Skip to content

Microsoft.Insights/activityLogAlerts/delete

Azure

Microsoft.Insights/activityLogAlerts/delete

service: Azure - Monitor
techniques:

Event

Removes one rule that evaluates Activity Log events and invokes configured actions. It does not delete the underlying Activity Log or action group, nor retract notifications already sent.

Security Context

Unauthorized removal can impair detection (T1685) if the rule was enabled and covered relevant events. Approved rule retirement or deduplication is also common. The rule name does not establish its actual conditions.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Insights/activityLogAlerts/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover prior scopes, conditions, enabled state, and linked action groups.
  3. Check overlapping rules, prior firings, delivered notifications, and the approved replacement or retirement.
  4. Establish the future detection gap; deleting a rule does not retroactively suppress a previous lock-removal alert.

Sample Event

Synthetic scenario. The sample deletes a rule named alert-rg-cannotdelete-removed. Its prior configuration and notification history are absent.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Insights/activityLogAlerts/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Insights/activityLogAlerts/alert-rg-cannotdelete-removed"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000011011000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000011011001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T20:24:42.7172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000011011010",
"operationName": {
"value": "Microsoft.Insights/activityLogAlerts/delete",
"localizedValue": "Delete Activity Log Alert"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Insights",
"localizedValue": "Microsoft Insights"
},
"resourceType": {
"value": "Microsoft.Insights/activityLogAlerts",
"localizedValue": "Microsoft.Insights/activityLogAlerts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Insights/activityLogAlerts/alert-rg-cannotdelete-removed",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T20:24:43.0218732Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Insights/activityLogAlerts/alert-rg-cannotdelete-removed",
"message": "Microsoft.Insights/activityLogAlerts/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000011011011",
"clientIpAddress": "203.0.113.66",
"method": "DELETE",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Insights/activityLogAlerts/alert-rg-cannotdelete-removed?api-version=2020-10-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.