This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
--> Secure secrets and keys by using Azure Key Vault
--> Implement Defender for Key Vault
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Azure Key Vault is designed to securely store and manage sensitive information such as:
- Cryptographic keys
- Secrets
- Passwords
- Connection strings
- Certificates
While Key Vault provides strong security controls for authentication, authorization, encryption, networking, and auditing, organizations also need to detect suspicious or potentially malicious access to the vault.
Microsoft Defender for Key Vault provides an additional threat-detection layer for Azure Key Vault. It uses security intelligence and behavioral analysis to identify unusual and potentially harmful access patterns involving Key Vault.
For the SC-500 exam, it is important to understand that Defender for Key Vault is primarily a threat detection and alerting capability. It does not replace Key Vault access controls, Azure RBAC, firewall rules, private endpoints, or diagnostic logging.
What Is Microsoft Defender for Key Vault?
Microsoft Defender for Key Vault is a workload protection capability within Microsoft Defender for Cloud.
It monitors Key Vault activity and looks for patterns that may indicate:
- Compromised credentials
- Credential theft
- Secret discovery or dumping
- Unauthorized access attempts
- Access from suspicious locations
- Unusual users or applications accessing a vault
- Unusual volumes of Key Vault operations
- Suspicious sequences of Key Vault operations
The goal is to detect threats that may not be obvious simply by looking at whether an individual request was technically authorized.
For example, suppose a service principal normally accesses one Key Vault from an expected application environment. Suddenly, the same identity accesses many Key Vaults and performs an unusually large number of secret operations.
The individual requests might be authorized, but the behavioral pattern could indicate that the identity has been compromised.
Defender for Key Vault can identify this type of activity and generate a security alert.
Why Defender for Key Vault Is Important
Key Vault frequently contains information that can provide an attacker with access to other systems.
For example, a secret might contain:
- A database password
- An API key
- A connection string
- A service credential
- A certificate
- An application secret
An attacker who gains access to Key Vault may therefore be able to move laterally into other resources.
This makes Key Vault a particularly attractive target.
Defender for Key Vault adds another security layer by attempting to identify suspicious access after authentication and authorization controls have been applied.
A useful way to think about the security layers is:
| Security layer | Primary purpose |
|---|---|
| Microsoft Entra ID | Authentication and identity |
| Azure RBAC / Key Vault permissions | Authorization |
| Network rules / firewall | Network access control |
| Private Endpoint | Private network connectivity |
| Diagnostic logging | Activity visibility |
| Microsoft Defender for Key Vault | Threat detection |
| Microsoft Sentinel | SIEM/SOAR investigation and response |
The important exam concept is that these controls complement one another.
Defender for Key Vault vs. Key Vault Security Controls
A common SC-500 question may describe several possible security mechanisms and ask which one addresses a particular requirement.
Authentication
Microsoft Entra ID determines who or what is attempting to access Key Vault.
Authorization
Azure RBAC or Key Vault’s supported permission model determines what that identity is allowed to do.
Network Security
Key Vault firewall/network settings and private endpoints determine where network access can originate from and how the service is reached.
Logging
Key Vault diagnostic logging records operations and provides information for auditing and investigation.
Defender for Key Vault
Defender for Key Vault analyzes activity for suspicious or anomalous behavior and generates security alerts.
Therefore:
Defender for Key Vault does not grant access, deny access, replace RBAC, or act as the Key Vault firewall.
Its primary role is threat detection.
Enabling Defender for Key Vault
Defender for Key Vault is enabled through Microsoft Defender for Cloud.
The general process is:
- Open Microsoft Defender for Cloud in the Azure portal.
- Select Environment settings.
- Select the Azure subscription to protect.
- Open Defender plans.
- Turn the Key Vault plan on.
- Save the configuration.
Once enabled, Defender for Key Vault provides threat protection for the applicable Key Vault resources in the protected subscription.
Important exam point
Defender for Key Vault is a Defender for Cloud workload protection plan.
