Remediation
From Azure Portalβ
- Go to
Key vaults
. - For each Key vault, click on
Keys
. - In the main pane, ensure that an appropriate
Expiration date
is set for any keys that areEnabled
.
From Azure CLIβ
Update the Expiration date
for the key using the below command:
az keyvault key set-attributes --name <keyName> --vault-name <vaultName> --expires Y-m-d'T'H:M:S'Z'
Note: To view the expiration date on all keys in a Key Vault using Microsoft API, the List Key
permission is required.
To update the expiration date for the keys:
- Go to the Key vault, click on Access Control (IAM).
- Click on Add role assignment and assign the role of Key Vault Crypto Officer to the appropriate user.
From PowerShellβ
Set-AzKeyVaultKeyAttribute -VaultName <VaultName> -Name <KeyName> -Expires <DateTime>