Skip to content

Microsoft.KeyVault/vaults/keys/read

Azure

Microsoft.KeyVault/vaults/keys/read

service: Azure - Key Vault
tactics:
techniques:

Event

KeyGet returns the public portion and metadata of a stored key. It does not return private key material; symmetric key material is not returned either. Decrypt, sign, and any supported key-release workflow are distinct operations with their own permissions and controls.

Security Context

Public-key lookup is normal cryptographic application behavior. This event alone does not demonstrate credential theft, private-key export, or decryption; no credential-access technique is assigned.

Log Source

Azure Key Vault resource logs, AuditEvent category, with operationName: KeyGet. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.

Key Fields

FieldInvestigation value
operationName, resultType, properties.httpStatusCodeData-plane operation and result.
identity.claim, callerIpAddressRecorded principal and client context; corroborate attribution.
properties.requestUri, properties.idVault object and version where specified.
correlationId, timeCorrelation and timing; no returned secret or private key is logged here.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm caller, exact key/version, result, and approved application purpose.
  3. Review key type, permitted operations, and effective data-plane authorization.
  4. Correlate separate cryptographic-operation or release records before asserting decryption, signing, or key disclosure.

Sample Event

Synthetic scenario. The sample records successful KeyGet. It contains no key response, private material, or cryptographic-operation evidence.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"time": "2026-04-15T17:50:33.2148201Z",
"resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD",
"operationName": "KeyGet",
"operationVersion": "7.4",
"category": "AuditEvent",
"resultType": "Success",
"resultSignature": "OK",
"resultDescription": "",
"durationMs": "32",
"callerIpAddress": "203.0.113.66",
"correlationId": "90000000-0000-4000-8000-000100000111",
"identity": {
"claim": {
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation"
}
},
"properties": {
"id": "https://kv-bowtruckle-prod.vault.azure.net/keys/bowtruckle-data-encryption-key/d00df1366a6c3ebde0c4e97370076507",
"clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)",
"requestUri": "https://kv-bowtruckle-prod.vault.azure.net/keys/bowtruckle-data-encryption-key/d00df1366a6c3ebde0c4e97370076507?api-version=7.4",
"httpStatusCode": 200
},
"tenantId": "10000000-0000-4000-8000-000000000001"
}

Sources

Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.