It is not a feature that you enable by going into an individual Key Vault and turning on a generic “Defender” switch.
Prerequisites
Before enabling Defender for Key Vault, Microsoft Defender for Cloud must be enabled for the Azure subscription.
The basic sequence is therefore:
Azure subscription → Microsoft Defender for Cloud → Key Vault plan
You should also understand that enabling Defender for Key Vault is different from configuring Key Vault itself.
A secure Key Vault should still have appropriate:
- Identity controls
- RBAC permissions
- Network restrictions
- Private connectivity where appropriate
- Logging
- Monitoring
- Key and secret lifecycle management
Defender for Key Vault provides additional threat detection rather than replacing these controls.
What Does Defender for Key Vault Detect?
Defender for Key Vault focuses on unusual and potentially malicious access patterns.
The exact alerts can evolve as Microsoft improves its threat detection capabilities, but important categories include the following.
Access From a Suspicious IP Address
Defender for Key Vault can detect successful Key Vault access originating from an IP address identified as suspicious by Microsoft’s threat intelligence.
For example:
A service principal normally accesses a Key Vault from an organization’s Azure environment. The same identity successfully accesses the vault from an IP address associated with malicious activity.
This can generate a security alert.
The important point is that the access may have succeeded.
Defender is detecting the suspicious nature of the access rather than simply reporting a failed authorization attempt.
Access From a TOR Exit Node
Access to a Key Vault through a known TOR exit node can indicate an attempt to conceal the source of the connection.
Defender for Key Vault can generate an alert when a vault is accessed from a known TOR exit node.
This is another example of behavioral/threat intelligence detection rather than traditional authorization.
High Volume of Key Vault Operations
Defender can identify an anomalous volume of operations involving a user, service principal, or Key Vault.
For example:
An application normally performs a few hundred Key Vault operations per day.
Suddenly, thousands of operations occur within a short period.
That behavior could indicate:
- Credential compromise
- Secret discovery
- Automated data collection
- An application malfunction
- Other abnormal activity
Defender can generate an alert for investigation.
Importantly, an anomaly does not automatically mean an attack occurred.
Legitimate applications can sometimes produce unusual patterns.
Suspicious Policy Change Followed by Secret Retrieval
One particularly important attack pattern involves changing access permissions and then retrieving secrets.
For example:
- An identity modifies Key Vault access permissions.
- The identity subsequently performs Secret Get operations.
- The sequence is unusual for that identity.
This could indicate that an attacker has obtained sufficient privileges to modify access controls and is attempting to gain access to secrets that were previously inaccessible.
Defender for Key Vault can identify this type of suspicious sequence.
Exam takeaway
Pay attention to sequences of actions, not just individual actions.
A single legitimate operation might not be suspicious.
A sequence such as:
change permissions → retrieve secrets
can be much more significant.
Suspicious Secret Listing Followed by Secret Retrieval
Another important pattern involves secret enumeration.
An attacker may first attempt to determine what secrets exist and then retrieve them.
For example:
Secret List → Secret Get → Secret Get → Secret Get
This can be associated with attempts to discover and extract credentials.
Defender for Key Vault can detect anomalous patterns involving secret listing followed by secret retrieval.
This is particularly important because stolen Key Vault secrets can potentially provide access to additional systems.
Unusual User Access
Defender can identify situations where a user who does not normally access a Key Vault suddenly accesses it.
For example:
An employee normally works with development resources and has never accessed production Key Vaults.
Suddenly, that user accesses a production Key Vault.
Even if the access is technically permitted, the behavioral anomaly may warrant investigation.
Unusual Application or Service Principal Access
The same concept applies to applications and service principals.
For example:
A service principal normally accesses:
- Key Vault A
It suddenly begins accessing:
- Key Vault B
- Key Vault C
- Key Vault D
- Key Vault E
Defender may identify the unusual application behavior.
This can be particularly useful for detecting compromised application identities.
