Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete
Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete
Event
The actual operation is Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete. It is asynchronous and scoped to an item in a Recovery Services vault. Backup-data recovery depends on soft-delete and other protection controls; do not equate deletion with immediate permanent loss.
Security Context
Malicious deletion can inhibit recovery (T1490) or destroy data (T1485). Approved retirement uses the same operation. Azure SQL Database’s built-in backups are distinct from Azure Backup protection for VMs or SQL Server running in a VM; this event does not establish removal of an Azure SQL Database’s PITR backups.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Resolve the protected workload and exact item ID, and verify approved stop-protection/delete intent.
- Follow the operation result and inspect soft-deleted items, retention, immutability, and multi-user authorization controls.
- Inventory remaining recovery points and independent backups before claiming no recovery path remains.
Sample Event
Synthetic scenario. The corrected sample targets an Azure VM backup item. It replaces the unsupported Azure SQL Database backup chain and does not show permanent purge or deletion of the source VM.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-phoenix-dr/providers/Microsoft.RecoveryServices/vaults/rsv-phoenix-backup/backupFabrics/Azure/protectionContainers/iaasvmcontainer;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001/protectedItems/vm;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "rsvBpiDel212ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100100001", "description": "", "eventDataId": "90000000-0000-4000-8000-000100100010", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:48:33.4218873Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100100011", "operationName": { "value": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete", "localizedValue": "Stop protection and delete backup data" }, "resourceGroupName": "rg-phoenix-dr", "resourceProviderName": { "value": "Microsoft.RecoveryServices", "localizedValue": "Microsoft.RecoveryServices" }, "resourceType": { "value": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems", "localizedValue": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-phoenix-dr/providers/Microsoft.RecoveryServices/vaults/rsv-phoenix-backup/backupFabrics/Azure/protectionContainers/iaasvmcontainer;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001/protectedItems/vm;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:48:34.0218002Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-phoenix-dr/providers/Microsoft.RecoveryServices/vaults/rsv-phoenix-backup/backupFabrics/Azure/protectionContainers/iaasvmcontainer;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001/protectedItems/vm;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001", "message": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1490 — Inhibit System Recovery — Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.