/premieraddons/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Premier Addons.

References #

microsoft.web/sites/slots/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.Web

Description

Creates or updates the diagnostic setting for the resource

References #

microsoft.web/sites/slots/publiccertificates/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Public Certificates.

References #

microsoft.web/sites/slots/publiccertificates/write

#
Namespace
Microsoft.Web

Description

Create or Update Web Apps Slots Public Certificates.

References #

Microsoft.Web/sites/slots/publish/Action

#
Namespace
Microsoft.Web

Description

Publish a Web App Slot

References #

Microsoft.Web/sites/slots/publishxml/Action

#
Namespace
Microsoft.Web

Description

Get publishing profile xml for Web App Slot

References #

microsoft.web/sites/slots/recover/action

#
Namespace
Microsoft.Web

Description

Recover Web Apps Slots.

References #

Microsoft.Web/sites/slots/resetSlotConfig/Action

#
Namespace
Microsoft.Web

Description

Reset web app slot configuration

References #

Microsoft.Web/sites/slots/restart/Action

#
Namespace
Microsoft.Web

Description

Restart a Web App Slot

References #

microsoft.web/sites/slots/restore/write

#
Namespace
Microsoft.Web

Description

Restore Web Apps Slots.

References #

microsoft.web/sites/slots/restorefrombackupblob/action

#
Namespace
Microsoft.Web

Description

Restore Web Apps Slot From Backup Blob.

References #

microsoft.web/sites/slots/restorefromdeletedapp/action

#
Namespace
Microsoft.Web

Description

Restore Web App Slots From Deleted App.

References #

microsoft.web/sites/slots/restoresnapshot/action

#
Namespace
Microsoft.Web

Description

Restore Web Apps Slots Snapshots.

References #

Microsoft.Web/sites/slots/sitecontainers/Delete

#
Namespace
Microsoft.Web

Description

Delete Sitecontainers of an existing Web App's Slot

References #

Microsoft.Web/sites/slots/sitecontainers/Write

#
Namespace
Microsoft.Web

Description

Create new or update existing Sitecontainers of a Web App's Slot

References #

microsoft.web/sites/slots/siteextensions/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Site Extensions.

References #

microsoft.web/sites/slots/siteextensions/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Site Extensions.

References #

microsoft.web/sites/slots/slotcopy/action

#
Namespace
Microsoft.Web

Description

Copy content from one deployment slot to another.

References #

Microsoft.Web/sites/slots/slotsdiffs/Action

#
Namespace
Microsoft.Web

Description

Get differences in configuration between web app and slots

References #

Microsoft.Web/sites/slots/slotsswap/Action

#
Namespace
Microsoft.Web

Description

Swap Web App deployment slots

References #

Microsoft.Web/sites/slots/sourcecontrols/Delete

#
Namespace
Microsoft.Web

Description

Delete Web App Slot's source control configuration settings

References #

Microsoft.Web/sites/slots/sourcecontrols/Write

#
Namespace
Microsoft.Web

Description

Update Web App Slot's source control configuration settings

References #

Microsoft.Web/sites/slots/start/Action

#
Namespace
Microsoft.Web

Description

Start a Web App Slot

References #

Microsoft.Web/sites/slots/startDevSession/Action

#
Namespace
Microsoft.Web

Description

Start Dev Session for Web App Slot

References #

Microsoft.Web/sites/slots/stop/Action

#
Namespace
Microsoft.Web

Description

Stop a Web App Slot

References #

microsoft.web/sites/slots/sync/action

#
Namespace
Microsoft.Web

Description

Sync Web Apps Slots.

References #

microsoft.web/sites/slots/syncfunctiontriggers/action

#
Namespace
Microsoft.Web

Description

Sync Function Triggers for deployment slot.

References #

microsoft.web/sites/slots/triggeredwebjobs/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Triggered WebJobs.

References #

microsoft.web/sites/slots/triggeredwebjobs/run/action

#
Namespace
Microsoft.Web

Description

Run Web Apps Slots Triggered WebJobs.

References #

microsoft.web/sites/slots/virtualnetworkconnections/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Slots Virtual Network Connections.

References #

microsoft.web/sites/slots/virtualnetworkconnections/gateways/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Virtual Network Connections Gateways.

References #

microsoft.web/sites/slots/virtualnetworkconnections/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Slots Virtual Network Connections.