Unusual User/Application Pair
Defender can also identify an unusual combination of a user and application/service principal accessing a Key Vault.
This provides a more contextual view than simply asking:
“Did this user access the vault?”
The detection can consider whether the user/application relationship itself is unusual.
High-Volume Access to Multiple Key Vaults
Another potentially suspicious pattern is when a user or service principal accesses an unusually large number of Key Vaults.
An attacker who compromises an identity may attempt to enumerate vaults throughout an environment in search of valuable secrets.
For example:
Key Vault 1 → Key Vault 2 → Key Vault 3 → Key Vault 4 → …
An unusually broad access pattern may indicate credential compromise or reconnaissance.
Unusual Access Denied Events
Defender for Key Vault can also detect certain unusual unsuccessful access attempts.
Examples include:
- A user who normally doesn’t access a Key Vault attempts access.
- A user or service principal attempts to access an unusually large number of Key Vaults.
- An access attempt originates from a suspicious IP address.
The distinction is important:
Successful suspicious access
Potentially indicates that an attacker has successfully gained access.
Failed suspicious access
May indicate reconnaissance or an attempted attack that was blocked.
Both can be useful security signals.
Defender for Key Vault Alerts
When Defender for Key Vault identifies suspicious activity, it generates security alerts in Microsoft Defender for Cloud.
The alert provides information that can help security personnel investigate the activity.
Depending on the alert, information can include details about:
- The affected Key Vault
- The user or service principal
- The activity
- Source IP information
- The suspicious behavior
- Severity
- Threat context
- Recommended investigation or remediation actions
Security teams can review these alerts through the Defender for Cloud security alerts experience.
Investigating a Defender for Key Vault Alert
When an alert is generated, don’t immediately assume that the identity has been compromised.
Instead, investigate the context.
A useful investigation process is:
1. Identify the affected Key Vault
Determine which vault was accessed.
Ask:
- Is this a production vault?
- What type of information does it contain?
- Which applications depend on it?
2. Identify the identity
Determine whether the activity came from:
- A user
- Service principal
- Managed identity
- Application
3. Examine the activity
Determine what operations were performed.
For example:
- Secret List
- Secret Get
- Key operations
- Permission changes
4. Examine the source
Investigate:
- Source IP
- Geographic context
- Network path
- Whether the source is expected
5. Determine whether the behavior is legitimate
For example, a deployment may legitimately cause a temporary increase in Key Vault operations.
6. Investigate related activity
Look for related activity involving:
- Microsoft Entra ID
- Azure resources
- Other Key Vaults
- Applications
- Service principals
- Other security alerts
7. Respond appropriately
Depending on the investigation, response actions could include:
- Disabling or restricting a compromised identity
- Revoking credentials
- Rotating secrets
- Reviewing RBAC assignments
- Restricting network access
- Removing unauthorized permissions
- Investigating other affected resources
Defender for Key Vault and Microsoft Sentinel
Defender for Cloud security alerts can be integrated with broader security operations workflows.
Microsoft Sentinel can be used to provide centralized SIEM/SOAR capabilities.
This allows organizations to correlate Key Vault security alerts with other security data.
For example:
Defender for Key Vault alert
↓
Microsoft Sentinel
↓
Correlate with Entra ID sign-in activity
↓
Investigate compromised identity
↓
Automate response if appropriate
This is especially useful in environments where Key Vault activity needs to be correlated with identity, endpoint, application, and network events.
Defender for Key Vault and Key Vault Diagnostic Logging
These capabilities serve different purposes.
Key Vault diagnostic logging
Provides information about operations occurring within Key Vault.
It is primarily useful for:
- Auditing
- Troubleshooting
- Investigation
- Operational monitoring
Defender for Key Vault
Provides specialized threat detection for suspicious access patterns.
It is primarily useful for:
- Threat detection
- Security alerts
- Behavioral analysis
- Identifying potentially malicious activity
The two should generally be considered complementary.
Defender for Key Vault vs. Defender CSPM
This is an important distinction for the exam.
