Skip to content

Microsoft.OperationalInsights/workspaces/sharedKeys/action

Azure

Microsoft.OperationalInsights/workspaces/sharedKeys/action

service: Azure - Log Analytics
techniques:

Event

The sharedKeys management endpoint returns workspace shared keys. With the workspace customerId, these can authenticate legacy HTTP Data Collector ingestion; they are not workspace query or ARM administration credentials. Support for that API ended September 14, 2026, although Microsoft says ingestion continues; its replacement uses the Logs ingestion API and a different authorization model.

Security Context

Unauthorized key retrieval can expose credentials (T1552) and enable fabricated custom log ingestion where the legacy path is usable. It does not prove ingestion, overwrite existing records, or confer arbitrary write access to every table. Legitimate legacy integrations also retrieve keys.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.OperationalInsights/workspaces/sharedKeys/action. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm retrieval approval and inventory remaining shared-key consumers and rotation dependencies.
  3. Identify whether the legacy ingestion path is used and inspect its limits and workspace configuration; do not infer that modern AMA uses these keys.
  4. Correlate actual ingestion anomalies and migration status. Keep any returned keys out of investigation notes.

Sample Event

Synthetic scenario. The sample records sharedKeys retrieval without returned values, a workspace customerId, or subsequent ingestion. The API path is sharedKeys, not getSharedKeys.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.OperationalInsights/workspaces/sharedKeys/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-prod"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "lawSk211ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100011110",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100011111",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:08:21.5128194Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100100000",
"operationName": {
"value": "Microsoft.OperationalInsights/workspaces/sharedKeys/action",
"localizedValue": "List Workspace Shared Keys"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.OperationalInsights",
"localizedValue": "Microsoft.OperationalInsights"
},
"resourceType": {
"value": "Microsoft.OperationalInsights/workspaces",
"localizedValue": "Microsoft.OperationalInsights/workspaces"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-prod",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:08:22.0801724Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.OperationalInsights/workspaces/law-fantasticlogs-prod/sharedKeys",
"message": "Microsoft.OperationalInsights/workspaces/sharedKeys/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.