Skip to content

Microsoft.ContainerService/managedClusters/listClusterUserCredential/action

Azure

Microsoft.ContainerService/managedClusters/listClusterUserCredential/action

service: Azure - Container Service
techniques:

Event

Access depends on cluster authentication configuration. With Entra integration, the user must authenticate and receives access according to effective user/group authorization. Without Entra integration, Microsoft documents clusterUser as having the same effect as clusterAdmin; the name does not guarantee restricted access.

Security Context

Credential exposure is contextual (T1552): an Entra login configuration is different from a usable local credential. Approved client setup is common, and downloading kubeconfig alone does not demonstrate Kubernetes API use.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerService/managedClusters/listClusterUserCredential/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Establish whether the cluster uses Entra integration, local accounts, and Azure or Kubernetes RBAC.
  3. Inspect the returned configuration’s authentication method securely and determine effective permissions and network reachability.
  4. Correlate sign-ins and Kubernetes audit logs to establish actual use and actions.

Sample Event

Synthetic scenario. The sample records kubeconfig retrieval but omits its contents and the cluster’s authentication configuration. Its resulting access level cannot be inferred from this record.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.ContainerService/managedClusters/listClusterUserCredential/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000011000000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000011000001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T22:48:32.5172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000011000010",
"operationName": {
"value": "Microsoft.ContainerService/managedClusters/listClusterUserCredential/action",
"localizedValue": "Get an AKS Managed Cluster's user Cluster Credentials"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.ContainerService",
"localizedValue": "Microsoft.ContainerService"
},
"resourceType": {
"value": "Microsoft.ContainerService/managedClusters",
"localizedValue": "Microsoft.ContainerService/managedClusters"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T22:48:33.0218732Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod",
"message": "Microsoft.ContainerService/managedClusters/listClusterUserCredential/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000011000011",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod/listClusterUserCredential?api-version=2024-02-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.