For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-k8k.md. A documentation index is available at /llms.txt.

Azure Key Vault should use RBAC

Rationale:

This detection identifies Azure Key Vaults with enable_rbac_authorization not set to true. This identifies Key Vaults where RBAC authentication is not implemented.

Remediation:

  1. Evaluate the need for the access policy permissions model in your Key Vault.
  2. If not required, migrate your Key Vault to the RBAC permissions model following guidance from Microsoft.