Skip to content

Microsoft.AppConfiguration/configurationStores/listKeys/action

Azure

Microsoft.AppConfiguration/configurationStores/listKeys/action

service: Azure - App Configuration
techniques:

Event

Returns store access keys and connection strings, including read-only and read-write keys. Primary and secondary keys exist for each access level; this is not simply one key of each kind. Effective data access also depends on access-key authentication being enabled and network reachability.

Security Context

Unauthorized key retrieval can expose credentials (T1552). Deployment tooling and key administration also use it. Keys are separate from the caller’s password, but can be rotated and access-key authentication disabled. Key Vault references are references, not proof that underlying Key Vault secrets were retrieved.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.AppConfiguration/configurationStores/ListKeys/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
resourceId, callerStore and requesting identity.
status, subStatusRequest outcome; the sample contains no returned key values.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify why this identity needed keys rather than its expected store access.
  3. Check key authentication, network controls, and which keys could have been returned; never copy live connection strings into notes.
  4. Correlate store data-plane activity and key rotation. Do not infer arbitrary downstream secrets from a store name.

Sample Event

Synthetic scenario. The sample records a successful key-list action without key material or evidence of subsequent data access.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.AppConfiguration/configurationStores/ListKeys/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000001110100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000001110101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T19:58:32.6172843Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000001110110",
"operationName": {
"value": "Microsoft.AppConfiguration/configurationStores/ListKeys/action",
"localizedValue": "List App Configuration store keys"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.AppConfiguration",
"localizedValue": "Microsoft App Configuration"
},
"resourceType": {
"value": "Microsoft.AppConfiguration/configurationStores",
"localizedValue": "Microsoft.AppConfiguration/configurationStores"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T19:58:33.0184215Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod",
"message": "Microsoft.AppConfiguration/configurationStores/ListKeys/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000001110111",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod/listKeys?api-version=2023-03-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.