Skip to content

Microsoft.KeyVault/vaults/delete

Azure

Microsoft.KeyVault/vaults/delete

service: Azure - Key Vault
tactics:
techniques:

Event

Deletion makes the vault unavailable for normal use. Soft-delete is enabled by default for new vaults and cannot be disabled once enabled; inspect the target’s settings. Recovery retention is 7–90 days, defaulting to 90. Purge is separate, and purge protection prevents early purge during retention.

Security Context

Malicious deletion can disrupt workloads or destroy data (contextual T1485), but a delete event alone does not establish permanent loss. Application impact depends on caching, redundancy, and dependencies.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.KeyVault/vaults/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify final vault state, soft-delete retention, purge protection, and recovery authority.
  3. Inspect dependent application failures and retained/cached credentials rather than assuming an immediate universal outage.
  4. Plan recovery with the resource owner; recovered vaults require associated RBAC assignments and Event Grid subscriptions to be recreated.

Sample Event

Synthetic scenario. The sample records vault deletion without retention settings, purge activity, prior secret theft, or workload failure evidence.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.KeyVault/vaults/delete",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "kvDel203ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100000100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100000101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:11:09.2418857Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100000110",
"operationName": {
"value": "Microsoft.KeyVault/vaults/delete",
"localizedValue": "Delete Key Vault"
},
"resourceGroupName": "rg-bowtruckle-vault",
"resourceProviderName": {
"value": "Microsoft.KeyVault",
"localizedValue": "Microsoft.KeyVault"
},
"resourceType": {
"value": "Microsoft.KeyVault/vaults",
"localizedValue": "Microsoft.KeyVault/vaults"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:11:09.7771204Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod",
"message": "Microsoft.KeyVault/vaults/delete",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.