Microsoft.Storage/storageAccounts/delete
Microsoft.Storage/storageAccounts/delete
Event
Account deletion removes access to its storage services. Container/blob soft-delete does not protect against account deletion. Microsoft provides a best-effort account recovery path for eligible ARM accounts deleted within 14 days, subject to conditions including no reuse of the name; recovery is not guaranteed.
Security Context
Unauthorized deletion can cause outage and data loss (T1485). Do not conclude either certain recoverability or certain permanent loss from the event alone. Approved decommissioning and independent copies must also be considered.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/delete. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor/authorization context; verify effective authority. |
resourceId, correlationId | Exact target and related management operations. |
status, subStatus | Outcome and any asynchronous follow-up. |
properties.requestbody | Submitted configuration where present; returned secrets are intentionally absent. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm the exact account, final deletion, approval, and dependent workloads.
- Check recovery eligibility promptly, including name reuse, resource group availability, and customer-managed encryption-key dependencies.
- Inventory external backups and restore dependencies; linked private endpoints are not automatically recreated during recovery.
Sample Event
Synthetic scenario. The sample deletes flcoccamy001. It does not establish a prior container deletion, the complete data inventory, or permanent loss of every copy.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Storage/storageAccounts/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "saDel223ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100010001", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010100", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:54:08.7421101Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100110111", "operationName": { "value": "Microsoft.Storage/storageAccounts/delete", "localizedValue": "Delete Storage Account" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Storage", "localizedValue": "Microsoft.Storage" }, "resourceType": { "value": "Microsoft.Storage/storageAccounts", "localizedValue": "Microsoft.Storage/storageAccounts" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:54:09.3211002Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001", "message": "Microsoft.Storage/storageAccounts/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...