Microsoft.Network/networkSecurityGroups/delete
Microsoft.Network/networkSecurityGroups/delete
Event
An NSG cannot be deleted while associated with a subnet or network interface. It must first be dissociated. Consequently this delete event does not itself detach an active NSG or establish unrestricted access; earlier association changes and other network controls determine exposure.
Security Context
Unauthorized removal can be part of cloud-firewall impairment (T1686.001). Routine decommissioning produces the same event. Check subnet/NIC NSGs, routes, host firewalls, and public connectivity rather than equating deletion with internet reachability.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/networkSecurityGroups/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover the NSG rules and correlate preceding subnet/NIC dissociation or replacement changes.
- Inspect effective security rules and all remaining controls on the affected traffic path.
- Verify actual connectivity changes and subsequent traffic, alongside approved decommissioning.
Sample Event
Synthetic scenario. The sample records deletion of nsg-demiguise-prod. It contains no association history or evidence of a newly reachable workload.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Network/networkSecurityGroups/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-demiguise-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "nsgDel206ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100001111", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010000", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:31:18.5042088Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100010001", "operationName": { "value": "Microsoft.Network/networkSecurityGroups/delete", "localizedValue": "Delete Network Security Group" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Network", "localizedValue": "Microsoft.Network" }, "resourceType": { "value": "Microsoft.Network/networkSecurityGroups", "localizedValue": "Microsoft.Network/networkSecurityGroups" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-demiguise-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:31:19.0851117Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-demiguise-prod", "message": "Microsoft.Network/networkSecurityGroups/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.