Skip to content

Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action

Azure

Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action

service: Azure - Container Service
techniques:

Event

Retrieves local administrative kubeconfig credentials when local accounts are enabled. These certificate credentials use a different authentication path from Entra sign-in. Disabling local accounts blocks this retrieval; certificate validity, rotation, and API-server reachability also constrain use.

Security Context

Unauthorized retrieval can expose administrative credentials (T1552). Azure roles permitting retrieval are distinct from Kubernetes authorization. The event does not establish that the kubeconfig was subsequently used.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify local-account settings and the caller’s credential-retrieval permissions.
  3. Review certificate validity/rotation and API-server network restrictions without copying private credential material into notes.
  4. Correlate Kubernetes audit activity with the retrieved credential context; do not assume an Entra user sign-in accompanies local certificate use.

Sample Event

Synthetic scenario. The sample shows successful admin-credential retrieval, with kubeconfig contents intentionally absent. It does not show a cluster operation.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010111100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010111101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T22:51:08.7172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010111110",
"operationName": {
"value": "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action",
"localizedValue": "Get an AKS Managed Cluster's admin Cluster Credentials"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.ContainerService",
"localizedValue": "Microsoft.ContainerService"
},
"resourceType": {
"value": "Microsoft.ContainerService/managedClusters",
"localizedValue": "Microsoft.ContainerService/managedClusters"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T22:51:09.1182233Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod",
"message": "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010111111",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod/listClusterAdminCredential?api-version=2024-02-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.