Skip to content

Microsoft.Network/networkSecurityGroups/securityRules/write

Azure

Microsoft.Network/networkSecurityGroups/securityRules/write

service: Azure - Network Security Group
techniques:

Event

Writes a rule’s direction, priority, protocol, address/port matches, and allow/deny action. Effective access depends on the complete ruleset and all NSGs applied to the traffic path. An allow rule does not create a public IP, route, listening service, or successful authenticated session.

Security Context

Unauthorized permissive rules can impair cloud-firewall controls (T1686.001). Approved connectivity changes are common. A wildcard destination in this sample is not a specific VM private IP, and internet-wide reachability still requires a viable network path.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/networkSecurityGroups/securityRules/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Compare the prior/new rule and approved purpose, including priority and wildcard source/destination ranges.
  3. Inspect subnet/NIC associations, effective rules, public IP/NAT, routing, host firewall, and service state.
  4. Correlate actual connection attempts and authentication outcomes before asserting RDP access or lateral movement.

Sample Event

Synthetic scenario. The rule allows inbound TCP/3389 with wildcard source and destination at priority 100. This is a configuration illustration, not proof that any VM can be reached from the internet.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Network/networkSecurityGroups/securityRules/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-vm-demiguise-prod/securityRules/allow-rdp-from-anywhere"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "nsgRule207ExampleUtid",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100010010",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100010011",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:33:54.1148902Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100010100",
"operationName": {
"value": "Microsoft.Network/networkSecurityGroups/securityRules/write",
"localizedValue": "Create or update Network Security Rule"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Network",
"localizedValue": "Microsoft.Network"
},
"resourceType": {
"value": "Microsoft.Network/networkSecurityGroups/securityRules",
"localizedValue": "Microsoft.Network/networkSecurityGroups/securityRules"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-vm-demiguise-prod/securityRules/allow-rdp-from-anywhere",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T18:33:54.7058821Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-vm-demiguise-prod/securityRules/allow-rdp-from-anywhere",
"message": "Microsoft.Network/networkSecurityGroups/securityRules/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"properties\":{\"protocol\":\"Tcp\",\"sourcePortRange\":\"*\",\"destinationPortRange\":\"3389\",\"sourceAddressPrefix\":\"*\",\"destinationAddressPrefix\":\"*\",\"access\":\"Allow\",\"priority\":100,\"direction\":\"Inbound\"}}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.