Microsoft.ContainerService/managedClusters/listClusterUserCredential/action
Microsoft.ContainerService/managedClusters/listClusterUserCredential/action
Event
Access depends on cluster authentication configuration. With Entra integration, the user must authenticate and receives access according to effective user/group authorization. Without Entra integration, Microsoft documents clusterUser as having the same effect as clusterAdmin; the name does not guarantee restricted access.
Security Context
Credential exposure is contextual (T1552): an Entra login configuration is different from a usable local credential. Approved client setup is common, and downloading kubeconfig alone does not demonstrate Kubernetes API use.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerService/managedClusters/listClusterUserCredential/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Establish whether the cluster uses Entra integration, local accounts, and Azure or Kubernetes RBAC.
- Inspect the returned configuration’s authentication method securely and determine effective permissions and network reachability.
- Correlate sign-ins and Kubernetes audit logs to establish actual use and actions.
Sample Event
Synthetic scenario. The sample records kubeconfig retrieval but omits its contents and the cluster’s authentication configuration. Its resulting access level cannot be inferred from this record.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.ContainerService/managedClusters/listClusterUserCredential/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000011000000", "description": "", "eventDataId": "90000000-0000-4000-8000-000011000001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T22:48:32.5172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000011000010", "operationName": { "value": "Microsoft.ContainerService/managedClusters/listClusterUserCredential/action", "localizedValue": "Get an AKS Managed Cluster's user Cluster Credentials" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.ContainerService", "localizedValue": "Microsoft.ContainerService" }, "resourceType": { "value": "Microsoft.ContainerService/managedClusters", "localizedValue": "Microsoft.ContainerService/managedClusters" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T22:48:33.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod", "message": "Microsoft.ContainerService/managedClusters/listClusterUserCredential/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000011000011", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod/listClusterUserCredential?api-version=2024-02-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...