How can I view who has viewed the Storage Account keys?

EnterpriseArchitect 5,691 Reputation points
2025-02-27T01:15:30.3566667+00:00

How can I view the logs for who has viewed the Storage Account keys in my Azure Storage Account?

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,393 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sathvika Reddy Dopathi 90 Reputation points Microsoft Vendor
    2025-02-27T04:50:20.2933333+00:00

    Hi @EnterpriseArchitect,

    Please be informed that Azure Storage does not offer native logging or auditing features specifically designed to track the individuals who has viewed the Storage Account keys. However, you have the option to activate Azure Storage logging and Azure Monitor logs to record activities and access related to your Azure Storage Account. This functionality can assist you in monitoring and auditing the actions performed within the storage account.

    1. Enable Azure Storage Logging:
      • Enable logging for your Azure Storage Account to capture data access logs, which include information about requests made against the storage account. You can log data operations such as reads, writes, and deletes.
      • You can configure logging settings in the Azure portal under the "Monitoring" section of your storage account.
    2. Enable Azure Monitor Logs:
      • Azure Monitor logs provide a centralized platform for collecting, analyzing, and acting on telemetry data from your Azure resources. You can use Azure Monitor logs to collect and analyze logs from Azure Storage Account activities.
      • Configure diagnostic settings to send logs to Azure Monitor logs for storage account activities. You can define which logs to collect and where to store them.
    3. Set up Alerts and Monitoring:
      • Use Azure Monitor to set up alerts based on specific criteria, such as key access events or unusual activity in your storage account. This can help you proactively monitor and respond to security-related events.
      • Create custom queries in Azure Monitor logs to search for specific events related to key access or other sensitive operations.

    By enabling Azure Storage logging and Azure Monitor logs, you can gain visibility into activities within your Azure Storage Account and monitor access to keys and other sensitive information. While you may not have direct logs for who has viewed the Storage Account keys, these logging and monitoring capabilities can help you track and audit access to your storage account.

    References:

    https://learn.microsoft.com/en-us/azure/storage/common/manage-storage-analytics-logs?tabs=azure-portal

    https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/create-diagnostic-settings?tabs=portal

    Please let us know if you have any further queries. I’m happy to assist you further.

    Please consider to “up-vote” and "accept the answer" wherever the information provided helps you, this can be beneficial to other community members.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.