Microsoft.SerialConsole/serialPorts/connect/action
Microsoft.SerialConsole/serialPorts/connect/action
Event
Provides a serial connection through Azure management services independently of the VM’s network path. Azure authorization, service prerequisites, and guest console configuration still apply. Normal guest shell access requires appropriate guest authentication; Azure does not supply a universal default VM password.
Security Context
Unexpected console access can support remote-service abuse (contextual T1021), but this connect event does not prove guest login, shell commands, or lateral movement. Troubleshooting an unreachable VM is a normal use. T1059 requires separate command-execution evidence and is removed from this connection-only entry.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.SerialConsole/serialPorts/connect/action. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify Azure authorization, boot/console configuration, and the approved support request.
- Correlate guest login and command/process evidence; distinguish opening a console from authenticating to the OS.
- Review nearby password-reset/VM-access changes and actual workload access without assuming a stored or default password.
Sample Event
Synthetic scenario. The sample records a serial-port connection for vm-demiguise-infer-001. No guest credential, authenticated shell, or command is shown. Storage-related prerequisites are subject to Microsoft’s documented console architecture transition and require environment verification.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.SerialConsole/serialPorts/connect/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001/providers/Microsoft.SerialConsole/serialPorts/0" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "serial217ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100110000", "description": "", "eventDataId": "90000000-0000-4000-8000-000100110001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:55:42.1148707Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100110010", "operationName": { "value": "Microsoft.SerialConsole/serialPorts/connect/action", "localizedValue": "Connect to Serial Port" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.SerialConsole", "localizedValue": "Microsoft.SerialConsole" }, "resourceType": { "value": "Microsoft.SerialConsole/serialPorts", "localizedValue": "Microsoft.SerialConsole/serialPorts" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001/providers/Microsoft.SerialConsole/serialPorts/0", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:55:42.7218194Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001/providers/Microsoft.SerialConsole/serialPorts/0", "message": "Microsoft.SerialConsole/serialPorts/connect/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Lateral Movement
- T1021 — Remote Services — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.