Information
Ensure that all Secrets in Azure Key Vaults with access policies have an expiration date set.
Note: Using access policies is a legacy method.For improved security, use the Role-Based Access Control (RBAC) permission model instead of access policies when managing Azure Key Vault. RBAC restricts permission management to only the Owner and User Access Administrator roles, ensuring a clear separation between security and administrative tasks.With the Access Policy permission model, users with the Contributor, Key Vault Contributor, or any role that includes Microsoft.KeyVault/vaults/write permissions can grant themselves data plane access by configuring a Key Vault access policy. This can result in unauthorized access and management of your key vaults, keys, secrets, and certificates. To reduce this risk, limit Contributor role access to key vaults when using the Access Policy model.
The Azure Key Vault enables users to store and keep secrets within the Microsoft Azure environment. Secrets in the Azure Key Vault are octet sequences with a maximum size of 25k bytes each. The exp (expiration date) attribute identifies the expiration date on or after which the secret MUST NOT be used. By default, secrets never expire. It is thus recommended to rotate secrets in the key vault and set an explicit expiration date for all secrets. This ensures that the secrets cannot be used beyond their assigned lifetimes.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Requisite Access Policy Permissions for Secrets - read section overview!
Remediation Permissions = Secrets: List, Get, Set
Remediate from Azure Portal
- Go to Key vaults.
- For each Key vault, click on Secrets.
- In the main pane, ensure that the status of the secret(s) is Enabled.
- Click on the secret(s) without Expiration date.
- Click on the current version secret
- Click the checkbox Set expiration date and set an appropriate Expiration date on the secret.
- Click Apply.
Remediate from Azure CLI
Update the Expiration date for the secret using the below command:
az keyvault secret set-attributes --name <secret_name> --vault-name <vault_name> --expires Y-m-d'T'H:M:S'Z'
Remediate from PowerShell
For each Key vault with the EnableRbacAuthorization setting set to False or empty, run the following command.
Set-AzKeyVaultSecret -VaultName <vault_name> -Name <secret_name> -Expires <date_time>
Impact:
Secrets cannot be used beyond their assigned expiry date respectively. Secrets need to be rotated periodically wherever they are used.