Azure Key Vault Azure-Microsoft.KeyVault

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.KeyVault rules that match the resource provider but no specific operation.NN
Microsoft.KeyVault/hsmPools/deleteDelete an HSM poolNN
Microsoft.KeyVault/hsmPools/joinVault/actionJoin a key vault to an HSM poolNN
Microsoft.KeyVault/hsmPools/writeCreate a new HSM pool of update the properties of an existing HSM poolNN
Microsoft.KeyVault/locations/deletedManagedHsms/deletePurge a soft deleted managed hsmNN
Microsoft.KeyVault/locations/deletedManagedHsms/purge/actionPurge a soft deleted managed hsmNN
Microsoft.KeyVault/locations/deletedVaults/purge/actionPurge a soft deleted key vaultYY
Microsoft.KeyVault/locations/deleteVirtualNetworkOrSubnets/actionNotifies Microsoft.KeyVault that a virtual network or subnet is being deletedNN
Microsoft.KeyVault/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/actionCheck if the configuration of the Network Security Perimeter needs updating.NN
Microsoft.KeyVault/managedHSMs/deleteDelete a Managed HSMNN
Microsoft.KeyVault/managedHSMs/keys/writeCreates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys.NN
Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/deleteDelete a connection proxy to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/validate/actionValidate a connection proxy to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/writeChange the state of a connection proxy to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/managedHSMs/privateEndpointConnections/deleteDelete a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/managedHSMs/privateEndpointConnections/writeChange the state of a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/managedHSMs/PrivateEndpointConnectionsApproval/actionApprove or reject a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/managedHSMs/providers/Microsoft.Insights/diagnosticSettings/WriteCreates or updates the diagnostic setting for the resourceNN
Microsoft.KeyVault/managedHSMs/writeCreate a new Managed HSM or update the properties of an existing Managed HSMNN
Microsoft.KeyVault/register/actionRegisters a subscriptionYN
Microsoft.KeyVault/unregister/actionUnregisters a subscriptionNN
Microsoft.KeyVault/vaults/accessPolicies/writeUpdates an existing access policy by merging or replacing, or adds a new access policy to the key vault.NY
Microsoft.KeyVault/vaults/deleteDeletes a key vaultYY
Microsoft.KeyVault/vaults/deploy/actionEnables access to secrets in a key vault when deploying Azure resourcesNY
Microsoft.KeyVault/vaults/eventGridFilters/deleteNotifies Microsoft.KeyVault that an EventGrid Subscription for Key Vault is being deletedNN
Microsoft.KeyVault/vaults/eventGridFilters/writeNotifies Microsoft.KeyVault that a new EventGrid Subscription for Key Vault is being createdNN
Microsoft.KeyVault/vaults/joinPerimeter/actionAction to join the Network Security Perimeter, used by linked access checks by NRP.NN
Microsoft.KeyVault/vaults/keys/writeCreates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys.NN
Microsoft.KeyVault/vaults/networkSecurityPerimeterAssociationProxies/deleteDelete an association proxy to a Network Security Perimeter resource of Microsoft.Network provider.NN
Microsoft.KeyVault/vaults/networkSecurityPerimeterAssociationProxies/writeChange the state of an association to a Network Security Perimeter resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/networkSecurityPerimeterConfigurations/reconcile/actionReconcile the Network Security Perimeter configuration stored in a vault with NRP's (Microsoft.Network Resource Provider) copy.NN
Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/deleteDelete a connection proxy to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/validate/actionValidate a connection proxy to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/writeChange the state of a connection proxy to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/privateEndpointConnections/deleteDelete a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/privateEndpointConnections/writeChange the state of a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/PrivateEndpointConnectionsApproval/actionApprove or reject a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.KeyVault/vaults/providers/Microsoft.Insights/diagnosticSettings/WriteCreates or updates the diagnostic setting for the resourceNN
Microsoft.KeyVault/vaults/secrets/writeCreates a new secret or updates the value of an existing secret.NY
Microsoft.KeyVault/vaults/writeCreates a new key vault or updates the properties of an existing key vault. Certain properties may require more permissions.YY

any: Azure Key Vault (catch-all)

#
Namespace
Microsoft.KeyVault

Description

Catch-all for Azure-Microsoft.KeyVault rules that match the resource provider but no specific operation.

