Microsoft.Storage/storageAccounts/blobServices/containers/delete
Microsoft.Storage/storageAccounts/blobServices/containers/delete
Event
Removes the specified container and its contents from normal access. Container soft-delete, if enabled before deletion, can preserve recovery during its configured retention period. Blob soft-delete alone is not a substitute for container protection; do not label every container deletion permanently unrecoverable.
Security Context
Malicious deletion can disrupt workloads or destroy data (contextual T1485). Approved cleanup uses the same operation. Actual data loss depends on protection settings, retained copies, and recovery outcome.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/blobServices/containers/delete. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent. Data-plane DeleteContainer requests use Storage resource logging instead; this page illustrates the ARM path.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor/authorization context; verify effective authority. |
resourceId, correlationId | Exact target and related management operations. |
status, subStatus | Outcome and any asynchronous follow-up. |
properties.requestbody | Submitted configuration where present; returned secrets are intentionally absent. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover the prior container and blob protection settings and inspect any retention or immutability constraints.
- Confirm deletion outcome, soft-deleted container state, and available independent backups.
- Assess dependent workload failures and coordinate recovery; the container name does not establish its contents.
Sample Event
Synthetic scenario. The sample records management-plane deletion of customers. It contains no data inventory, protection configuration, or recovery attempt.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Storage/storageAccounts/blobServices/containers/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/blobServices/default/containers/customers" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "ctnrDel222ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100010010", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010011", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:51:14.4218812Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100110110", "operationName": { "value": "Microsoft.Storage/storageAccounts/blobServices/containers/delete", "localizedValue": "Delete Blob Container" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Storage", "localizedValue": "Microsoft.Storage" }, "resourceType": { "value": "Microsoft.Storage/storageAccounts/blobServices/containers", "localizedValue": "Microsoft.Storage/storageAccounts/blobServices/containers" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/blobServices/default/containers/customers", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:51:15.0298128Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/blobServices/default/containers/customers", "message": "Microsoft.Storage/storageAccounts/blobServices/containers/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...