Skip to content

Microsoft.OperationalInsights/workspaces/delete

Azure

Microsoft.OperationalInsights/workspaces/delete

service: Azure - Log Analytics
techniques:

Event

Normal deletion offers a 14-day soft-delete recovery period for the workspace and data. The force=true query option bypasses that recovery path. Recovering a soft-deleted workspace does not automatically restore removed solutions and linked services; verify and reconfigure them separately.

Security Context

Malicious deletion can impair logging (T1685.002) and cause data loss (T1485). Actual Sentinel/detection impact depends on the workspace’s integrations. Other exported copies and other workspaces are separate; a workspace name alone does not establish its role.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.OperationalInsights/workspaces/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Inspect the actual deletion URL or client evidence for force=true and confirm the final deletion state.
  3. Inventory affected agents, solutions, Sentinel configuration, and retained external copies.
  4. Determine recoverability and observed monitoring gaps; coordinate recovery with the owner if a soft-delete window remains.

Sample Event

Synthetic scenario. The illustrative DELETE URL explicitly includes force=true. The query parameter is not part of the resource identity. No Sentinel integration or independently retained copies are shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.OperationalInsights/workspaces/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000010/resourceGroups/rg-security/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-security"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "lawDel210ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100011011",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100011100",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:42:08.7218304Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100011101",
"operationName": {
"value": "Microsoft.OperationalInsights/workspaces/delete",
"localizedValue": "Delete Log Analytics Workspace"
},
"resourceGroupName": "rg-security",
"resourceProviderName": {
"value": "Microsoft.OperationalInsights",
"localizedValue": "Microsoft.OperationalInsights"
},
"resourceType": {
"value": "Microsoft.OperationalInsights/workspaces",
"localizedValue": "Microsoft.OperationalInsights/workspaces"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000010/resourceGroups/rg-security/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-security",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:42:09.4001882Z",
"subscriptionId": "20000000-0000-4000-8000-000000000010",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000010/resourceGroups/rg-security/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-security",
"message": "Microsoft.OperationalInsights/workspaces/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000010"
},
"relatedEvents": [],
"httpRequest": {
"method": "DELETE",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000010/resourceGroups/rg-security/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-security?api-version=2025-07-01&force=true"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment Impact

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.