Skip to content

Microsoft.Batch/batchAccounts/listKeys/action

Azure

Microsoft.Batch/batchAccounts/listKeys/action

service: Azure - Batch
techniques:

Event

The Batch management Get Keys API uses the listKeys endpoint and returns primary and secondary account keys. Current documentation requires SharedKey in allowedAuthenticationModes; getting keys fails when it is not allowed. Subsequent service access also depends on network and account configuration.

Security Context

Unauthorized retrieval may expose credentials (T1552). Legitimate provisioning also uses it. These keys are distinct from the initiating identity’s credentials, but their usefulness can be curtailed by rotation or authentication-mode changes. The event is not proof of submitted jobs or accessed packages.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Batch/batchAccounts/listKeys/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
resourceId, callerBatch account and requesting principal.
status, subStatusOutcome; key values are intentionally absent.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify approved key use and effective management-plane authorization.
  3. Check allowedAuthenticationModes, network restrictions, and relevant key-rotation history.
  4. Correlate Batch jobs/tasks and service telemetry rather than assuming downstream access from the list operation.

Sample Event

Synthetic scenario. The sample records a successful listKeys operation with no returned secret material or subsequent job activity.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Batch/batchAccounts/listKeys/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010011000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010011001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T21:31:18.5172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010011010",
"operationName": {
"value": "Microsoft.Batch/batchAccounts/listKeys/action",
"localizedValue": "List Batch account keys"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Batch",
"localizedValue": "Microsoft Batch"
},
"resourceType": {
"value": "Microsoft.Batch/batchAccounts",
"localizedValue": "Microsoft.Batch/batchAccounts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T21:31:19.0218728Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy",
"message": "Microsoft.Batch/batchAccounts/listKeys/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010011011",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy/listKeys?api-version=2024-07-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.