Review Azure Key Vault audit-log collection

Send Key Vault AuditEvent logs to the required destination and verify actual access records.

Description

Key Vault handles sensitive access to keys, secrets and certificates. Without the required audit logs, centrally tracing who performed an operation is difficult, and identifying an incident’s cause and affected scope can take longer.

Export the AuditEvent category through diagnostic settings and verify actual collection. Logging does not replace access control, and the log destination also needs appropriate protection.

Potential impact

  • Investigating operations involving secret retrieval or key use can become difficult.
  • Missing audit evidence can delay incident investigation and assessment of the affected scope.

Remediation

  • Select AuditEvent in the vault’s azurerm_monitor_diagnostic_setting and specify a Storage Account, Log Analytics or Event Hubs destination.
  • Use real Key Vault operations to test log delivery and confirm that required events are included.
  • Manage retention and access at the destination, and configure monitoring and alerts for unusual access.

Examples

This logging comparison omits referenced resources. Key permissions, network controls and deletion protection need separate review.

Before

hcl
resource "azurerm_key_vault" "example" {
  name                        = "testvault"
  location                    = azurerm_resource_group.example.location
  resource_group_name         = azurerm_resource_group.example.name
  enabled_for_disk_encryption = true
  tenant_id                   = data.azurerm_client_config.current.tenant_id
  soft_delete_retention_days  = 7
  purge_protection_enabled    = false

  sku_name = "standard"
}

This excerpt has no audit-log export. Check whether other existing diagnostic settings collect the required records.

After

hcl
resource "azurerm_key_vault" "example" {
  name                        = "testvault"
  location                    = azurerm_resource_group.example.location
  resource_group_name         = azurerm_resource_group.example.name
  enabled_for_disk_encryption = true
  tenant_id                   = data.azurerm_client_config.current.tenant_id
  soft_delete_retention_days  = 7
  purge_protection_enabled    = false

  sku_name = "standard"
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "keyvault-diagnostics"
  target_resource_id = azurerm_key_vault.example.id
  storage_account_id = data.azurerm_storage_account.example.id

  enabled_log {
    category = "AuditEvent"
  }
}

AuditEvent logs are sent to the existing storage account. Verify actual records and the destination’s retention and access policies after configuration.

References