Microsoft.KeyVault/vaults/accessPolicies/write
Microsoft.KeyVault/vaults/accessPolicies/write
Event
Changes data-plane permissions under the vault access-policy authorization model. In Azure RBAC mode, data access is controlled by role assignments instead. The API selects add, replace, or remove in the URL operationKind; a body alone does not identify the mode.
Security Context
Unauthorized grants can support account manipulation (T1098). Secret get can disclose a secret value, while key get returns public material/metadata rather than private keys. A policy change does not prove subsequent data access and does not override network restrictions.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.KeyVault/vaults/accessPolicies/write. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the vault authorization model, request URL operationKind, and previous/new policy entries.
- Review the principal IDs and individual key, secret, and certificate permissions; key get/list does not grant decrypt.
- Correlate authorized AuditEvent collection and actual successful reads, with network restrictions and resource state.
Sample Event
Synthetic scenario. The submitted entry grants keys get/list and secrets get/list, with an empty certificates permission list. It does not grant certificate reads. The request URL and subsequent access are absent.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.KeyVault/vaults/accessPolicies/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "kvAccPol202ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100000000", "description": "", "eventDataId": "90000000-0000-4000-8000-000100000001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:46:55.8174302Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100000010", "operationName": { "value": "Microsoft.KeyVault/vaults/accessPolicies/write", "localizedValue": "Update Access Policy" }, "resourceGroupName": "rg-bowtruckle-vault", "resourceProviderName": { "value": "Microsoft.KeyVault", "localizedValue": "Microsoft.KeyVault" }, "resourceType": { "value": "Microsoft.KeyVault/vaults/accessPolicies", "localizedValue": "Microsoft.KeyVault/vaults/accessPolicies" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:46:56.4023881Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod", "message": "Microsoft.KeyVault/vaults/accessPolicies/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"properties\":{\"accessPolicies\":[{\"tenantId\":\"10000000-0000-4000-8000-000000000001\",\"objectId\":\"30000000-0000-4000-8000-001010011010\",\"permissions\":{\"keys\":[\"get\",\"list\"],\"secrets\":[\"get\",\"list\"],\"certificates\":[]}}]}}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...