Skip to content

Microsoft.Network/networkSecurityGroups/delete

Azure

Microsoft.Network/networkSecurityGroups/delete

service: Azure - Network Security Group
techniques:

Event

An NSG cannot be deleted while associated with a subnet or network interface. It must first be dissociated. Consequently this delete event does not itself detach an active NSG or establish unrestricted access; earlier association changes and other network controls determine exposure.

Security Context

Unauthorized removal can be part of cloud-firewall impairment (T1686.001). Routine decommissioning produces the same event. Check subnet/NIC NSGs, routes, host firewalls, and public connectivity rather than equating deletion with internet reachability.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/networkSecurityGroups/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover the NSG rules and correlate preceding subnet/NIC dissociation or replacement changes.
  3. Inspect effective security rules and all remaining controls on the affected traffic path.
  4. Verify actual connectivity changes and subsequent traffic, alongside approved decommissioning.

Sample Event

Synthetic scenario. The sample records deletion of nsg-demiguise-prod. It contains no association history or evidence of a newly reachable workload.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Network/networkSecurityGroups/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-demiguise-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "nsgDel206ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100001111",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100010000",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:31:18.5042088Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100010001",
"operationName": {
"value": "Microsoft.Network/networkSecurityGroups/delete",
"localizedValue": "Delete Network Security Group"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Network",
"localizedValue": "Microsoft.Network"
},
"resourceType": {
"value": "Microsoft.Network/networkSecurityGroups",
"localizedValue": "Microsoft.Network/networkSecurityGroups"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-demiguise-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:31:19.0851117Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-demiguise-prod",
"message": "Microsoft.Network/networkSecurityGroups/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.