Skip to content

Microsoft.SerialConsole/serialPorts/connect/action

Azure

Microsoft.SerialConsole/serialPorts/connect/action

service: Azure - Compute
techniques:

Event

Provides a serial connection through Azure management services independently of the VM’s network path. Azure authorization, service prerequisites, and guest console configuration still apply. Normal guest shell access requires appropriate guest authentication; Azure does not supply a universal default VM password.

Security Context

Unexpected console access can support remote-service abuse (contextual T1021), but this connect event does not prove guest login, shell commands, or lateral movement. Troubleshooting an unreachable VM is a normal use. T1059 requires separate command-execution evidence and is removed from this connection-only entry.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.SerialConsole/serialPorts/connect/action. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify Azure authorization, boot/console configuration, and the approved support request.
  3. Correlate guest login and command/process evidence; distinguish opening a console from authenticating to the OS.
  4. Review nearby password-reset/VM-access changes and actual workload access without assuming a stored or default password.

Sample Event

Synthetic scenario. The sample records a serial-port connection for vm-demiguise-infer-001. No guest credential, authenticated shell, or command is shown. Storage-related prerequisites are subject to Microsoft’s documented console architecture transition and require environment verification.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.SerialConsole/serialPorts/connect/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001/providers/Microsoft.SerialConsole/serialPorts/0"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "serial217ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100110000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100110001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:55:42.1148707Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100110010",
"operationName": {
"value": "Microsoft.SerialConsole/serialPorts/connect/action",
"localizedValue": "Connect to Serial Port"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.SerialConsole",
"localizedValue": "Microsoft.SerialConsole"
},
"resourceType": {
"value": "Microsoft.SerialConsole/serialPorts",
"localizedValue": "Microsoft.SerialConsole/serialPorts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001/providers/Microsoft.SerialConsole/serialPorts/0",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:55:42.7218194Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001/providers/Microsoft.SerialConsole/serialPorts/0",
"message": "Microsoft.SerialConsole/serialPorts/connect/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Lateral Movement

Techniques:
  • T1021 — Remote Services — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.