Microsoft.Sql/servers/databases/delete
Microsoft.Sql/servers/databases/delete
Event
Deletes the database resource. A deleted database can be restored on the surviving logical server within applicable backup retention. Deleting the logical server is a different operation and also removes its PITR backups; separately retained long-term backups require separate review.
Security Context
Malicious deletion can cause outage or data loss (contextual T1485), but it does not automatically establish irreversible destruction. Azure SQL Database’s built-in backup system is not the same as a Recovery Services protected item for SQL Server in a VM.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Sql/servers/databases/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm final database state and approved retirement, with the logical server’s state.
- Inventory deleted-database backups, applicable retention, long-term retention, replicas, and external exports.
- Assess workload impact and coordinate supported restoration; do not invent a prior backup-deletion chain.
Sample Event
Synthetic scenario. The sample deletes sqldb-occamy-events. It shows neither logical-server deletion nor elimination of PITR or long-term recovery options.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Sql/servers/databases/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "sqlDel220ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100001110", "description": "", "eventDataId": "90000000-0000-4000-8000-000100001111", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:50:18.5128814Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100110100", "operationName": { "value": "Microsoft.Sql/servers/databases/delete", "localizedValue": "Delete SQL database" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Sql", "localizedValue": "Microsoft.Sql" }, "resourceType": { "value": "Microsoft.Sql/servers/databases", "localizedValue": "Microsoft.Sql/servers/databases" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:50:19.0428128Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events", "message": "Microsoft.Sql/servers/databases/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...