Skip to content

Microsoft.Storage/storageAccounts/blobServices/containers/delete

Azure

Microsoft.Storage/storageAccounts/blobServices/containers/delete

service: Azure - Azure Storage
tactics:
techniques:

Event

Removes the specified container and its contents from normal access. Container soft-delete, if enabled before deletion, can preserve recovery during its configured retention period. Blob soft-delete alone is not a substitute for container protection; do not label every container deletion permanently unrecoverable.

Security Context

Malicious deletion can disrupt workloads or destroy data (contextual T1485). Approved cleanup uses the same operation. Actual data loss depends on protection settings, retained copies, and recovery outcome.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/blobServices/containers/delete. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent. Data-plane DeleteContainer requests use Storage resource logging instead; this page illustrates the ARM path.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor/authorization context; verify effective authority.
resourceId, correlationIdExact target and related management operations.
status, subStatusOutcome and any asynchronous follow-up.
properties.requestbodySubmitted configuration where present; returned secrets are intentionally absent.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover the prior container and blob protection settings and inspect any retention or immutability constraints.
  3. Confirm deletion outcome, soft-deleted container state, and available independent backups.
  4. Assess dependent workload failures and coordinate recovery; the container name does not establish its contents.

Sample Event

Synthetic scenario. The sample records management-plane deletion of customers. It contains no data inventory, protection configuration, or recovery attempt.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Storage/storageAccounts/blobServices/containers/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/blobServices/default/containers/customers"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "ctnrDel222ExampleUti",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100010010",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100010011",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:51:14.4218812Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100110110",
"operationName": {
"value": "Microsoft.Storage/storageAccounts/blobServices/containers/delete",
"localizedValue": "Delete Blob Container"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Storage",
"localizedValue": "Microsoft.Storage"
},
"resourceType": {
"value": "Microsoft.Storage/storageAccounts/blobServices/containers",
"localizedValue": "Microsoft.Storage/storageAccounts/blobServices/containers"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/blobServices/default/containers/customers",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:51:15.0298128Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/blobServices/default/containers/customers",
"message": "Microsoft.Storage/storageAccounts/blobServices/containers/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.