Skip to main content
orphan · azure

Key vaults with zero API hits in 30 days that may be safe to retire

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Azure Key Vault records every request in the `ServiceApiHit` metric. ZopNight flags a vault whose `ServiceApiHit` average and maximum are both zero across the trailing 30 days, as long as the vault is older than 30 days. Standard vaults bill per operation, so the finding is mainly hygiene and may carry a $0 saving.

Signal and threshold

How ZopNight evaluates Key vaults with zero API hits in 30 days that may be safe to retire.
Field Value
Rule IDsRC-1370
Categoryorphan
Severitylow
MetricServiceApiHit
Thresholdzero API hits
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.KeyVault/vaults/read · Microsoft.Insights/Metrics/Read

What an unused vault costs, and what it risks

Key Vault pricing is built from operations: standard vaults are charged per 10,000 transactions for secrets and key operations, with certificate renewals and HSM-protected keys (charged per key per month) on top. A vault that receives no requests therefore often costs little or nothing in its own right.

The reason to act is the contents. A forgotten vault still holds secrets, keys and certificates that someone once trusted, with access policies or role assignments that nobody reviews. Every unused vault is a place where a stale credential can outlive its purpose.

Counting requests against a vault

List the vaults, then check a month of request totals for each one:

Terminal window
az keyvault list --query "[].{name:name, group:resourceGroup}" -o table
az monitor metrics list \
--resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.KeyVault/vaults/<vault> \
--metric ServiceApiHit --aggregation Total --interval PT24H --offset 30d

Every daily total at zero means no application, pipeline or person read or wrote anything in the vault for the month.

The single signal this rule trusts

Azure Monitor’s ServiceApiHit metric is the only input. For the vault to be flagged, the metric must be present and both its average and its maximum must be zero over the trailing 30 days. Tags are never used as a substitute.

Missing data and young vaults

If ZopNight has metrics for other resources but none for this vault, that gap suppresses the finding, and if no metrics are available at all, nothing fires. A vault created less than 30 days ago is skipped, because a vault that was just provisioned has not had a chance to be used yet. When the creation time is unknown, the vault is still evaluated, so a genuinely stale vault with a missing timestamp is not hidden.

Why the saving is often $0

Terminal window
saving = the vault's priced monthly cost, which is usually $0 for an idle standard vault

This rule reports the idle state regardless of the dollar figure. Treat it as a security and hygiene cleanup rather than a cost win.

Retiring a vault safely

  1. Check the vault’s activity log and access configuration to find who owned it and what used to read from it.
  2. Search app settings, pipelines and infrastructure code for the vault’s URI before deleting.
  3. Delete it: az keyvault delete --name <vault> --resource-group <rg>.
  4. Deleted vaults stay recoverable for the soft-delete retention period. Use az keyvault list-deleted to see them and az keyvault purge --name <vault> only once you are sure.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·