Azure Key Vault Azure-Microsoft.KeyVault
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.KeyVault rules that match the resource provider but no specific operation. | N | N |
| Microsoft.KeyVault/ | Delete an HSM pool | N | N |
| Microsoft.KeyVault/ | Join a key vault to an HSM pool | N | N |
| Microsoft.KeyVault/ | Create a new HSM pool of update the properties of an existing HSM pool | N | N |
| Microsoft.KeyVault/ | Purge a soft deleted managed hsm | N | N |
| Microsoft.KeyVault/ | Purge a soft deleted managed hsm | N | N |
| Microsoft.KeyVault/ | Purge a soft deleted key vault | Y | Y |
| Microsoft.KeyVault/ | Notifies Microsoft.KeyVault that a virtual network or subnet is being deleted | N | N |
| Microsoft.KeyVault/ | Check if the configuration of the Network Security Perimeter needs updating. | N | N |
| Microsoft.KeyVault/ | Delete a Managed HSM | N | N |
| Microsoft.KeyVault/ | Creates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys. | N | N |
| Microsoft.KeyVault/ | Delete a connection proxy to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Validate a connection proxy to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Change the state of a connection proxy to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Delete a connection to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Change the state of a connection to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Creates or updates the diagnostic setting for the resource | N | N |
| Microsoft.KeyVault/ | Create a new Managed HSM or update the properties of an existing Managed HSM | N | N |
| Microsoft.KeyVault/ | Registers a subscription | Y | N |
| Microsoft.KeyVault/ | Unregisters a subscription | N | N |
| Microsoft.KeyVault/ | Updates an existing access policy by merging or replacing, or adds a new access policy to the key vault. | N | Y |
| Microsoft.KeyVault/ | Deletes a key vault | Y | Y |
| Microsoft.KeyVault/ | Enables access to secrets in a key vault when deploying Azure resources | N | Y |
| Microsoft.KeyVault/ | Notifies Microsoft.KeyVault that an EventGrid Subscription for Key Vault is being deleted | N | N |
| Microsoft.KeyVault/ | Notifies Microsoft.KeyVault that a new EventGrid Subscription for Key Vault is being created | N | N |
| Microsoft.KeyVault/ | Action to join the Network Security Perimeter, used by linked access checks by NRP. | N | N |
| Microsoft.KeyVault/ | Creates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys. | N | N |
| Microsoft.KeyVault/ | Delete an association proxy to a Network Security Perimeter resource of Microsoft.Network provider. | N | N |
| Microsoft.KeyVault/ | Change the state of an association to a Network Security Perimeter resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Reconcile the Network Security Perimeter configuration stored in a vault with NRP's (Microsoft.Network Resource Provider) copy. | N | N |
| Microsoft.KeyVault/ | Delete a connection proxy to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Validate a connection proxy to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Change the state of a connection proxy to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Delete a connection to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Change the state of a connection to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider | N | N |
| Microsoft.KeyVault/ | Creates or updates the diagnostic setting for the resource | N | N |
| Microsoft.KeyVault/ | Creates a new secret or updates the value of an existing secret. | N | Y |
| Microsoft.KeyVault/ | Creates a new key vault or updates the properties of an existing key vault. Certain properties may require more permissions. | Y | Y |
any: Azure Key Vault (catch-all)
#Description
Catch-all for Azure-Microsoft.KeyVault rules that match the resource provider but no specific operation.
References #
Microsoft.KeyVault/hsmPools/write
#Description
Create a new HSM pool of update the properties of an existing HSM pool
References #
Microsoft.KeyVault/locations/deletedManagedHsms/delete
#Description
Purge a soft deleted managed hsm
References #
Microsoft.KeyVault/locations/deletedManagedHsms/purge/action
#Description
Purge a soft deleted managed hsm
References #
Microsoft.KeyVault/locations/deletedVaults/purge/action
#Description
Purge a soft deleted key vault
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Accept",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Accepted",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "720299af-cad2-4539-b0b4-89844d6b755c",
"EventDataId": "0276f2cd-67bb-d42a-f506-daaf923f6457",
"EventSubmissionTimestamp": "2026-06-29T17:51:10.8826105Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.KEYVAULT/LOCATIONS/DELETEDVAULTS/PURGE/ACTION",
"Properties": {
"statusCode": "Accepted",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault/locations/westus2/deletedVaults/zckv25343",
"message": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "0276f2cd-67bb-d42a-f506-daaf923f6457",
"eventSubmissionTimestamp": "2026-06-29T17:51:10.8826105Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "westus2/zckv25343",
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "Accepted"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault/locations/westus2/deletedVaults/zckv25343",
"message": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "0276f2cd-67bb-d42a-f506-daaf923f6457",
"eventSubmissionTimestamp": "2026-06-29T17:51:10.8826105Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "westus2/zckv25343",
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"statusCode": "Accepted",
"serviceRequestId": "",
"activitySubstatusValue": "Accepted"
},
"Resource": "",
"ResourceGroup": "",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.KEYVAULT",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:51:10.8826105Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.keyvault/locations/westus2/deletedvaults/zckv25343"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490
References #
Microsoft.KeyVault/locations/deleteVirtualNetworkOrSubnets/action
#Description
Notifies Microsoft.KeyVault that a virtual network or subnet is being deleted
References #
Microsoft.KeyVault/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action
#Description
Check if the configuration of the Network Security Perimeter needs updating.
