Microsoft.Insights/diagnosticSettings/delete
Microsoft.Insights/diagnosticSettings/delete
Event
Removes the categories and destinations configured in that setting. Other diagnostic settings and retained destination data can remain. The subscription Activity Log retains its own records for 90 days independently of this export configuration.
Security Context
Unauthorized removal can impair cloud-log collection (T1685.002). It does not prove that all logging stopped. User Access Administrator from elevateAccess does not itself grant permission to delete diagnostic settings.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Insights/diagnosticSettings/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover the exact resource scope, enabled categories, and destinations from prior configuration.
- Review effective caller permissions and approved routing changes, including any replacement setting.
- Confirm destination ingestion gaps and remaining routes; preserve existing source and destination records.
Sample Event
Synthetic scenario. The sample deletes a subscription-level setting. Its name suggests Log Analytics, but the prior destination and enabled categories are not shown.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Insights/diagnosticSettings/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/microsoft.insights/diagnosticSettings/fantasticlogs-activity-to-loganalytics" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "iat": "1776592800", "nbf": "1776592800", "exp": "1776681600", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "appidacr": "0", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Malfoy", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Draco", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "draco@fantasticlogs.cloud", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "f58310d9-a9f6-439a-9e8d-f62e7b41a168", "uti": "diagDel200ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000011111010", "description": "", "eventDataId": "90000000-0000-4000-8000-000011111011", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:38:11.4302187Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000011111100", "operationName": { "value": "Microsoft.Insights/diagnosticSettings/delete", "localizedValue": "Deletes the diagnostic setting" }, "resourceGroupName": "", "resourceProviderName": { "value": "Microsoft.Insights", "localizedValue": "Microsoft Insights" }, "resourceType": { "value": "Microsoft.Insights/diagnosticSettings", "localizedValue": "Microsoft.Insights/diagnosticSettings" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/microsoft.insights/diagnosticSettings/fantasticlogs-activity-to-loganalytics", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:38:12.0148921Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/microsoft.insights/diagnosticSettings/fantasticlogs-activity-to-loganalytics", "message": "Microsoft.Insights/diagnosticSettings/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...