Azure Key Vault

Discover secrets from Azure Key Vault. Populates the secrets inventory with names, enabled state, and expiry-based rotation metadata. Secret values are never read.

Source connector

Source connector — pulls identity and access data from Azure Key Vault into ComplianceScout where it is scored against your compliance frameworks and violation rules.

What ComplianceScout collects

After a successful sync, the following data is available in your ComplianceScout dashboard for violation detection and reporting.

  • All secret names and their enabled/disabled state (values never read)
  • Secret expiry dates and days until expiration
  • Creation and last-updated timestamps
  • Content type metadata if set
  • Key Vault access policies and RBAC assignments

Required credentials

These fields are collected when you add the connector in the ComplianceScout dashboard. Secrets are encrypted at rest using AES-256-GCM and are never logged.

FieldTypeRequiredNotes
Vault URLURLRequirede.g. https://acme.vault.azure.net
Tenant IDTextRequiredAzure AD tenant ID (GUID).
Client IDTextRequiredApplication (client) ID of the service principal.
Client secretSecretRequiredClient secret of the service principal. The SP must have the Key Vault Secrets User role on the vault.

How to set up this connector

Follow these steps to gather the credentials above and connect Azure Key Vault to ComplianceScout.

  1. In the Azure Portal, go to Microsoft Entra ID → App registrations → New registration. Name it "ComplianceScout".

  2. Go to Certificates & secrets → New client secret, set an expiry, and copy the value.

  3. Copy the Application (client) ID and Directory (tenant) ID from the Overview page.

  4. Navigate to your Key Vault → Access control (IAM) → Add role assignment. Assign the "Key Vault Secrets User" role to the app registration.

  5. In ComplianceScout, go to Data & Secrets → Integrations → Add Connector → Azure Key Vault, enter the Vault URL and credentials, then click Test and Save.

Ready to connect Azure Key Vault?

Start a free trial — your tenant is provisioned instantly and you can wire up this integration from the connectors page.