Microsoft.Compute/sshPublicKeys/write
Microsoft.Compute/sshPublicKeys/write
Event
Stores a reusable SSH public key as an Azure resource. Creating or changing this resource does not install the key into existing VMs’ authorized_keys files, generate a private key through this write alone, or establish an SSH connection.
Security Context
Unexpected key-resource creation can inform a wider access investigation, but it is not itself SSH authorized-key persistence or lateral movement. No ATT&CK technique is assigned without a corresponding installation or use event. Legitimate VM provisioning uses stored public keys.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Compute/sshPublicKeys/write. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId, properties.requestbody | Key resource and submitted public key/location where recorded. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the key’s fingerprint, owner, and approved provisioning purpose.
- Correlate deployments, extensions, or Run Command with actual guest authorized_keys changes.
- Check SSH authentication and network reachability separately; storing a public key does not establish host access.
Sample Event
Synthetic scenario. The sample stores a valid illustrative RSA public key. It was generated locally for this example and its private key discarded; no VM was changed or contacted.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Compute/sshPublicKeys/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010100100", "description": "", "eventDataId": "90000000-0000-4000-8000-000010100101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T21:54:08.5183194Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010100110", "operationName": { "value": "Microsoft.Compute/sshPublicKeys/write", "localizedValue": "Create or update an SSH public key resource" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Compute", "localizedValue": "Microsoft.Compute" }, "resourceType": { "value": "Microsoft.Compute/sshPublicKeys", "localizedValue": "Microsoft.Compute/sshPublicKeys" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Created", "localizedValue": "Created (HTTP Status Code: 201)" }, "submissionTimestamp": "2026-04-15T21:54:09.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Created", "serviceRequestId": null, "requestbody": "{\"location\":\"eastus\",\"properties\":{\"publicKey\":\"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCSFAOzPrWNzzx1t+oKZz+tec7iBOVi7G8Qqt0pR7IgPqkM+d/ZoTjNQNveR6ZBbXkECM0a/hmYp31MsoILkko0HXPunBEvi6mvjwbC0fSIOY1meuDuckdVUgfvoyyJSKbRh3gQKNuYlD6rDOsedot7u3zXD0wUgnFrL7kBSoOmc7s4EV0FNC8dyoaQd0fLXbyKguQLYFx9ddrd5QwQccCV4TnSaXIwvgCYYFCi5RLDJjN/nlB8aJkI2HJIbSbcE1MbvqO6ffnjnF/gVzbI/vA5LlLNvdsdYd3Z0Wbs/GiIVoP4P7oTeg1e9Sgo5Qo+xRD3KM1iyQjAn83U6bGPp+UX synthetic-review-example\"}}", "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666", "message": "Microsoft.Compute/sshPublicKeys/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010100111", "clientIpAddress": "203.0.113.66", "method": "PUT", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/sshPublicKeys/draco-ssh-666?api-version=2024-03-01" }, "identity": null}