Microsoft.Compute/disks/beginGetAccess/action
Microsoft.Compute/disks/beginGetAccess/action
Event
Requests time-limited SAS access to a managed disk. Inspect access mode and duration; the illustrative request asks for Read. A 202 response can represent asynchronous acceptance and must be followed to final status. Availability and use depend on resource state and configured export/network controls.
Security Context
Unauthorized export access can prepare cloud-data collection (contextual T1530). Backup and migration are common. Issuing a SAS does not prove bytes were downloaded or transferred to a different cloud account, so T1537 is not assigned to this event alone.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Compute/disks/beginGetAccess/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId, properties.requestbody | Target, access mode, duration, and optional guest-state request. |
status, subStatus, correlationId | Request and asynchronous outcome; no live SAS belongs in investigation notes. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify export approval, resource ownership, disk/snapshot state, and applicable network/authentication restrictions.
- Confirm final access-grant outcome, expiration/revocation, and any resulting transfer evidence.
- Identify actual destination and bytes accessed before claiming exfiltration. An unrelated CopyBlob example is not corroborating evidence.
Sample Event
Synthetic scenario. The sample requests one hour of read access. It does not show a returned SAS, completed VHD download, or a linked copy operation.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Compute/disks/beginGetAccess/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/disks/vm-demiguise-infer-001-osdisk" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010011100", "description": "", "eventDataId": "90000000-0000-4000-8000-000010011101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T21:42:18.7382194Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010011110", "operationName": { "value": "Microsoft.Compute/disks/beginGetAccess/action", "localizedValue": "Get Disk SAS URI" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Compute", "localizedValue": "Microsoft.Compute" }, "resourceType": { "value": "Microsoft.Compute/disks", "localizedValue": "Microsoft.Compute/disks" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/disks/vm-demiguise-infer-001-osdisk", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Accepted", "localizedValue": "Accepted (HTTP Status Code: 202)" }, "submissionTimestamp": "2026-04-15T21:42:19.0184217Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Accepted", "serviceRequestId": null, "requestbody": "{\"access\":\"Read\",\"durationInSeconds\":3600,\"getSecureVMGuestStateSAS\":false}", "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/disks/vm-demiguise-infer-001-osdisk", "message": "Microsoft.Compute/disks/beginGetAccess/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010011111", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/disks/vm-demiguise-infer-001-osdisk/beginGetAccess?api-version=2023-10-02" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.