Skip to content

Microsoft.Sql/servers/databases/delete

Azure

Microsoft.Sql/servers/databases/delete

service: Azure - Azure SQL
tactics:
techniques:

Event

Deletes the database resource. A deleted database can be restored on the surviving logical server within applicable backup retention. Deleting the logical server is a different operation and also removes its PITR backups; separately retained long-term backups require separate review.

Security Context

Malicious deletion can cause outage or data loss (contextual T1485), but it does not automatically establish irreversible destruction. Azure SQL Database’s built-in backup system is not the same as a Recovery Services protected item for SQL Server in a VM.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Sql/servers/databases/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm final database state and approved retirement, with the logical server’s state.
  3. Inventory deleted-database backups, applicable retention, long-term retention, replicas, and external exports.
  4. Assess workload impact and coordinate supported restoration; do not invent a prior backup-deletion chain.

Sample Event

Synthetic scenario. The sample deletes sqldb-occamy-events. It shows neither logical-server deletion nor elimination of PITR or long-term recovery options.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Sql/servers/databases/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "sqlDel220ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100001110",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100001111",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:50:18.5128814Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100110100",
"operationName": {
"value": "Microsoft.Sql/servers/databases/delete",
"localizedValue": "Delete SQL database"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Sql",
"localizedValue": "Microsoft.Sql"
},
"resourceType": {
"value": "Microsoft.Sql/servers/databases",
"localizedValue": "Microsoft.Sql/servers/databases"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:50:19.0428128Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events",
"message": "Microsoft.Sql/servers/databases/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.