Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action
Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action
Event
Retrieves local administrative kubeconfig credentials when local accounts are enabled. These certificate credentials use a different authentication path from Entra sign-in. Disabling local accounts blocks this retrieval; certificate validity, rotation, and API-server reachability also constrain use.
Security Context
Unauthorized retrieval can expose administrative credentials (T1552). Azure roles permitting retrieval are distinct from Kubernetes authorization. The event does not establish that the kubeconfig was subsequently used.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify local-account settings and the caller’s credential-retrieval permissions.
- Review certificate validity/rotation and API-server network restrictions without copying private credential material into notes.
- Correlate Kubernetes audit activity with the retrieved credential context; do not assume an Entra user sign-in accompanies local certificate use.
Sample Event
Synthetic scenario. The sample shows successful admin-credential retrieval, with kubeconfig contents intentionally absent. It does not show a cluster operation.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010111100", "description": "", "eventDataId": "90000000-0000-4000-8000-000010111101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T22:51:08.7172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010111110", "operationName": { "value": "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action", "localizedValue": "Get an AKS Managed Cluster's admin Cluster Credentials" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.ContainerService", "localizedValue": "Microsoft.ContainerService" }, "resourceType": { "value": "Microsoft.ContainerService/managedClusters", "localizedValue": "Microsoft.ContainerService/managedClusters" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T22:51:09.1182233Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod", "message": "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010111111", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod/listClusterAdminCredential?api-version=2024-02-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...