Skip to content

Microsoft.Security/pricings/write

Azure

Microsoft.Security/pricings/write

service: Azure - Microsoft Defender for Cloud
techniques:

Event

Updates a plan’s pricingTier and, where applicable, subPlan or extension settings. Free and Standard indicate basic versus paid plan capabilities. Scope, inheritance, resource overrides, and individual feature configuration determine effective coverage; one plan change is not a blanket shutdown of every security product.

Security Context

Unauthorized downgrade can impair defenses (T1685). Approved subscription or licensing changes are common. A write of Free does not prove the previous tier was Standard, immediate sensor removal, or that separately licensed endpoint protection stopped.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Security/pricings/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Compare the complete prior/new plan, scope, subplan, and extension settings with approval.
  3. Inspect resource-level effective pricing, inheritance/enforcement, and actual feature coverage.
  4. Correlate endpoint state and detection/assessment changes before claiming a specific protection stopped.

Sample Event

Synthetic scenario. The sample writes pricingTier Free for VirtualMachines at subscription scope. No prior tier, resource override, sensor state, or actual alert loss is shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Security/pricings/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/pricings/VirtualMachines"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "secPri215ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100101010",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100101011",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:32:18.5028104Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100101100",
"operationName": {
"value": "Microsoft.Security/pricings/write",
"localizedValue": "Create or Update Pricing"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Security",
"localizedValue": "Microsoft.Security"
},
"resourceType": {
"value": "Microsoft.Security/pricings",
"localizedValue": "Microsoft.Security/pricings"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/pricings/VirtualMachines",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:32:19.0492881Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/pricings/VirtualMachines",
"message": "Microsoft.Security/pricings/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"properties\":{\"pricingTier\":\"Free\"}}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.