Defender for Key Vault focuses on protecting Key Vault through threat detection of suspicious access and activity.
Defender CSPM focuses primarily on improving security posture, identifying risks, and providing security recommendations and related posture-management capabilities.
For example:
| Requirement | Appropriate capability |
|---|---|
| Detect suspicious Key Vault access | Defender for Key Vault |
| Detect anomalous secret access patterns | Defender for Key Vault |
| Identify security misconfigurations | Defender CSPM / Defender for Cloud posture capabilities |
| Improve overall cloud security posture | Defender CSPM |
| Generate Key Vault threat alerts | Defender for Key Vault |
A scenario asking you to detect malicious or anomalous Key Vault access should immediately make you think of Defender for Key Vault.
Defender for Key Vault vs. Azure Policy
Azure Policy and Defender for Key Vault solve very different problems.
Azure Policy
Used to enforce or audit configuration requirements.
For example:
Require Defender for Key Vault to be enabled.
A built-in Azure Policy definition can audit whether Defender for Key Vault is enabled.
Defender for Key Vault
Actually provides the workload threat-detection capability for Key Vault.
Therefore:
Azure Policy → governance
Defender for Key Vault → threat protection
An organization can use both.
A Typical Defense-in-Depth Architecture
A secure Key Vault environment might look like this:
Microsoft Entra ID
↓
Authentication
Azure RBAC
↓
Authorization
Key Vault firewall / network rules
↓
Network restriction
Private Endpoint
↓
Private connectivity
Key Vault diagnostic logging
↓
Audit and visibility
Microsoft Defender for Key Vault
↓
Threat detection
Microsoft Sentinel
↓
Centralized investigation and automated response
This layered approach is consistent with the defense-in-depth philosophy emphasized throughout the SC-500 exam.
Key Exam Concepts to Remember
The following points are particularly important for SC-500.
Remember #1: Defender for Key Vault is part of Defender for Cloud
You enable it through the Defender for Cloud → Environment settings → Defender plans experience.
Remember #2: It detects suspicious activity
Its primary purpose is threat detection, not authorization.
Remember #3: It can detect anomalous behavior
Examples include:
- Unusual users
- Unusual applications
- Unusual user/application combinations
- Unusual operation patterns
- High operation volume
- Access from suspicious IP addresses
- TOR-based access
- Suspicious secret listing and retrieval
- Suspicious permission changes followed by secret retrieval
Remember #4: A successful login can still be suspicious
An identity can be valid and authorized while its behavior is anomalous.
Remember #5: It does not replace RBAC
RBAC determines what an identity is allowed to do.
Defender determines whether activity appears suspicious.
Remember #6: Logging and Defender are complementary
Logging provides activity records.
Defender provides specialized threat detection and security alerts.
Remember #7: Defender alerts require investigation
An anomaly is a security signal, not automatically proof of compromise.
Remember #8: Think behaviorally
Many Defender for Key Vault detections are based on patterns and anomalies, rather than a single isolated event.
Practice Exam Questions
Question 1
An organization stores database credentials and API keys in Azure Key Vault. The security team wants to detect when a service principal begins accessing the vault in an unusual manner compared with its historical behavior.
Which solution should you implement?
A. Azure Resource Locks
B. Microsoft Defender for Key Vault
C. Azure Firewall
D. Azure Policy
Answer: B
Explanation
Microsoft Defender for Key Vault is designed to detect unusual and potentially harmful access patterns involving Key Vault. It can identify anomalous behavior involving users, service principals, applications, operation patterns, and access locations.
Azure Resource Locks protect resources from accidental deletion or modification. Azure Firewall provides network traffic filtering, while Azure Policy provides governance and compliance enforcement. None is specifically designed to perform behavioral threat detection for Key Vault.
Question 2
A security engineer wants to detect a situation in which an attacker changes Key Vault permissions and then retrieves secrets that the attacker previously could not access.
Which Defender for Key Vault capability is most relevant?