References #
Microsoft.KeyVault/managedHSMs/keys/write
#Description
Creates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys.
References #
Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/delete
#Description
Delete a connection proxy to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/validate/action
#Description
Validate a connection proxy to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/write
#Description
Change the state of a connection proxy to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/managedHSMs/privateEndpointConnections/delete
#Description
Delete a connection to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/managedHSMs/privateEndpointConnections/write
#Description
Change the state of a connection to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/managedHSMs/PrivateEndpointConnectionsApproval/action
#Description
Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/managedHSMs/providers/Microsoft.Insights/diagnosticSettings/Write
#Description
Creates or updates the diagnostic setting for the resource
References #
Microsoft.KeyVault/managedHSMs/write
#Description
Create a new Managed HSM or update the properties of an existing Managed HSM
References #
Microsoft.KeyVault/register/action
#Description
Registers a subscription
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.KeyVault/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.KeyVault/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "dad8a35b-5208-4f16-8918-aecab6b0cfc0",
"EventDataId": "6b047f50-05c3-fde4-ed1d-be45ecb99937",
"EventSubmissionTimestamp": "2026-06-29T17:47:15.6284723Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.KEYVAULT/REGISTER/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault",
"message": "Microsoft.KeyVault/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6b047f50-05c3-fde4-ed1d-be45ecb99937",
"eventSubmissionTimestamp": "2026-06-29T17:47:15.6284723Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault",
"message": "Microsoft.KeyVault/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6b047f50-05c3-fde4-ed1d-be45ecb99937",
"eventSubmissionTimestamp": "2026-06-29T17:47:15.6284723Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"Resource": "",
"ResourceGroup": "",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.KEYVAULT",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:47:15.6284723Z",
"Type": "AzureActivity",
"_ResourceId": ""
}
References #
Microsoft.KeyVault/vaults/accessPolicies/write
#Description
Updates an existing access policy by merging or replacing, or adds a new access policy to the key vault.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1552, T1552.001↳ also matches Microsoft.KeyVault/vaults/delete, Microsoft.KeyVault/vaults/deploy/action, Microsoft.KeyVault/vaults/write
References #
Microsoft.KeyVault/vaults/delete
#Description
Deletes a key vault
Example Resource Log Record #
{
"TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
"SourceSystem": "Azure",
"CallerIpAddress": "37.142.150.162",
"CategoryValue": "Administrative",
"CorrelationId": "b62b273a-d336-4ead-b1ac-223f3220e772",
"Authorization": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
"action": "Microsoft.KeyVault/vaults/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
"action": "Microsoft.KeyVault/vaults/delete",
"evidence": {
"role": "Contributor",
"roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
"roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
"roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
"principalId": "9b117c67170e4aed9702658b3fddc889",
"principalType": "User"
}
},
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
"iat": "1619620278",
"nbf": "1619620278",
"exp": "1619624178",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
"appidacr": "2",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
"groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
"ipaddr": "37.142.150.162",
"name": "Adele Vance",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
"puid": "10032000C757D25F",
"rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
"http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
"uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
"ver": "1.0",
"xms_tcdt": "1591748537"
},
"OperationNameValue": "MICROSOFT.KEYVAULT/VAULTS/DELETE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "c1c4dc22-3b83-4b2e-ae58-1a829989b8e4",
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
"message": "Microsoft.KeyVault/vaults/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "63139859-0aaf-474c-98b9-ed18b7d4b6a7",
"eventSubmissionTimestamp": "2021-04-28T14:42:51.9161118Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "oneloginlogs1234",
"resourceGroup": "GBB01",
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "c1c4dc22-3b83-4b2e-ae58-1a829989b8e4",
"eventCategory": "Administrative",
"entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
"message": "Microsoft.KeyVault/vaults/delete",
"hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"caller": "AdeleV@M365x816222.OnMicrosoft.com",
"eventDataId": "63139859-0aaf-474c-98b9-ed18b7d4b6a7",
"eventSubmissionTimestamp": "2021-04-28T14:42:51.9161118Z",
"httpRequest": {
"clientIpAddress": "37.142.150.162"
},
"resource": "oneloginlogs1234",
"resourceGroup": "GBB01",
