Skip to content

Microsoft.Storage/storageAccounts/regenerateKey/action

Azure

Microsoft.Storage/storageAccounts/regenerateKey/action

service: Azure - Azure Storage
techniques:

Event

Replaces the selected key and returns account key information to the authorized caller. Requests signed using the old key, including associated account/service SAS tokens, can lose access. The other account key and Entra-based authorization are separate; impact depends on what clients actually use.

Security Context

Unauthorized rotation can expose credentials (T1552) or disrupt legitimate access (T1531). Planned rotation is normal. This is not application-token theft, and one rotation does not prove all applications failed or the new key was used.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Storage/storageAccounts/regenerateKey/action. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor/authorization context; verify effective authority.
resourceId, correlationIdExact target and related management operations.
status, subStatusOutcome and any asynchronous follow-up.
properties.requestbodySubmitted configuration where present; returned secrets are intentionally absent.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify keyName, approved rotation, and the returned operation outcome without recording live key values.
  3. Inventory clients and SAS tokens tied to that key, fallback to the other key, and non-key authentication.
  4. Correlate observed authentication failures and subsequent storage access before claiming outage or credential abuse.

Sample Event

Synthetic scenario. The sample regenerates key1, with no returned key, client inventory, or authentication results shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "saRk225ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100010111",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100011000",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:59:18.5028207Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100111001",
"operationName": {
"value": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"localizedValue": "Regenerate Storage Account Keys"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Storage",
"localizedValue": "Microsoft.Storage"
},
"resourceType": {
"value": "Microsoft.Storage/storageAccounts",
"localizedValue": "Microsoft.Storage/storageAccounts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:59:19.0421112Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Storage/storageAccounts/flcoccamy001/regenerateKey",
"message": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"keyName\":\"key1\"}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access Impact

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.