Azure Resource Lock Deletion - Defense Evasion
Detects the successful removal of Azure Resource Management locks. Attackers may attempt to delete these locks to modify, move, or delete protected resources that would otherwise be restricted, often as a precursor to data destruction or infrastructure tampering.
Microsoft Sentinel (KQL)

