More Info:

In Microsoft Azure Key Vault, check for any secrets that does not have any expiration time set.

Risk Level

Medium

Address

Security

Compliance Standards

GDPR, ISO27001, CISAZURE, CBP, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration of secrets not having an expiration time in AZURE, you can follow the below steps:

  1. Login to the AZURE portal using your credentials.
  2. Navigate to the “Key vaults” service from the dashboard.
  3. Select the key vault that contains the secrets that you want to remediate.
  4. Click on the “Secrets” option from the left-hand side menu.
  5. Select the secret that you want to remediate and click on it.
  6. In the secret details page, scroll down to the “Validity period” section.
  7. Click on the “Enable” button to enable the expiration time for the secret.
  8. Set the expiration time as per your requirement using the “Expires” field.
  9. Click on the “Save” button to save the changes.

By following the above steps, you can remediate the misconfiguration of secrets not having an expiration time in AZURE.

Additional Reading: