
Key Vault Contributor Privilege Escalation: Reading All Secrets via Access Policies
A holder of the built-in Key Vault Contributor role abuses its Microsoft.KeyVault/vaults/write permission to write itself a full data-plane access policy on a production Azure Key Vault, then dumps every secret, key, and certificate it holds. Working purely from the cloud audit trail, correlate the control-plane access-policy change in the Azure Activity Log with the data-plane secret, key, and certificate reads in the Key Vault diagnostic log, identify the principal and what it stole, and classify the privilege-escalation and credential-access techniques.
Launches in 5 days
Tuesday, September 29, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
What you'll investigate
8 objectives unlock when this operation goes live.
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Sep 29, 2026, you can jump straight in.
Get Started Free