Remediation
From Azure Portalβ
- Go to
Key Vaults. - For each Key Vault, select
Keys. - In the main pane, ensure that an appropriate
Expiration dateis set for any keys that areEnabled.
From Azure CLIβ
Update the Expiration date for the key using the following command. Use a UTC timestamp in ISO 8601 format.
az keyvault key set-attributes \
--name {{key-name}} \
--vault-name {{vault-name}} \
--expires {{expiration-date-time-utc}}
Note: To view the expiration date on all keys in a Key Vault using Microsoft API, the List Key permission is required.
To update the expiration date for the keys:
- Go to the Key Vault and select
Access Control (IAM). - Select
Add role assignmentand assign theKey Vault Crypto Officerrole to the appropriate user.
From PowerShellβ
Set-AzKeyVaultKeyAttribute `
-VaultName {{vault-name}} `
-Name {{key-name}} `
-Expires {{date-time}}