VaultPatch
VaultPatch
Event
Vault PATCH updates selected configuration and is recorded under Microsoft.KeyVault/vaults/write. An ACL defaultAction of Allow can relax firewall filtering when public access is enabled, but publicNetworkAccess, other network controls, and data-plane authorization still govern access. Omitted properties do not demonstrate their existing values.
Security Context
Unauthorized firewall relaxation can impair cloud network controls (T1686.001). A vault configuration write does not retrieve secrets, so the credential-store access mapping is removed. Purge protection cannot be disabled once enabled; a null field is not proof of prior protection or successful removal.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.KeyVault/vaults/write. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor/authorization context; verify effective authority. |
resourceId, correlationId | Exact target and related management operations. |
status, subStatus | Outcome and any asynchronous follow-up. |
properties.requestbody | Submitted configuration where present; returned secrets are intentionally absent. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Compare complete before/after vault configuration and approval, including publicNetworkAccess and network ACLs.
- Verify the authorization model and effective data-plane grants separately from network reachability.
- Correlate actual Key Vault AuditEvent reads and their results before asserting secret disclosure.
Sample Event
Synthetic scenario. The request changes only networkAcls to defaultAction Allow with empty rules. The unneeded soft-delete and null purge-protection properties were removed; prior configuration and successful secret access are not shown.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.KeyVault/vaults/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "kvPatch233ExampleUtid", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100100011", "description": "", "eventDataId": "90000000-0000-4000-8000-000100100100", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:44:18.4218072Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100111101", "operationName": { "value": "Microsoft.KeyVault/vaults/write", "localizedValue": "VaultPatch" }, "resourceGroupName": "rg-bowtruckle-vault", "resourceProviderName": { "value": "Microsoft.KeyVault", "localizedValue": "Microsoft.KeyVault" }, "resourceType": { "value": "Microsoft.KeyVault/vaults", "localizedValue": "Microsoft.KeyVault/vaults" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:44:19.0301428Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-bowtruckle-vault/providers/Microsoft.KeyVault/vaults/kv-bowtruckle-prod", "message": "Microsoft.KeyVault/vaults/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"properties\":{\"networkAcls\":{\"defaultAction\":\"Allow\",\"bypass\":\"AzureServices\",\"ipRules\":[],\"virtualNetworkRules\":[]}}}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.