Skip to content

Microsoft.Storage/storageAccounts/listKeys/action

Azure

Microsoft.Storage/storageAccounts/listKeys/action

service: Azure - Azure Storage
techniques:

Event

Lists account keys that can authorize broad data-plane access through supported Shared Key mechanisms and sign account/service SAS tokens. These are not ARM administration credentials. Usability depends on service-specific Shared Key settings, account existence, key rotation, and network controls.

Security Context

Unauthorized retrieval can expose credentials (T1552). It does not prove any blob or other data was accessed. Approved tooling may also retrieve keys. The keys do not bypass storage firewalls, and disabling applicable Shared Key authorization can prevent their use without rotating them.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/listKeys/action. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor/authorization context; verify effective authority.
resourceId, correlationIdExact target and related management operations.
status, subStatusOutcome and any asynchronous follow-up.
properties.requestbodySubmitted configuration where present; returned secrets are intentionally absent.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify approved retrieval and effective management-plane authorization.
  3. Inspect allowSharedKeyAccess, the targeted storage service, network restrictions, and each key’s rotation history.
  4. Correlate storage resource logs and SAS/shared-key usage; protect returned keys and do not invent a later deletion chain.

Sample Event

Synthetic scenario. The sample records successful listKeys without secret values or data-plane activity.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Storage/storageAccounts/listKeys/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "saLk224ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100010101",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100010110",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:58:42.4218107Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100111000",
"operationName": {
"value": "Microsoft.Storage/storageAccounts/listKeys/action",
"localizedValue": "List Storage Account Keys"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Storage",
"localizedValue": "Microsoft.Storage"
},
"resourceType": {
"value": "Microsoft.Storage/storageAccounts",
"localizedValue": "Microsoft.Storage/storageAccounts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:58:43.0182701Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/listKeys",
"message": "Microsoft.Storage/storageAccounts/listKeys/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.