Microsoft.Authorization/roleAssignments/delete
Microsoft.Authorization/roleAssignments/delete
Event
Removes the grant represented by a role-assignment resource. Resolve its principal, role definition, and scope from available response data or earlier inventory. Other direct, group-based, or inherited assignments can preserve access, and authorization changes can take time to propagate.
Security Context
Malicious revocation may deny account access (T1531). Routine offboarding and least-privilege cleanup use the same API. Removing one Reader assignment does not prove the whole security team lost visibility or that the user lost every access path.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/roleAssignments/delete. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId, properties.responseBody | Assignment ID and deleted assignment details if present. |
caller, status, correlationId | Deleting actor, recorded outcome, and related changes. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the revocation request and resolve the affected principal/role/scope.
- Evaluate remaining assignments, group memberships, inherited access, and propagation.
- Correlate access failures and incident-response disruption before asserting lockout.
Sample Event
Synthetic scenario. The illustrative response identifies a subscription Reader grant for Neville. Remaining permissions and actual loss of visibility are unknown.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Authorization/roleAssignments/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000000000100" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "18d7d88d-d35e-4fb5-a5c3-7773c20a72d9" }, "correlationId": "90000000-0000-4000-8000-000001111100", "description": "", "eventDataId": "90000000-0000-4000-8000-000001111101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T20:32:18.4172593Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000001111110", "operationName": { "value": "Microsoft.Authorization/roleAssignments/delete", "localizedValue": "Delete role assignment" }, "resourceGroupName": "", "resourceProviderName": { "value": "Microsoft.Authorization", "localizedValue": "Microsoft.Authorization" }, "resourceType": { "value": "Microsoft.Authorization/roleAssignments", "localizedValue": "Microsoft.Authorization/roleAssignments" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000000000100", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T20:32:18.9148229Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "responseBody": "{\"properties\":{\"roleDefinitionId\":\"/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7\",\"principalId\":\"30000000-0000-4000-8000-000000000100\",\"principalType\":\"User\",\"scope\":\"/subscriptions/20000000-0000-4000-8000-000000000001\",\"createdOn\":\"2025-09-12T08:14:03.0184217Z\",\"updatedOn\":\"2025-09-12T08:14:03.0184217Z\",\"createdBy\":\"30000000-0000-4000-8000-000000000001\",\"updatedBy\":\"30000000-0000-4000-8000-001010011010\"},\"id\":\"/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000000000100\",\"type\":\"Microsoft.Authorization/roleAssignments\",\"name\":\"60000000-0000-4000-8000-000000000100\"}", "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000000000100", "message": "Microsoft.Authorization/roleAssignments/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000001111111", "clientIpAddress": "203.0.113.66", "method": "DELETE", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000000000100?api-version=2022-04-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....