References #

Microsoft.KeyVault/hsmPools/delete

#
Namespace
Microsoft.KeyVault

Description

Delete an HSM pool

References #

Microsoft.KeyVault/hsmPools/joinVault/action

#
Namespace
Microsoft.KeyVault

Description

Join a key vault to an HSM pool

References #

Microsoft.KeyVault/hsmPools/write

#
Namespace
Microsoft.KeyVault

Description

Create a new HSM pool of update the properties of an existing HSM pool

References #

Microsoft.KeyVault/locations/deletedManagedHsms/delete

#
Namespace
Microsoft.KeyVault

Description

Purge a soft deleted managed hsm

References #

Microsoft.KeyVault/locations/deletedManagedHsms/purge/action

#
Namespace
Microsoft.KeyVault

Description

Purge a soft deleted managed hsm

References #

Microsoft.KeyVault/locations/deletedVaults/purge/action

#
Namespace
Microsoft.KeyVault

Description

Purge a soft deleted key vault

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Accepted",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "720299af-cad2-4539-b0b4-89844d6b755c",
  "EventDataId": "0276f2cd-67bb-d42a-f506-daaf923f6457",
  "EventSubmissionTimestamp": "2026-06-29T17:51:10.8826105Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.KEYVAULT/LOCATIONS/DELETEDVAULTS/PURGE/ACTION",
  "Properties": {
    "statusCode": "Accepted",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault/locations/westus2/deletedVaults/zckv25343",
    "message": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "0276f2cd-67bb-d42a-f506-daaf923f6457",
    "eventSubmissionTimestamp": "2026-06-29T17:51:10.8826105Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "westus2/zckv25343",
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "Accepted"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault/locations/westus2/deletedVaults/zckv25343",
    "message": "Microsoft.KeyVault/locations/deletedVaults/purge/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "0276f2cd-67bb-d42a-f506-daaf923f6457",
    "eventSubmissionTimestamp": "2026-06-29T17:51:10.8826105Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "westus2/zckv25343",
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "statusCode": "Accepted",
    "serviceRequestId": "",
    "activitySubstatusValue": "Accepted"
  },
  "Resource": "",
  "ResourceGroup": "",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.KEYVAULT",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:51:10.8826105Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.keyvault/locations/westus2/deletedvaults/zckv25343"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Key Vault Permanently Purged source low: Detects when an entire Azure Key Vault is permanently purged. Purging a Key Vault is an irreversible operation that permanently destroys all keys, secrets, and certificates stored within it. This is more destructive than deleting a vault and may indicate ransomware activity or malicious data destruction.T1485, T1490

References #

Microsoft.KeyVault/locations/deleteVirtualNetworkOrSubnets/action

#
Namespace
Microsoft.KeyVault

Description

Notifies Microsoft.KeyVault that a virtual network or subnet is being deleted

References #

Microsoft.KeyVault/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action

#
Namespace
Microsoft.KeyVault

Description

Check if the configuration of the Network Security Perimeter needs updating.

References #

Microsoft.KeyVault/managedHSMs/delete

#
Namespace
Microsoft.KeyVault

Description

Delete a Managed HSM

References #

Microsoft.KeyVault/managedHSMs/keys/write

#
Namespace
Microsoft.KeyVault

Description

Creates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys.

