Skip to content

Storage Analytics logging disabled

Azure

Storage Analytics logging disabled

service: Azure - Azure Storage
techniques:

Event

The former catalog label Microsoft.Storage/storageAccounts/stopLogging/action could not be verified in current Microsoft operation documentation. Legacy Storage Analytics logging is configured per service through service properties, such as Set Blob Service Properties. Azure Monitor diagnostic settings are a separate collection path.

Security Context

Unauthorized disabling of active logging can impair cloud visibility (T1685.002). A legacy logging change does not prove all storage telemetry is disabled or delete historical logs. Approved migrations may turn off redundant collection.

Log Source

No native Azure Activity Log event with the former stopLogging/action name was verified. Investigate actual service-property changes and logging configuration; Azure Monitor diagnostic-setting changes are separate ARM operations. The configuration summary below is not a detection fixture.

Key Fields

FieldInvestigation value
service, documentedOperationWhich storage service and documented configuration API are being discussed.
logging.read, logging.write, logging.deleteIllustrative disabled categories; not claimed native audit field names.
logging.retentionPolicyIllustrative retention setting; historical records require separate inspection.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Identify the actual API and storage service, and compare previous/new read, write, and delete logging flags.
  3. Inspect Azure Monitor diagnostic settings, destinations, and historical Storage Analytics records independently.
  4. Confirm a real collection gap and approved migration context; do not build a detection around the unverified stopLogging/action string.

Sample Event

Synthetic scenario. The JSON is an explanatory configuration summary for disabling Blob Storage Analytics categories, not a native audit event or an executable REST request. The documented REST operation uses XML. This replaces the unsupported Activity Log example while preserving the page URL.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"illustrationType": "Configuration summary, not a native log or REST body",
"service": "Azure Blob Storage",
"documentedOperation": "Set Blob Service Properties",
"logging": {
"version": "1.0",
"read": false,
"write": false,
"delete": false,
"retentionPolicy": {
"enabled": false
}
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.