Skip to content

Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete

Azure

Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete

service: Azure - Backup
tactics:
techniques:

Event

The actual operation is Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete. It is asynchronous and scoped to an item in a Recovery Services vault. Backup-data recovery depends on soft-delete and other protection controls; do not equate deletion with immediate permanent loss.

Security Context

Malicious deletion can inhibit recovery (T1490) or destroy data (T1485). Approved retirement uses the same operation. Azure SQL Database’s built-in backups are distinct from Azure Backup protection for VMs or SQL Server running in a VM; this event does not establish removal of an Azure SQL Database’s PITR backups.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Resolve the protected workload and exact item ID, and verify approved stop-protection/delete intent.
  3. Follow the operation result and inspect soft-deleted items, retention, immutability, and multi-user authorization controls.
  4. Inventory remaining recovery points and independent backups before claiming no recovery path remains.

Sample Event

Synthetic scenario. The corrected sample targets an Azure VM backup item. It replaces the unsupported Azure SQL Database backup chain and does not show permanent purge or deletion of the source VM.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-phoenix-dr/providers/Microsoft.RecoveryServices/vaults/rsv-phoenix-backup/backupFabrics/Azure/protectionContainers/iaasvmcontainer;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001/protectedItems/vm;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "rsvBpiDel212ExampleUti",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100100001",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100100010",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:48:33.4218873Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100100011",
"operationName": {
"value": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete",
"localizedValue": "Stop protection and delete backup data"
},
"resourceGroupName": "rg-phoenix-dr",
"resourceProviderName": {
"value": "Microsoft.RecoveryServices",
"localizedValue": "Microsoft.RecoveryServices"
},
"resourceType": {
"value": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems",
"localizedValue": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-phoenix-dr/providers/Microsoft.RecoveryServices/vaults/rsv-phoenix-backup/backupFabrics/Azure/protectionContainers/iaasvmcontainer;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001/protectedItems/vm;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:48:34.0218002Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-phoenix-dr/providers/Microsoft.RecoveryServices/vaults/rsv-phoenix-backup/backupFabrics/Azure/protectionContainers/iaasvmcontainer;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001/protectedItems/vm;iaasvmcontainerv2;rg-phoenix-dr;vm-phoenix-backup-001",
"message": "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1490 — Inhibit System Recovery — Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.