Microsoft.HybridCompute/machines/extensions/delete
Microsoft.HybridCompute/machines/extensions/delete
Event
Removes the specified Arc extension resource through its handler lifecycle. The effect on installed software depends on the extension and host state. An MDE.Linux resource name is not enough to prove sensor uninstall, offboarding, or lost telemetry.
Security Context
Unauthorized removal of a security extension can impair defenses (contextual T1685). Agent repair and planned retirement also use this operation. HTTP 202 acceptance does not establish completed removal or the endpoint’s protection state.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.HybridCompute/machines/extensions/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover extension publisher, type, version, and configuration and compare with approved maintenance.
- Follow removal to completion and inspect handler logs, host services, and Defender onboarding/protection state.
- Check actual telemetry continuity and any policy-driven reinstallation; distinguish offboarding from uninstall.
Sample Event
Synthetic scenario. The sample records an accepted deletion request for an extension named MDE.Linux. No host-side result or telemetry gap is shown.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.HybridCompute/machines/extensions/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.HybridCompute/machines/arc-onprem-pipeline-01/extensions/MDE.Linux" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000011010100", "description": "", "eventDataId": "90000000-0000-4000-8000-000011010101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T23:18:08.7172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000011010110", "operationName": { "value": "Microsoft.HybridCompute/machines/extensions/delete", "localizedValue": "Delete Machine Extension" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.HybridCompute", "localizedValue": "Microsoft.HybridCompute" }, "resourceType": { "value": "Microsoft.HybridCompute/machines/extensions", "localizedValue": "Microsoft.HybridCompute/machines/extensions" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.HybridCompute/machines/arc-onprem-pipeline-01/extensions/MDE.Linux", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Accepted", "localizedValue": "Accepted (HTTP Status Code: 202)" }, "submissionTimestamp": "2026-04-15T23:18:09.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Accepted", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.HybridCompute/machines/arc-onprem-pipeline-01/extensions/MDE.Linux", "message": "Microsoft.HybridCompute/machines/extensions/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000011010111", "clientIpAddress": "203.0.113.66", "method": "DELETE", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.HybridCompute/machines/arc-onprem-pipeline-01/extensions/MDE.Linux?api-version=2024-07-10" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...