References #

Microsoft.Web/sites/slots/Write

#
Namespace
Microsoft.Web

Description

Create a new Web App Slot or update an existing one

References #

Microsoft.Web/sites/slotsdiffs/Action

#
Namespace
Microsoft.Web

Description

Get differences in configuration between web app and slots

References #

Microsoft.Web/sites/slotsswap/Action

#
Namespace
Microsoft.Web

Description

Swap Web App deployment slots

References #

Microsoft.Web/sites/sourcecontrols/Delete

#
Namespace
Microsoft.Web

Description

Delete Web App's source control configuration settings

References #

Microsoft.Web/sites/sourcecontrols/Write

#
Namespace
Microsoft.Web

Description

Update Web App's source control configuration settings

References #

Microsoft.Web/sites/start/Action

#
Namespace
Microsoft.Web

Description

Start a Web App

References #

Microsoft.Web/sites/startDevSession/Action

#
Namespace
Microsoft.Web

Description

Start Dev Session for a Web App

References #

Microsoft.Web/sites/stop/Action

#
Namespace
Microsoft.Web

Description

Stop a Web App

References #

microsoft.web/sites/sync/action

#
Namespace
Microsoft.Web

Description

Sync Web Apps.

References #

microsoft.web/sites/syncfunctiontriggers/action

#
Namespace
Microsoft.Web

Description

Sync Function Triggers.

References #

microsoft.web/sites/triggeredwebjobs/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Triggered WebJobs.

References #

microsoft.web/sites/triggeredwebjobs/run/action

#
Namespace
Microsoft.Web

Description

Run Web Apps Triggered WebJobs.

References #

microsoft.web/sites/virtualnetworkconnections/delete

#
Namespace
Microsoft.Web

Description

Delete Web Apps Virtual Network Connections.

References #

microsoft.web/sites/virtualnetworkconnections/gateways/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Virtual Network Connections Gateways.

References #

microsoft.web/sites/virtualnetworkconnections/write

#
Namespace
Microsoft.Web

Description

Update Web Apps Virtual Network Connections.

References #

Microsoft.Web/sites/Write

#
Namespace
Microsoft.Web

Description

Create a new Web App or update an existing one

References #

microsoft.web/sourcecontrols/write

#
Namespace
Microsoft.Web

Description

Update Source Controls.

