More Info:

In Microsoft Azure Key Vault, check for any keys that does not have any expiration time set.

Risk Level

Medium

Address

Security, Operational Maturity

Compliance Standards

GDPR, ISO27001, CISAZURE, CBP, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration of keys not having an expiration time in Azure, you can follow the below steps:

  1. Log in to the Azure portal using your credentials.
  2. Navigate to the Azure Key Vault service.
  3. Select the Key Vault that contains the key that needs to be remediated.
  4. Click on the “Keys” option from the left-hand menu.
  5. Select the key that needs to be remediated.
  6. Click on the “Settings” option from the top menu.
  7. In the “Settings” menu, select the “Lifetime” option.
  8. Set an expiration time for the key by selecting a duration from the dropdown menu or by specifying a custom duration.
  9. Click on the “Save” button to apply the changes.

By following these steps, you can remediate the misconfiguration of keys not having an expiration time in Azure using the Azure console.

Additional Reading: