Microsoft.Batch/batchAccounts/listKeys/action
Microsoft.Batch/batchAccounts/listKeys/action
Event
The Batch management Get Keys API uses the listKeys endpoint and returns primary and secondary account keys. Current documentation requires SharedKey in allowedAuthenticationModes; getting keys fails when it is not allowed. Subsequent service access also depends on network and account configuration.
Security Context
Unauthorized retrieval may expose credentials (T1552). Legitimate provisioning also uses it. These keys are distinct from the initiating identity’s credentials, but their usefulness can be curtailed by rotation or authentication-mode changes. The event is not proof of submitted jobs or accessed packages.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Batch/batchAccounts/listKeys/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId, caller | Batch account and requesting principal. |
status, subStatus | Outcome; key values are intentionally absent. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify approved key use and effective management-plane authorization.
- Check allowedAuthenticationModes, network restrictions, and relevant key-rotation history.
- Correlate Batch jobs/tasks and service telemetry rather than assuming downstream access from the list operation.
Sample Event
Synthetic scenario. The sample records a successful listKeys operation with no returned secret material or subsequent job activity.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Batch/batchAccounts/listKeys/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010011000", "description": "", "eventDataId": "90000000-0000-4000-8000-000010011001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T21:31:18.5172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010011010", "operationName": { "value": "Microsoft.Batch/batchAccounts/listKeys/action", "localizedValue": "List Batch account keys" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Batch", "localizedValue": "Microsoft Batch" }, "resourceType": { "value": "Microsoft.Batch/batchAccounts", "localizedValue": "Microsoft.Batch/batchAccounts" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T21:31:19.0218728Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy", "message": "Microsoft.Batch/batchAccounts/listKeys/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010011011", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Batch/batchAccounts/batchoccamy/listKeys?api-version=2024-07-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...