Microsoft.Network/networkSecurityGroups/securityRules/write
Microsoft.Network/networkSecurityGroups/securityRules/write
Event
Writes a rule’s direction, priority, protocol, address/port matches, and allow/deny action. Effective access depends on the complete ruleset and all NSGs applied to the traffic path. An allow rule does not create a public IP, route, listening service, or successful authenticated session.
Security Context
Unauthorized permissive rules can impair cloud-firewall controls (T1686.001). Approved connectivity changes are common. A wildcard destination in this sample is not a specific VM private IP, and internet-wide reachability still requires a viable network path.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/networkSecurityGroups/securityRules/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Compare the prior/new rule and approved purpose, including priority and wildcard source/destination ranges.
- Inspect subnet/NIC associations, effective rules, public IP/NAT, routing, host firewall, and service state.
- Correlate actual connection attempts and authentication outcomes before asserting RDP access or lateral movement.
Sample Event
Synthetic scenario. The rule allows inbound TCP/3389 with wildcard source and destination at priority 100. This is a configuration illustration, not proof that any VM can be reached from the internet.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Network/networkSecurityGroups/securityRules/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-vm-demiguise-prod/securityRules/allow-rdp-from-anywhere" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "nsgRule207ExampleUtid", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100010010", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010011", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:33:54.1148902Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100010100", "operationName": { "value": "Microsoft.Network/networkSecurityGroups/securityRules/write", "localizedValue": "Create or update Network Security Rule" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Network", "localizedValue": "Microsoft.Network" }, "resourceType": { "value": "Microsoft.Network/networkSecurityGroups/securityRules", "localizedValue": "Microsoft.Network/networkSecurityGroups/securityRules" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-vm-demiguise-prod/securityRules/allow-rdp-from-anywhere", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Created", "localizedValue": "Created (HTTP Status Code: 201)" }, "submissionTimestamp": "2026-04-15T18:33:54.7058821Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Created", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/networkSecurityGroups/nsg-vm-demiguise-prod/securityRules/allow-rdp-from-anywhere", "message": "Microsoft.Network/networkSecurityGroups/securityRules/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"properties\":{\"protocol\":\"Tcp\",\"sourcePortRange\":\"*\",\"destinationPortRange\":\"3389\",\"sourceAddressPrefix\":\"*\",\"destinationAddressPrefix\":\"*\",\"access\":\"Allow\",\"priority\":100,\"direction\":\"Inbound\"}}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.