References #

Microsoft.Web/staticSites/authproviders/listusers/Action

#
Namespace
Microsoft.Web

Description

List the users for a Static Site

References #

Microsoft.Web/staticSites/authproviders/users/Delete

#
Namespace
Microsoft.Web

Description

Delete a user for a Static Site

References #

Microsoft.Web/staticSites/authproviders/users/Write

#
Namespace
Microsoft.Web

Description

Update a user for a Static Site

References #

Microsoft.Web/staticSites/builds/config/Write

#
Namespace
Microsoft.Web

Description

Create or update app settings for a Static Site Build

References #

Microsoft.Web/staticSites/builds/databaseConnections/Delete

#
Namespace
Microsoft.Web

Description

Delete a Database Connection from a Static Site Build

References #

Microsoft.Web/staticSites/builds/databaseConnections/show/action

#
Namespace
Microsoft.Web

Description

Show details for a Database Connection for a Static Site Build

References #

Microsoft.Web/staticSites/builds/databaseConnections/Write

#
Namespace
Microsoft.Web

Description

Create or Update a Database Connection with a Static Site Build

References #

Microsoft.Web/staticSites/builds/Delete

#
Namespace
Microsoft.Web

Description

Delete a build for a Static Site

References #

Microsoft.Web/staticSites/builds/linkedBackends/Delete

#
Namespace
Microsoft.Web

Description

Unlink a Backend from a Static Site Build

References #

Microsoft.Web/staticSites/builds/linkedBackends/validate/action

#
Namespace
Microsoft.Web

Description

Validate a Linked Backend for a Static Site Build

References #

Microsoft.Web/staticSites/builds/linkedBackends/Write

#
Namespace
Microsoft.Web

Description

Register a Linked Backend with a Static Site Build

References #

Microsoft.Web/staticSites/builds/listappsettings/Action

#
Namespace
Microsoft.Web

Description

List app settings for a Static Site Build

References #

Microsoft.Web/staticSites/builds/listfunctionappsettings/Action

#
Namespace
Microsoft.Web

Description

List function app settings for a Static Site Build

References #

Microsoft.Web/staticSites/builds/showDatabaseConnections/action

#
Namespace
Microsoft.Web

Description

Show details for Database Connections for a Static Site Build

References #

Microsoft.Web/staticSites/builds/userProvidedFunctionApps/Delete

#
Namespace
Microsoft.Web

Description

Detach a User Provided Function App from a Static Site Build

References #

Microsoft.Web/staticSites/builds/userProvidedFunctionApps/Write

#
Namespace
Microsoft.Web

Description

Register a User Provided Function App with a Static Site Build

References #

Microsoft.Web/staticSites/builds/zipdeploy/action

#
Namespace
Microsoft.Web

Description

Deploy a Static Site Build from zipped content

References #

Microsoft.Web/staticSites/config/Write

#
Namespace
Microsoft.Web

Description

Create or update app settings for a Static Site

References #

Microsoft.Web/staticSites/createinvitation/action

#
Namespace
Microsoft.Web

Description

Creates invitiation link for static site user for a set of roles

References #

Microsoft.Web/staticSites/customdomains/Delete

#
Namespace
Microsoft.Web

Description

Delete a custom domain for a Static Site

References #

Microsoft.Web/staticSites/customdomains/validate/Action

#
Namespace
Microsoft.Web

Description

Validate a custom domain can be added to a Static Site

References #

Microsoft.Web/staticSites/customdomains/Write

#
Namespace
Microsoft.Web

Description

Create a custom domain for a Static Site

References #

Microsoft.Web/staticSites/databaseConnections/Delete

#
Namespace
Microsoft.Web

Description

Delete a Database Connection from a Static Site

References #

Microsoft.Web/staticSites/databaseConnections/show/action

#
Namespace
Microsoft.Web

Description

Show details for a Database Connection for a Static Site

References #

Microsoft.Web/staticSites/databaseConnections/Write

#
Namespace
Microsoft.Web

Description

Create or Update a Database Connection with a Static Site

References #

Microsoft.Web/staticSites/Delete

#
Namespace
Microsoft.Web

Description

Delete an existing Static Site

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "action": "Microsoft.Web/staticSites/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "action": "Microsoft.Web/staticSites/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "0acaaa56-0c0f-45b4-8a4e-a462fb8c04be",
  "EventDataId": "40ab81cd-7f69-e4bc-327b-b7b8a3eeec8c",
  "EventSubmissionTimestamp": "2026-07-03T02:16:36.6004923Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.WEB/STATICSITES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "message": "Microsoft.Web/staticSites/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "40ab81cd-7f69-e4bc-327b-b7b8a3eeec8c",
    "eventSubmissionTimestamp": "2026-07-03T02:16:36.6004923Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dstaticsite",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "message": "Microsoft.Web/staticSites/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "40ab81cd-7f69-e4bc-327b-b7b8a3eeec8c",
    "eventSubmissionTimestamp": "2026-07-03T02:16:36.6004923Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dstaticsite",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Web/staticSites/detach/Action

#
Namespace
Microsoft.Web

Description

Detach a Static Site from the currently linked repository

References #

Microsoft.Web/staticSites/getuser/Action

#
Namespace
Microsoft.Web

Description

Get a user's information for a Static Site

References #

Microsoft.Web/staticSites/linkedBackends/Delete

#
Namespace
Microsoft.Web

Description

Unlink a Backend from a Static Site

References #

Microsoft.Web/staticSites/linkedBackends/validate/action

#
Namespace
Microsoft.Web

Description

Validate a Linked Backend for a Static Site

References #

Microsoft.Web/staticSites/linkedBackends/Write

#
Namespace
Microsoft.Web

Description

Register a Linked Backend with a Static Site

References #

Microsoft.Web/staticSites/listappsettings/Action

#
Namespace
Microsoft.Web

Description

List app settings for a Static Site

References #

Microsoft.Web/staticSites/listConfiguredRoles/action

#
Namespace
Microsoft.Web

Description

Lists the roles configured for the static site.