A. Detection of excessive Key Vault latency
B. Detection of suspicious policy changes followed by secret retrieval
C. Detection of expired certificates
D. Detection of Key Vault resource deletion
Answer: B
Explanation
Defender for Key Vault can detect anomalous patterns in which a user or service principal performs a suspicious vault policy change followed by Secret Get operations.
This pattern can indicate that an attacker modified permissions to gain access to previously inaccessible secrets.
The other choices do not describe this Defender for Key Vault detection scenario.
Question 3
An organization has enabled Microsoft Defender for Cloud and wants to enable threat protection specifically for Azure Key Vault.
Where should the security engineer configure the protection?
A. Azure Key Vault → Networking → Firewalls
B. Azure Key Vault → Access configuration → RBAC
C. Microsoft Defender for Cloud → Environment settings → Defender plans → Key Vault
D. Microsoft Entra admin center → Authentication methods
Answer: C
Explanation
Defender for Key Vault is enabled as a Defender for Cloud workload protection plan.
The administrator selects the appropriate subscription under Microsoft Defender for Cloud → Environment settings, enables the Key Vault plan, and saves the configuration.
The other options configure different security capabilities.
Question 4
A user who has never previously accessed a production Key Vault suddenly accesses it from a location that is unusual for that user. The user has valid permissions.
What is the primary security capability that can identify this type of behavior?
A. Azure Resource Manager locks
B. Azure Private Link
C. Microsoft Defender for Key Vault
D. Azure Policy
Answer: C
Explanation
Defender for Key Vault can identify unusual user access patterns, including situations where a user who does not normally access a Key Vault suddenly accesses one.
The fact that the user has valid permissions does not necessarily mean the activity is safe. Defender for Key Vault is specifically designed to detect potentially suspicious behavior even when the activity involves an otherwise valid identity.
Question 5
A service principal normally accesses one Key Vault. An attacker compromises the service principal and begins enumerating many Key Vaults in the organization.
Which Defender for Key Vault detection is most relevant?
A. User or service principal accessing an anomalously high volume of Key Vaults
B. Key Vault certificate expiration
C. Key Vault resource lock modification
D. Azure VM disk encryption failure
Answer: A
Explanation
Defender for Key Vault can detect anomalously high-volume access to Key Vaults by users or service principals.
This type of behavior can indicate that an attacker is attempting to discover additional vaults and credentials after compromising an identity.
The other choices are unrelated to this Key Vault threat-detection scenario.
Question 6
An organization wants to ensure that every Azure subscription has Microsoft Defender for Key Vault enabled. The organization wants noncompliant subscriptions to be identified automatically.
Which service is best suited for enforcing or auditing this configuration requirement?
A. Microsoft Sentinel
B. Azure Policy
C. Microsoft Defender for Key Vault
D. Azure Bastion
Answer: B
Explanation
Azure Policy can audit or enforce organizational configuration requirements. There is a built-in policy definition for auditing whether Defender for Key Vault is enabled.
The important distinction is:
Azure Policy → governance and compliance
Defender for Key Vault → threat detection
Microsoft Sentinel is primarily a SIEM/SOAR platform, while Azure Bastion provides secure administrative access to virtual machines.
Question 7
A security analyst receives a Defender for Key Vault alert indicating that a vault was accessed from a known TOR exit node.
What does this alert primarily indicate?
A. The Key Vault certificate has expired
B. The Key Vault has reached its transaction limit
C. The vault was accessed through a network associated with TOR
D. The Key Vault was automatically deleted
Answer: C
Explanation
Defender for Key Vault can generate alerts when a Key Vault is accessed from a known TOR exit node.
TOR can be used to obscure the source of network traffic, so access from a TOR exit node can represent a potential threat indicator.
The alert does not itself prove that the account was compromised, but it should be investigated.
Question 8
A security engineer is explaining the difference between Azure Key Vault diagnostic logging and Microsoft Defender for Key Vault to a new administrator.
