Microsoft.KeyVault/vaults/keys/read
Microsoft.KeyVault/vaults/keys/read
Event
KeyGet returns the public portion and metadata of a stored key. It does not return private key material; symmetric key material is not returned either. Decrypt, sign, and any supported key-release workflow are distinct operations with their own permissions and controls.
Security Context
Public-key lookup is normal cryptographic application behavior. This event alone does not demonstrate credential theft, private-key export, or decryption; no credential-access technique is assigned.
Log Source
Azure Key Vault resource logs, AuditEvent category, with operationName: KeyGet. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.
Key Fields
| Field | Investigation value |
|---|---|
operationName, resultType, properties.httpStatusCode | Data-plane operation and result. |
identity.claim, callerIpAddress | Recorded principal and client context; corroborate attribution. |
properties.requestUri, properties.id | Vault object and version where specified. |
correlationId, time | Correlation and timing; no returned secret or private key is logged here. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm caller, exact key/version, result, and approved application purpose.
- Review key type, permitted operations, and effective data-plane authorization.
- Correlate separate cryptographic-operation or release records before asserting decryption, signing, or key disclosure.
Sample Event
Synthetic scenario. The sample records successful KeyGet. It contains no key response, private material, or cryptographic-operation evidence.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "time": "2026-04-15T17:50:33.2148201Z", "resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD", "operationName": "KeyGet", "operationVersion": "7.4", "category": "AuditEvent", "resultType": "Success", "resultSignature": "OK", "resultDescription": "", "durationMs": "32", "callerIpAddress": "203.0.113.66", "correlationId": "90000000-0000-4000-8000-000100000111", "identity": { "claim": { "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation" } }, "properties": { "id": "https://kv-bowtruckle-prod.vault.azure.net/keys/bowtruckle-data-encryption-key/d00df1366a6c3ebde0c4e97370076507", "clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)", "requestUri": "https://kv-bowtruckle-prod.vault.azure.net/keys/bowtruckle-data-encryption-key/d00df1366a6c3ebde0c4e97370076507?api-version=7.4", "httpStatusCode": 200 }, "tenantId": "10000000-0000-4000-8000-000000000001"}