Microsoft.Storage/storageAccounts/listKeys/action
Microsoft.Storage/storageAccounts/listKeys/action
Event
Lists account keys that can authorize broad data-plane access through supported Shared Key mechanisms and sign account/service SAS tokens. These are not ARM administration credentials. Usability depends on service-specific Shared Key settings, account existence, key rotation, and network controls.
Security Context
Unauthorized retrieval can expose credentials (T1552). It does not prove any blob or other data was accessed. Approved tooling may also retrieve keys. The keys do not bypass storage firewalls, and disabling applicable Shared Key authorization can prevent their use without rotating them.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/listKeys/action. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor/authorization context; verify effective authority. |
resourceId, correlationId | Exact target and related management operations. |
status, subStatus | Outcome and any asynchronous follow-up. |
properties.requestbody | Submitted configuration where present; returned secrets are intentionally absent. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify approved retrieval and effective management-plane authorization.
- Inspect allowSharedKeyAccess, the targeted storage service, network restrictions, and each key’s rotation history.
- Correlate storage resource logs and SAS/shared-key usage; protect returned keys and do not invent a later deletion chain.
Sample Event
Synthetic scenario. The sample records successful listKeys without secret values or data-plane activity.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Storage/storageAccounts/listKeys/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "saLk224ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100010101", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010110", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:58:42.4218107Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100111000", "operationName": { "value": "Microsoft.Storage/storageAccounts/listKeys/action", "localizedValue": "List Storage Account Keys" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Storage", "localizedValue": "Microsoft.Storage" }, "resourceType": { "value": "Microsoft.Storage/storageAccounts", "localizedValue": "Microsoft.Storage/storageAccounts" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:58:43.0182701Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/listKeys", "message": "Microsoft.Storage/storageAccounts/listKeys/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...