Skip to content

Microsoft.Insights/diagnosticSettings/delete

Azure

Microsoft.Insights/diagnosticSettings/delete

service: Azure - Monitor
techniques:

Event

Removes the categories and destinations configured in that setting. Other diagnostic settings and retained destination data can remain. The subscription Activity Log retains its own records for 90 days independently of this export configuration.

Security Context

Unauthorized removal can impair cloud-log collection (T1685.002). It does not prove that all logging stopped. User Access Administrator from elevateAccess does not itself grant permission to delete diagnostic settings.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Insights/diagnosticSettings/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover the exact resource scope, enabled categories, and destinations from prior configuration.
  3. Review effective caller permissions and approved routing changes, including any replacement setting.
  4. Confirm destination ingestion gaps and remaining routes; preserve existing source and destination records.

Sample Event

Synthetic scenario. The sample deletes a subscription-level setting. Its name suggests Log Analytics, but the prior destination and enabled categories are not shown.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Insights/diagnosticSettings/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/microsoft.insights/diagnosticSettings/fantasticlogs-activity-to-loganalytics"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"iat": "1776592800",
"nbf": "1776592800",
"exp": "1776681600",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Malfoy",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Draco",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "draco@fantasticlogs.cloud",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "f58310d9-a9f6-439a-9e8d-f62e7b41a168",
"uti": "diagDel200ExampleUti",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000011111010",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000011111011",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:38:11.4302187Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000011111100",
"operationName": {
"value": "Microsoft.Insights/diagnosticSettings/delete",
"localizedValue": "Deletes the diagnostic setting"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Insights",
"localizedValue": "Microsoft Insights"
},
"resourceType": {
"value": "Microsoft.Insights/diagnosticSettings",
"localizedValue": "Microsoft.Insights/diagnosticSettings"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/microsoft.insights/diagnosticSettings/fantasticlogs-activity-to-loganalytics",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:38:12.0148921Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/microsoft.insights/diagnosticSettings/fantasticlogs-activity-to-loganalytics",
"message": "Microsoft.Insights/diagnosticSettings/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.