Skip to content

Microsoft.Compute/sshPublicKeys/write

Azure

Microsoft.Compute/sshPublicKeys/write

service: Azure - Compute
tactics:
techniques:

Event

Stores a reusable SSH public key as an Azure resource. Creating or changing this resource does not install the key into existing VMs’ authorized_keys files, generate a private key through this write alone, or establish an SSH connection.

Security Context

Unexpected key-resource creation can inform a wider access investigation, but it is not itself SSH authorized-key persistence or lateral movement. No ATT&CK technique is assigned without a corresponding installation or use event. Legitimate VM provisioning uses stored public keys.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Compute/sshPublicKeys/write. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
resourceId, properties.requestbodyKey resource and submitted public key/location where recorded.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the key’s fingerprint, owner, and approved provisioning purpose.
  3. Correlate deployments, extensions, or Run Command with actual guest authorized_keys changes.
  4. Check SSH authentication and network reachability separately; storing a public key does not establish host access.

Sample Event

Synthetic scenario. The sample stores a valid illustrative RSA public key. It was generated locally for this example and its private key discarded; no VM was changed or contacted.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Compute/sshPublicKeys/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010100100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010100101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T21:54:08.5183194Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010100110",
"operationName": {
"value": "Microsoft.Compute/sshPublicKeys/write",
"localizedValue": "Create or update an SSH public key resource"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Compute",
"localizedValue": "Microsoft.Compute"
},
"resourceType": {
"value": "Microsoft.Compute/sshPublicKeys",
"localizedValue": "Microsoft.Compute/sshPublicKeys"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T21:54:09.0218732Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"requestbody": "{\"location\":\"eastus\",\"properties\":{\"publicKey\":\"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCSFAOzPrWNzzx1t+oKZz+tec7iBOVi7G8Qqt0pR7IgPqkM+d/ZoTjNQNveR6ZBbXkECM0a/hmYp31MsoILkko0HXPunBEvi6mvjwbC0fSIOY1meuDuckdVUgfvoyyJSKbRh3gQKNuYlD6rDOsedot7u3zXD0wUgnFrL7kBSoOmc7s4EV0FNC8dyoaQd0fLXbyKguQLYFx9ddrd5QwQccCV4TnSaXIwvgCYYFCi5RLDJjN/nlB8aJkI2HJIbSbcE1MbvqO6ffnjnF/gVzbI/vA5LlLNvdsdYd3Z0Wbs/GiIVoP4P7oTeg1e9Sgo5Qo+xRD3KM1iyQjAn83U6bGPp+UX synthetic-review-example\"}}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666",
"message": "Microsoft.Compute/sshPublicKeys/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010100111",
"clientIpAddress": "203.0.113.66",
"method": "PUT",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666?api-version=2024-03-01"
},
"identity": null
}

Sources

Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.