Which statement is correct?
A. Diagnostic logging provides activity information, while Defender for Key Vault provides specialized threat detection
B. Diagnostic logging replaces the need for Defender for Key Vault
C. Defender for Key Vault is responsible for assigning RBAC permissions
D. Defender for Key Vault replaces Key Vault network controls
Answer: A
Explanation
Key Vault diagnostic logging provides information about operations performed against the vault and supports auditing and investigation.
Defender for Key Vault adds specialized threat-detection capabilities designed to identify unusual and potentially malicious access patterns.
These capabilities are complementary.
Defender for Key Vault does not assign RBAC permissions or replace network controls.
Question 9
A security team wants to investigate whether a suspicious Key Vault access event is related to other identity and security events across the organization.
Which service would provide the strongest centralized SIEM/SOAR capability for correlating these events?
A. Azure Resource Manager
B. Azure Key Vault
C. Microsoft Sentinel
D. Azure Policy
Answer: C
Explanation
Microsoft Sentinel provides SIEM/SOAR capabilities that can be used to collect, correlate, investigate, and respond to security events from multiple sources.
For example, a Defender for Key Vault alert could be correlated with Microsoft Entra sign-in activity and other security signals to determine whether an identity may have been compromised.
Azure Key Vault is the protected service, Azure Resource Manager manages Azure resources, and Azure Policy provides governance.
Question 10
A developer reports that a Key Vault application is generating thousands of operations in a short period. The application normally performs only a small number of operations each day.
Which Defender for Key Vault capability could identify this behavior?
A. Detection of expired Key Vault certificates
B. Detection of anomalous Key Vault operation volume
C. Detection of Azure VM configuration drift
D. Detection of missing resource locks
Answer: B
Explanation
Defender for Key Vault can detect anomalous operation volumes involving users, service principals, and Key Vaults.
An unusually high volume of operations could be legitimate—for example, because of a deployment or application change—but it can also indicate credential compromise, automated secret discovery, or another attack.
The alert should therefore be investigated rather than automatically treated as proof of malicious activity.
SC-500 Exam Quick Reference
| Concept | What to remember |
|---|---|
| Defender for Key Vault | Threat protection for Azure Key Vault |
| Where enabled? | Microsoft Defender for Cloud |
| Configuration level | Defender for Cloud environment/subscription |
| Primary purpose | Detect suspicious and anomalous Key Vault activity |
| Detects suspicious IP access? | Yes |
| Detects TOR access? | Yes |
| Detects unusual users? | Yes |
| Detects unusual applications/service principals? | Yes |
| Detects anomalous operation volume? | Yes |
| Detects suspicious secret listing/retrieval patterns? | Yes |
| Detects suspicious permission change + secret retrieval? | Yes |
| Replaces Azure RBAC? | No |
| Replaces Key Vault firewall? | No |
| Replaces diagnostic logging? | No |
| Provides threat alerts? | Yes |
| Can work with broader security operations workflows? | Yes |
| Azure Policy’s role | Governance/auditing of configuration |
| Microsoft Sentinel’s role | SIEM/SOAR, correlation, investigation, response |
The Big Exam Takeaway
When an SC-500 question describes unusual, anomalous, or potentially malicious access to Azure Key Vault, think:
Microsoft Defender for Key Vault
When the question instead asks you to control who can access Key Vault, think:
Microsoft Entra ID + Azure RBAC/Key Vault permissions
When it asks you to restrict where Key Vault can be accessed from, think:
Network rules, firewall settings, and/or Private Endpoint
When it asks you to record and audit Key Vault operations, think:
Diagnostic logging
When it asks you to enforce organizational configuration requirements, think:
Azure Policy
And when it asks you to correlate Key Vault security events with identity, endpoint, and other security signals, think:
Microsoft Sentinel
That distinction between preventive controls, governance controls, logging, and threat detection is one of the most important concepts to retain for this SC-500 topic.
Go to the SC-500 Exam Prep Hub main page