References #

Microsoft.Web/staticSites/listfunctionappsettings/Action

#
Namespace
Microsoft.Web

Description

List function app settings for a Static Site

References #

Microsoft.Web/staticSites/listsecrets/action

#
Namespace
Microsoft.Web

Description

List the secrets for a Static Site

References #

Microsoft.Web/staticSites/networkConfigs/Delete

#
Namespace
Microsoft.Web

Description

Disconnects a network configuration from a Static Site

References #

Microsoft.Web/staticSites/networkConfigs/Write

#
Namespace
Microsoft.Web

Description

Updates network configuration for a Static Site

References #

Microsoft.Web/staticSites/privateEndpointConnectionProxies/Delete

#
Namespace
Microsoft.Web

Description

Delete Private Endpoint Connection Proxies for a Static Site

References #

Microsoft.Web/staticSites/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Web

Description

Validate Private Endpoint Connection Proxies for a Static Site

References #

Microsoft.Web/staticSites/privateEndpointConnectionProxies/Write

#
Namespace
Microsoft.Web

Description

Create or Update Private Endpoint Connection Proxies for a Static Site

References #

Microsoft.Web/staticSites/privateEndpointConnections/Delete

#
Namespace
Microsoft.Web

Description

Delete a Private Endpoint Connection for a Static Site

References #

Microsoft.Web/staticSites/privateEndpointConnections/Write

#
Namespace
Microsoft.Web

Description

Approve or Reject Private Endpoint Connection for a Static Site

References #

Microsoft.Web/staticSites/publish/action

#
Namespace
Microsoft.Web

Description

Check publish access to static web app

References #

Microsoft.Web/staticSites/resetapikey/Action

#
Namespace
Microsoft.Web

Description

Reset the api key for a Static Site

References #

Microsoft.Web/staticSites/showDatabaseConnections/action

#
Namespace
Microsoft.Web

Description

Show details for Database Connections for a Static Site

References #

Microsoft.Web/staticSites/userProvidedFunctionApps/Delete

#
Namespace
Microsoft.Web

Description

Detach a User Provided Function App from a Static Site

References #

Microsoft.Web/staticSites/userProvidedFunctionApps/Write

#
Namespace
Microsoft.Web

Description

Register a User Provided Function App with a Static Site

References #

Microsoft.Web/staticSites/validateCustomDomainOwnership/action

#
Namespace
Microsoft.Web

Description

Validate the custom domain ownership for a static site

References #

Microsoft.Web/staticSites/Write

#
Namespace
Microsoft.Web

Description

Create a new Static Site or update an existing one

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "action": "Microsoft.Web/staticSites/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "action": "Microsoft.Web/staticSites/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "61ccd227-e1e5-4943-9135-05bec6b08e02",
  "EventDataId": "b78ec877-ee19-082a-c9e9-04806b9cdc46",
  "EventSubmissionTimestamp": "2026-07-03T02:15:31.3370071Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.WEB/STATICSITES/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "message": "Microsoft.Web/staticSites/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b78ec877-ee19-082a-c9e9-04806b9cdc46",
    "eventSubmissionTimestamp": "2026-07-03T02:15:31.3370071Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dstaticsite",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Web/staticSites/dwhc6a93dstaticsite",
    "message": "Microsoft.Web/staticSites/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b78ec877-ee19-082a-c9e9-04806b9cdc46",
    "eventSubmissionTimestamp": "2026-07-03T02:15:31.3370071Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dstaticsite",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.WEB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.WEB",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.Web/staticSites/zipdeploy/action

#
Namespace
Microsoft.Web

Description

Deploy a Static Site from zipped content

References #

microsoft.web/unregister/action

#
Namespace
Microsoft.Web

Description

Unregister Microsoft.Web resource provider for the subscription.

References #

microsoft.web/validate/action

#

microsoft.web/verifyhostingenvironmentvnet/action

#
Namespace
Microsoft.Web

Description

Verify Hosting Environment Vnet.

References #

Microsoft.Web/workerApps/delete

#
Namespace
Microsoft.Web

Description

Delete a Worker App

References #

Microsoft.Web/workerApps/write

#
Namespace
Microsoft.Web

Description

Create a Worker App or update an existing one

References #

Microsoft.Web/deletedSites/restore/action

#
Namespace
Microsoft.Web

Description

Restore Deleted Web App

References #

Microsoft.Web/locations/deletedSites/restore/action

#
Namespace
Microsoft.Web

Description

Restore Deleted Web App at location

References #