References #

Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.KeyVault

Description

Delete a connection proxy to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.KeyVault

Description

Validate a connection proxy to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/managedHSMs/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.KeyVault

Description

Change the state of a connection proxy to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/managedHSMs/privateEndpointConnections/delete

#
Namespace
Microsoft.KeyVault

Description

Delete a connection to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/managedHSMs/privateEndpointConnections/write

#
Namespace
Microsoft.KeyVault

Description

Change the state of a connection to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/managedHSMs/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.KeyVault

Description

Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/managedHSMs/providers/Microsoft.Insights/diagnosticSettings/Write

#
Namespace
Microsoft.KeyVault

Description

Creates or updates the diagnostic setting for the resource

References #

Microsoft.KeyVault/managedHSMs/write

#
Namespace
Microsoft.KeyVault

Description

Create a new Managed HSM or update the properties of an existing Managed HSM

References #

Microsoft.KeyVault/register/action

#
Namespace
Microsoft.KeyVault

Description

Registers a subscription

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.KeyVault/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.KeyVault/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "dad8a35b-5208-4f16-8918-aecab6b0cfc0",
  "EventDataId": "6b047f50-05c3-fde4-ed1d-be45ecb99937",
  "EventSubmissionTimestamp": "2026-06-29T17:47:15.6284723Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.KEYVAULT/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault",
    "message": "Microsoft.KeyVault/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6b047f50-05c3-fde4-ed1d-be45ecb99937",
    "eventSubmissionTimestamp": "2026-06-29T17:47:15.6284723Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.KeyVault",
    "message": "Microsoft.KeyVault/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6b047f50-05c3-fde4-ed1d-be45ecb99937",
    "eventSubmissionTimestamp": "2026-06-29T17:47:15.6284723Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "Resource": "",
  "ResourceGroup": "",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.KEYVAULT",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:47:15.6284723Z",
  "Type": "AzureActivity",
  "_ResourceId": ""
}

References #

Microsoft.KeyVault/unregister/action

#
Namespace
Microsoft.KeyVault

Description

Unregisters a subscription

References #

Microsoft.KeyVault/vaults/accessPolicies/write

#
Namespace
Microsoft.KeyVault

Description

Updates an existing access policy by merging or replacing, or adds a new access policy to the key vault.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Microsoft.KeyVault/vaults/delete

#
Namespace
Microsoft.KeyVault

Description

Deletes a key vault

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "b62b273a-d336-4ead-b1ac-223f3220e772",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
    "action": "Microsoft.KeyVault/vaults/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
    "action": "Microsoft.KeyVault/vaults/delete",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619620278",
    "nbf": "1619620278",
    "exp": "1619624178",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAA7zVpz1MTiN5PcZ84YU7VvUqYvGDj8M8XljPirr2ynbiIAMHm6UVn78uuUS6hpfLV",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "H9u_0K6Ph0a_X_ZpaCFwAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "OperationNameValue": "MICROSOFT.KEYVAULT/VAULTS/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "c1c4dc22-3b83-4b2e-ae58-1a829989b8e4",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
    "message": "Microsoft.KeyVault/vaults/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "63139859-0aaf-474c-98b9-ed18b7d4b6a7",
    "eventSubmissionTimestamp": "2021-04-28T14:42:51.9161118Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "oneloginlogs1234",
    "resourceGroup": "GBB01",
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "c1c4dc22-3b83-4b2e-ae58-1a829989b8e4",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/GBB01/providers/Microsoft.KeyVault/vaults/OneLoginLogs1234",
    "message": "Microsoft.KeyVault/vaults/delete",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "63139859-0aaf-474c-98b9-ed18b7d4b6a7",
    "eventSubmissionTimestamp": "2021-04-28T14:42:51.9161118Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "oneloginlogs1234",
    "resourceGroup": "GBB01",
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "63139859-0aaf-474c-98b9-ed18b7d4b6a7",
  "EventSubmissionTimestamp": "4/28/2021, 2:42:51.916 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "GBB01",
  "ResourceProviderValue": "MICROSOFT.KEYVAULT",
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:42:51.916 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

