Skip to content

Microsoft.ServiceBus/namespaces/authorizationRules/listKeys/action

Azure

Microsoft.ServiceBus/namespaces/authorizationRules/listKeys/action

service: Azure - Service Bus
techniques:

Event

Returns the rule’s primary/secondary keys and connection strings. SAS use is constrained by the rule’s rights and scope; RootManageSharedAccessKey is a namespace-wide management rule. SAS authentication does not bypass network restrictions, and disabling local authentication prevents use of SAS credentials.

Security Context

Unauthorized retrieval can expose credentials (T1552). Approved integration setup also uses this operation. Retrieval does not establish message access, queue/topic changes, or internet-wide connectivity.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.ServiceBus/namespaces/authorizationRules/listKeys/action. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the authorization rule’s actual rights, scope, and approved key-retrieval purpose.
  3. Review disableLocalAuth, firewall/private-network configuration, and primary/secondary key rotation history.
  4. Correlate actual messaging and entity-management activity; keep keys and connection strings out of incident notes.

Sample Event

Synthetic scenario. The sample retrieves keys for RootManageSharedAccessKey. It contains no returned credentials, network configuration, or subsequent Service Bus access.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.ServiceBus/namespaces/authorizationRules/listKeys/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ServiceBus/namespaces/sb-occamy-events/AuthorizationRules/RootManageSharedAccessKey"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "sbLk219ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100001101",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100001110",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:54:21.1428207Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100110011",
"operationName": {
"value": "Microsoft.ServiceBus/namespaces/authorizationRules/listKeys/action",
"localizedValue": "List Service Bus Namespace Keys"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.ServiceBus",
"localizedValue": "Microsoft.ServiceBus"
},
"resourceType": {
"value": "Microsoft.ServiceBus/namespaces/AuthorizationRules",
"localizedValue": "Microsoft.ServiceBus/namespaces/AuthorizationRules"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ServiceBus/namespaces/sb-occamy-events/AuthorizationRules/RootManageSharedAccessKey",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:54:21.6029108Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ServiceBus/namespaces/sb-occamy-events/AuthorizationRules/RootManageSharedAccessKey/listKeys",
"message": "Microsoft.ServiceBus/namespaces/authorizationRules/listKeys/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.