Microsoft.KeyVault/vaults/secrets/delete
Microsoft.KeyVault/vaults/secrets/delete
Event
SecretDelete acts on the named secret, including all versions, rather than selecting a single version. With soft-delete, recovery remains possible during retention; purge is a separate operation. Deleting a stored password does not itself rotate or invalidate that password in the downstream service.
Security Context
Malicious deletion can disrupt dependent workloads (contextual T1485). Approved retirement also uses it. Cached values and redundancy affect impact, and deletion is not proof of immediate application failure or irreversible loss.
Log Source
Azure Key Vault resource logs, AuditEvent category, with operationName: SecretDelete. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.
Key Fields
| Field | Investigation value |
|---|---|
operationName, resultType, properties.httpStatusCode | Data-plane operation and result. |
identity.claim, callerIpAddress | Recorded principal and client context; corroborate attribution. |
properties.requestUri, properties.id | Vault object and version where specified. |
correlationId, time | Correlation and timing; no returned secret or private key is logged here. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm the secret name, outcome, retention, purge protection, and any recovery or purge records.
- Review dependent applications and observed retrieval failures, including caches and alternative credentials.
- Coordinate recovery or downstream credential rotation according to the actual incident; do not infer prior exfiltration.
Sample Event
Synthetic scenario. The sample deletes bowtruckle-prod-db-password without a version suffix. It does not show purge, downstream password invalidation, or application impact.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "time": "2026-04-15T18:13:42.6029771Z", "resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD", "operationName": "SecretDelete", "operationVersion": "7.4", "category": "AuditEvent", "resultType": "Success", "resultSignature": "OK", "resultDescription": "", "durationMs": "33", "callerIpAddress": "203.0.113.66", "correlationId": "90000000-0000-4000-8000-000100001000", "identity": { "claim": { "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation" } }, "properties": { "id": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password", "clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)", "requestUri": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password?api-version=7.4", "httpStatusCode": 200 }, "tenantId": "10000000-0000-4000-8000-000000000001"}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...