  • Azure Key Vault Deleted source medium: Detects when an Azure Key Vault is deleted. Key Vault deletion is a destructive operation that may indicate ransomware activity or malicious destruction of secrets and encryption keys.T1485, T1490

References #

Microsoft.KeyVault/vaults/deploy/action

#
Namespace
Microsoft.KeyVault

Description

Enables access to secrets in a key vault when deploying Azure resources

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Microsoft.KeyVault/vaults/eventGridFilters/delete

#
Namespace
Microsoft.KeyVault

Description

Notifies Microsoft.KeyVault that an EventGrid Subscription for Key Vault is being deleted

References #

Microsoft.KeyVault/vaults/eventGridFilters/write

#
Namespace
Microsoft.KeyVault

Description

Notifies Microsoft.KeyVault that a new EventGrid Subscription for Key Vault is being created

References #

Microsoft.KeyVault/vaults/joinPerimeter/action

#
Namespace
Microsoft.KeyVault

Description

Action to join the Network Security Perimeter, used by linked access checks by NRP.

References #

Microsoft.KeyVault/vaults/keys/write

#
Namespace
Microsoft.KeyVault

Description

Creates the first version of a new key if it does not exist. If it already exists, then the existing key is returned without any modification. This API does not create subsequent versions, and does not update existing keys.

References #

Microsoft.KeyVault/vaults/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.KeyVault

Description

Delete an association proxy to a Network Security Perimeter resource of Microsoft.Network provider.

References #

Microsoft.KeyVault/vaults/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.KeyVault

Description

Change the state of an association to a Network Security Perimeter resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/networkSecurityPerimeterConfigurations/reconcile/action

#
Namespace
Microsoft.KeyVault

Description

Reconcile the Network Security Perimeter configuration stored in a vault with NRP's (Microsoft.Network Resource Provider) copy.

References #

Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.KeyVault

Description

Delete a connection proxy to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.KeyVault

Description

Validate a connection proxy to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.KeyVault

Description

Change the state of a connection proxy to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/privateEndpointConnections/delete

#
Namespace
Microsoft.KeyVault

Description

Delete a connection to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/privateEndpointConnections/write

#
Namespace
Microsoft.KeyVault

Description

Change the state of a connection to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.KeyVault

Description

Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider

References #

Microsoft.KeyVault/vaults/providers/Microsoft.Insights/diagnosticSettings/Write

#
Namespace
Microsoft.KeyVault

Description

Creates or updates the diagnostic setting for the resource

References #

Microsoft.KeyVault/vaults/secrets/write

#
Namespace
Microsoft.KeyVault

Description

Creates a new secret or updates the value of an existing secret.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Microsoft.KeyVault/vaults/write

#
Namespace
Microsoft.KeyVault

Description

Creates a new key vault or updates the properties of an existing key vault. Certain properties may require more permissions.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Accept",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
    "action": "Microsoft.KeyVault/vaults/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
    "action": "Microsoft.KeyVault/vaults/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "6c2c3a4d-9ca4-421c-bfd2-d179ad984175",
  "EventDataId": "62c9e2e9-5b38-c8be-00a7-7a27dfe762d0",
  "EventSubmissionTimestamp": "2026-06-29T19:02:31.9512786Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.KEYVAULT/VAULTS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
    "message": "Microsoft.KeyVault/vaults/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "62c9e2e9-5b38-c8be-00a7-7a27dfe762d0",
    "eventSubmissionTimestamp": "2026-06-29T19:02:31.9512786Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zckv39748",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.KeyVault/vaults/zckv39748",
    "message": "Microsoft.KeyVault/vaults/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "62c9e2e9-5b38-c8be-00a7-7a27dfe762d0",
    "eventSubmissionTimestamp": "2026-06-29T19:02:31.9512786Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zckv39748",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.KEYVAULT",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Accept",
    "activitySubstatusValue": "OK"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.KEYVAULT",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:02:31.9512786Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.keyvault/vaults/zckv39748"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #