Skip to content

Microsoft.KeyVault/vaults/certificates/read

Azure

Microsoft.KeyVault/vaults/certificates/read

service: Azure - Key Vault
tactics:
techniques:

Event

The data-plane CertificateGet operation returns a public certificate and metadata, including references to its associated key and secret. It does not return the private key. Exporting an eligible certificate’s private key instead requires access to its backing secret and an exportable policy; nonexportable/HSM keys cannot be assumed exportable.

Security Context

Certificate inventory and validation routinely use this operation. Public certificate retrieval alone is not credential theft, so no ATT&CK credential-access mapping is assigned. Investigate separate SecretGet evidence if private-key export is suspected.

Log Source

Azure Key Vault resource logs, AuditEvent category, with operationName: CertificateGet. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.

Key Fields

FieldInvestigation value
operationName, resultType, properties.httpStatusCodeData-plane operation and result.
identity.claim, callerIpAddressRecorded principal and client context; corroborate attribution.
properties.requestUri, properties.idVault object and version where specified.
correlationId, timeCorrelation and timing; no returned secret or private key is logged here.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm caller authorization and the exact certificate name/version and outcome.
  3. Review linked key/secret identifiers and exportability without retrieving private material during routine review.
  4. Correlate separate secret access and downstream authentication before asserting private-key theft.

Sample Event

Synthetic scenario. The sample shows successful CertificateGet for an illustrative version. It contains neither a private key nor evidence of backing-secret retrieval.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"time": "2026-04-15T17:48:21.5421047Z",
"resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD",
"operationName": "CertificateGet",
"operationVersion": "7.4",
"category": "AuditEvent",
"resultType": "Success",
"resultSignature": "OK",
"resultDescription": "",
"durationMs": "47",
"callerIpAddress": "203.0.113.66",
"correlationId": "90000000-0000-4000-8000-000100000011",
"identity": {
"claim": {
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation"
}
},
"properties": {
"id": "https://kv-bowtruckle-prod.vault.azure.net/certificates/bowtruckle-prod-tls-cert/a197a2b2e441539aff6947a64eacf1a6",
"clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)",
"requestUri": "https://kv-bowtruckle-prod.vault.azure.net/certificates/bowtruckle-prod-tls-cert/a197a2b2e441539aff6947a64eacf1a6?api-version=7.4",
"httpStatusCode": 200
},
"tenantId": "10000000-0000-4000-8000-000000000001"
}

Sources

Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.