Microsoft.Security/securitySolutions/delete
Microsoft.Security/securitySolutions/delete
Event
Microsoft’s operation catalog identifies this action as deletion of a security solution. It is distinct from securityConnectors, IoT security solutions, and endpoint extension removal. Effects depend on the actual solution and its integration; the operation name alone does not establish sensor uninstall or loss of a vendor’s alerts.
Security Context
Unauthorized deletion can impair a confirmed security integration (contextual T1685). Approved decommissioning is also possible. The sample’s product-like resource name does not verify a real supported integration or its behavior.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Security/securitySolutions/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover the solution resource definition, provider/version, ownership, and linked components.
- Verify final deletion and consult the actual integration’s documentation for lifecycle effects.
- Compare vendor-side protection and alert delivery before/after the change; preserve independently stored findings.
Sample Event
Synthetic scenario. The sample is a generic securitySolutions deletion record. niffler-edr-integration is fictional and does not establish a specific vendor integration or alert-stream effect.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Security/securitySolutions/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Security/securitySolutions/niffler-edr-integration" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "secSolDel216ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100101101", "description": "", "eventDataId": "90000000-0000-4000-8000-000100101110", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:34:11.7218104Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100101111", "operationName": { "value": "Microsoft.Security/securitySolutions/delete", "localizedValue": "Delete Security Solution" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Security", "localizedValue": "Microsoft.Security" }, "resourceType": { "value": "Microsoft.Security/securitySolutions", "localizedValue": "Microsoft.Security/securitySolutions" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Security/securitySolutions/niffler-edr-integration", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:34:12.2702118Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Security/securitySolutions/niffler-edr-integration", "message": "Microsoft.Security/securitySolutions/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...