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Caller": "AdeleV@M365x816222.OnMicrosoft.com",
"EventDataId": "63139859-0aaf-474c-98b9-ed18b7d4b6a7",
"EventSubmissionTimestamp": "4/28/2021, 2:42:51.916 PM",
"HTTPRequest": {
"clientIpAddress": "37.142.150.162"
},
"ResourceGroup": "GBB01",
"ResourceProviderValue": "MICROSOFT.KEYVAULT",
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
"TimeGenerated": "4/28/2021, 2:42:51.916 PM",
"SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
"Type": "AzureActivity"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1552, T1552.001↳ also matches Microsoft.KeyVault/vaults/accessPolicies/write, Microsoft.KeyVault/vaults/deploy/action, Microsoft.KeyVault/vaults/write Panther #
T1485, T1490
References #
Microsoft.KeyVault/vaults/deploy/action
#Description
Enables access to secrets in a key vault when deploying Azure resources
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1552, T1552.001↳ also matches Microsoft.KeyVault/vaults/accessPolicies/write, Microsoft.KeyVault/vaults/delete, Microsoft.KeyVault/vaults/write
References #
Microsoft.KeyVault/vaults/eventGridFilters/delete
#Description
Notifies Microsoft.KeyVault that an EventGrid Subscription for Key Vault is being deleted
References #
Microsoft.KeyVault/vaults/eventGridFilters/write
#Description
Notifies Microsoft.KeyVault that a new EventGrid Subscription for Key Vault is being created
References #
Microsoft.KeyVault/vaults/joinPerimeter/action
#Description
Action to join the Network Security Perimeter, used by linked access checks by NRP.
References #
Microsoft.KeyVault/vaults/keys/write
#Description
Creates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys.
References #
Microsoft.KeyVault/vaults/networkSecurityPerimeterAssociationProxies/delete
#Description
Delete an association proxy to a Network Security Perimeter resource of Microsoft.Network provider.
References #
Microsoft.KeyVault/vaults/networkSecurityPerimeterAssociationProxies/write
#Description
Change the state of an association to a Network Security Perimeter resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/networkSecurityPerimeterConfigurations/reconcile/action
#Description
Reconcile the Network Security Perimeter configuration stored in a vault with NRP's (Microsoft.Network Resource Provider) copy.
References #
Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/delete
#Description
Delete a connection proxy to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/validate/action
#Description
Validate a connection proxy to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/write
#Description
Change the state of a connection proxy to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/privateEndpointConnections/delete
#Description
Delete a connection to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/privateEndpointConnections/write
#Description
Change the state of a connection to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/PrivateEndpointConnectionsApproval/action
#Description
Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider
References #
Microsoft.KeyVault/vaults/providers/Microsoft.Insights/diagnosticSettings/Write
#Description
Creates or updates the diagnostic setting for the resource
References #
Microsoft.KeyVault/vaults/secrets/write
#Description
Creates a new secret or updates the value of an existing secret.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1552, T1552.001
References #
Microsoft.KeyVault/vaults/write
#Description
Creates a new key vault or updates the properties of an existing key vault. Certain properties may require more permissions.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Accept",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
"action": "Microsoft.KeyVault/vaults/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
"action": "Microsoft.KeyVault/vaults/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "6c2c3a4d-9ca4-421c-bfd2-d179ad984175",
"EventDataId": "62c9e2e9-5b38-c8be-00a7-7a27dfe762d0",
"EventSubmissionTimestamp": "2026-06-29T19:02:31.9512786Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.KEYVAULT/VAULTS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
"message": "Microsoft.KeyVault/vaults/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "62c9e2e9-5b38-c8be-00a7-7a27dfe762d0",
"eventSubmissionTimestamp": "2026-06-29T19:02:31.9512786Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zckv39748",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
"message": "Microsoft.KeyVault/vaults/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "62c9e2e9-5b38-c8be-00a7-7a27dfe762d0",
"eventSubmissionTimestamp": "2026-06-29T19:02:31.9512786Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zckv39748",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.KEYVAULT",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Accept",
"activitySubstatusValue": "OK"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.KEYVAULT",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:02:31.9512786Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.keyvault/vaults/zckv39748"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1552, T1552.001↳ also matches Microsoft.KeyVault/vaults/accessPolicies/write, Microsoft.KeyVault/vaults/delete, Microsoft.KeyVault/vaults/deploy/action