Microsoft.Security/autoProvisioningSettings/write
Microsoft.Security/autoProvisioningSettings/write
Event
The legacy API exposes autoProvision On/Off for automatic security-agent installation. Microsoft retired Log Analytics agent (MMA) auto-provisioning in 2024. This setting must not be treated as a current universal switch for Azure Monitor Agent, Defender for Endpoint, agentless scanning, or all Defender resource inventory.
Security Context
Historically, disabling a functioning provisioning path could impair monitoring (contextual T1685). A present-day Off write can be obsolete configuration or cleanup and does not prove new machines lack protection. Existing agents are not shown being uninstalled by this event.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Security/autoProvisioningSettings/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Establish the event date, prior setting, and whether any provisioning path still depends on this legacy setting.
- Inspect actual AMA policy/DCR assignments, Defender plan extensions, MDE onboarding, and agentless coverage separately.
- Compare newly deployed machines and real telemetry with approved changes before asserting a monitoring gap.
Sample Event
Synthetic scenario. The sample writes Off to the legacy default setting in 2026, after MMA auto-provisioning retirement. It does not establish disabling AMA or creating an unmonitored C2 host.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Security/autoProvisioningSettings/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/autoProvisioningSettings/default" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "autoProv214ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100100111", "description": "", "eventDataId": "90000000-0000-4000-8000-000100101000", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:35:42.0218107Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100101001", "operationName": { "value": "Microsoft.Security/autoProvisioningSettings/write", "localizedValue": "Create or Update Auto Provisioning Settings" }, "resourceGroupName": "", "resourceProviderName": { "value": "Microsoft.Security", "localizedValue": "Microsoft.Security" }, "resourceType": { "value": "Microsoft.Security/autoProvisioningSettings", "localizedValue": "Microsoft.Security/autoProvisioningSettings" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/autoProvisioningSettings/default", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:35:42.5781055Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/autoProvisioningSettings/default", "message": "Microsoft.Security/autoProvisioningSettings/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"properties\":{\"autoProvision\":\"Off\"}}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...