Skip to content

Microsoft.KeyVault/vaults/accessPolicies/write

Azure

Microsoft.KeyVault/vaults/accessPolicies/write

service: Azure - Key Vault
techniques:

Event

Changes data-plane permissions under the vault access-policy authorization model. In Azure RBAC mode, data access is controlled by role assignments instead. The API selects add, replace, or remove in the URL operationKind; a body alone does not identify the mode.

Security Context

Unauthorized grants can support account manipulation (T1098). Secret get can disclose a secret value, while key get returns public material/metadata rather than private keys. A policy change does not prove subsequent data access and does not override network restrictions.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.KeyVault/vaults/accessPolicies/write. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the vault authorization model, request URL operationKind, and previous/new policy entries.
  3. Review the principal IDs and individual key, secret, and certificate permissions; key get/list does not grant decrypt.
  4. Correlate authorized AuditEvent collection and actual successful reads, with network restrictions and resource state.

Sample Event

Synthetic scenario. The submitted entry grants keys get/list and secrets get/list, with an empty certificates permission list. It does not grant certificate reads. The request URL and subsequent access are absent.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.KeyVault/vaults/accessPolicies/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "kvAccPol202ExampleUti",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100000000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100000001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:46:55.8174302Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100000010",
"operationName": {
"value": "Microsoft.KeyVault/vaults/accessPolicies/write",
"localizedValue": "Update Access Policy"
},
"resourceGroupName": "rg-bowtruckle-vault",
"resourceProviderName": {
"value": "Microsoft.KeyVault",
"localizedValue": "Microsoft.KeyVault"
},
"resourceType": {
"value": "Microsoft.KeyVault/vaults/accessPolicies",
"localizedValue": "Microsoft.KeyVault/vaults/accessPolicies"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:46:56.4023881Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod",
"message": "Microsoft.KeyVault/vaults/accessPolicies/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"properties\":{\"accessPolicies\":[{\"tenantId\":\"10000000-0000-4000-8000-000000000001\",\"objectId\":\"30000000-0000-4000-8000-001010011010\",\"permissions\":{\"keys\":[\"get\",\"list\"],\"secrets\":[\"get\",\"list\"],\"certificates\":[]}}]}}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.