Skip to content

Microsoft.Storage/storageAccounts/delete

Azure

Microsoft.Storage/storageAccounts/delete

service: Azure - Azure Storage
tactics:
techniques:

Event

Account deletion removes access to its storage services. Container/blob soft-delete does not protect against account deletion. Microsoft provides a best-effort account recovery path for eligible ARM accounts deleted within 14 days, subject to conditions including no reuse of the name; recovery is not guaranteed.

Security Context

Unauthorized deletion can cause outage and data loss (T1485). Do not conclude either certain recoverability or certain permanent loss from the event alone. Approved decommissioning and independent copies must also be considered.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/delete. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor/authorization context; verify effective authority.
resourceId, correlationIdExact target and related management operations.
status, subStatusOutcome and any asynchronous follow-up.
properties.requestbodySubmitted configuration where present; returned secrets are intentionally absent.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm the exact account, final deletion, approval, and dependent workloads.
  3. Check recovery eligibility promptly, including name reuse, resource group availability, and customer-managed encryption-key dependencies.
  4. Inventory external backups and restore dependencies; linked private endpoints are not automatically recreated during recovery.

Sample Event

Synthetic scenario. The sample deletes flcoccamy001. It does not establish a prior container deletion, the complete data inventory, or permanent loss of every copy.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Storage/storageAccounts/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "saDel223ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100010001",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100010100",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:54:08.7421101Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100110111",
"operationName": {
"value": "Microsoft.Storage/storageAccounts/delete",
"localizedValue": "Delete Storage Account"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Storage",
"localizedValue": "Microsoft.Storage"
},
"resourceType": {
"value": "Microsoft.Storage/storageAccounts",
"localizedValue": "Microsoft.Storage/storageAccounts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:54:09.3211002Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001",
"message": "Microsoft.Storage/storageAccounts/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.