More Info:

Ensure that a Microsoft Azure activity log alert is fired whenever Delete Key Vault event is triggered inside your Microsoft Azure cloud account.

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

Sure, here are the step by step instructions to remediate the misconfiguration “Setup Alerts for Delete Key Vault Events” for Azure using the Azure console:

  1. Log in to the Azure portal (portal.azure.com) using your credentials.
  2. Navigate to the Key Vaults service in the Azure portal.
  3. Select the Key Vault for which you want to set up the alerts.
  4. In the Key Vault menu, select “Monitoring” under the “Settings” section.
  5. Click on “Alerts” and then click on “New alert rule”.
  6. In the “Create rule” page, select “Key Vault” as the resource type and then select the specific Key Vault for which you want to set up the alerts.
  7. Select the “Delete” event type under the “Event type” section.
  8. Set the appropriate threshold and frequency for the alert rule.
  9. In the “Actions” section, click on “Add action group” to create a new action group.
  10. In the “Create action group” page, enter the required details such as the name of the action group, the email address or phone number to receive the alerts, and the severity level of the alerts.
  11. Click on “Create” to create the action group, and then click on “OK” to close the “Create rule” page.
  12. Your alert rule is now set up, and you will receive an alert whenever a delete event occurs in the specified Key Vault.

That’s it! You have successfully set up alerts for delete Key Vault events in Azure using the Azure console.

Additional Reading: