Microsoft.AppConfiguration/configurationStores/listKeys/action
Microsoft.AppConfiguration/configurationStores/listKeys/action
Event
Returns store access keys and connection strings, including read-only and read-write keys. Primary and secondary keys exist for each access level; this is not simply one key of each kind. Effective data access also depends on access-key authentication being enabled and network reachability.
Security Context
Unauthorized key retrieval can expose credentials (T1552). Deployment tooling and key administration also use it. Keys are separate from the caller’s password, but can be rotated and access-key authentication disabled. Key Vault references are references, not proof that underlying Key Vault secrets were retrieved.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.AppConfiguration/configurationStores/ListKeys/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId, caller | Store and requesting identity. |
status, subStatus | Request outcome; the sample contains no returned key values. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify why this identity needed keys rather than its expected store access.
- Check key authentication, network controls, and which keys could have been returned; never copy live connection strings into notes.
- Correlate store data-plane activity and key rotation. Do not infer arbitrary downstream secrets from a store name.
Sample Event
Synthetic scenario. The sample records a successful key-list action without key material or evidence of subsequent data access.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.AppConfiguration/configurationStores/ListKeys/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000001110100", "description": "", "eventDataId": "90000000-0000-4000-8000-000001110101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T19:58:32.6172843Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000001110110", "operationName": { "value": "Microsoft.AppConfiguration/configurationStores/ListKeys/action", "localizedValue": "List App Configuration store keys" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.AppConfiguration", "localizedValue": "Microsoft App Configuration" }, "resourceType": { "value": "Microsoft.AppConfiguration/configurationStores", "localizedValue": "Microsoft.AppConfiguration/configurationStores" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T19:58:33.0184215Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod", "message": "Microsoft.AppConfiguration/configurationStores/ListKeys/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000001110111", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.AppConfiguration/configurationStores/appconf-occamy-prod/listKeys?api-version=2023-03-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...