Microsoft.Compute/virtualMachines/delete
Microsoft.Compute/virtualMachines/delete
Event
Deletes the VM resource asynchronously. Retention or deletion of attached disks and network interfaces depends on their configured deleteOption values. forceDeletion controls the deletion procedure; it is not a rule that deletes disks in the same resource group. Inspect prior VM configuration and final resource state.
Security Context
Malicious deletion can destroy data or remove forensic artifacts (contextual T1485/T1578.003). Approved decommissioning is common. VM deletion does not necessarily delete retained disks, backups, or exported logs, and a 202 response is not proof that every resource is gone.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Compute/virtualMachines/delete. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId, httpRequest | VM target and deletion request; forceDeletion if supplied. |
status, subStatus, correlationId | Operation outcome and asynchronous follow-up. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify decommission approval and recover prior disk/NIC deleteOption settings.
- Follow deletion to completion and inventory retained/deleted disks, network resources, backups, and logs.
- Assess workload outage and actual data/evidence loss; do not invent a preceding snapshot or export chain.
Sample Event
Synthetic scenario. The sample records an accepted VM deletion request. It does not show disk deleteOption values, completed removal, or prior exfiltration.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Compute/virtualMachines/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010101000", "description": "", "eventDataId": "90000000-0000-4000-8000-000010101001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T22:08:42.7172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010101010", "operationName": { "value": "Microsoft.Compute/virtualMachines/delete", "localizedValue": "Delete Virtual Machine" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Compute", "localizedValue": "Microsoft.Compute" }, "resourceType": { "value": "Microsoft.Compute/virtualMachines", "localizedValue": "Microsoft.Compute/virtualMachines" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Accepted", "localizedValue": "Accepted (HTTP Status Code: 202)" }, "submissionTimestamp": "2026-04-15T22:08:43.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Accepted", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001", "message": "Microsoft.Compute/virtualMachines/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010101011", "clientIpAddress": "203.0.113.66", "method": "DELETE", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001?api-version=2024-03-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Impact Defense Impairment
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1578.003 — Delete Cloud Instance — An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence. Deleting an instance or virtual machine can remove valuable forensic artifacts and other evidence of suspicious behavior if the instance...