Microsoft.KeyVault/vaults/delete
Microsoft.KeyVault/vaults/delete
Event
Deletion makes the vault unavailable for normal use. Soft-delete is enabled by default for new vaults and cannot be disabled once enabled; inspect the target’s settings. Recovery retention is 7–90 days, defaulting to 90. Purge is separate, and purge protection prevents early purge during retention.
Security Context
Malicious deletion can disrupt workloads or destroy data (contextual T1485), but a delete event alone does not establish permanent loss. Application impact depends on caching, redundancy, and dependencies.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.KeyVault/vaults/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify final vault state, soft-delete retention, purge protection, and recovery authority.
- Inspect dependent application failures and retained/cached credentials rather than assuming an immediate universal outage.
- Plan recovery with the resource owner; recovered vaults require associated RBAC assignments and Event Grid subscriptions to be recreated.
Sample Event
Synthetic scenario. The sample records vault deletion without retention settings, purge activity, prior secret theft, or workload failure evidence.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.KeyVault/vaults/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "kvDel203ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100000100", "description": "", "eventDataId": "90000000-0000-4000-8000-000100000101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:11:09.2418857Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100000110", "operationName": { "value": "Microsoft.KeyVault/vaults/delete", "localizedValue": "Delete Key Vault" }, "resourceGroupName": "rg-bowtruckle-vault", "resourceProviderName": { "value": "Microsoft.KeyVault", "localizedValue": "Microsoft.KeyVault" }, "resourceType": { "value": "Microsoft.KeyVault/vaults", "localizedValue": "Microsoft.KeyVault/vaults" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:11:09.7771204Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod", "message": "Microsoft.KeyVault/vaults/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...