Key vaults with zero API hits in 30 days that may be safe to retire
What does ZopNight detect here?
Azure Key Vault records every request in the `ServiceApiHit` metric. ZopNight flags a vault whose `ServiceApiHit` average and maximum are both zero across the trailing 30 days, as long as the vault is older than 30 days. Standard vaults bill per operation, so the finding is mainly hygiene and may carry a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1370 |
| Category | orphan |
| Severity | low |
| Metric | ServiceApiHit |
| Threshold | zero API hits |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.KeyVault/vaults/read · Microsoft.Insights/Metrics/Read |
Where it applies
What an unused vault costs, and what it risks
Key Vault pricing is built from operations: standard vaults are charged per 10,000 transactions for secrets and key operations, with certificate renewals and HSM-protected keys (charged per key per month) on top. A vault that receives no requests therefore often costs little or nothing in its own right.
The reason to act is the contents. A forgotten vault still holds secrets, keys and certificates that someone once trusted, with access policies or role assignments that nobody reviews. Every unused vault is a place where a stale credential can outlive its purpose.
Counting requests against a vault
List the vaults, then check a month of request totals for each one:
az keyvault list --query "[].{name:name, group:resourceGroup}" -o table
az monitor metrics list \ --resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.KeyVault/vaults/<vault> \ --metric ServiceApiHit --aggregation Total --interval PT24H --offset 30dEvery daily total at zero means no application, pipeline or person read or wrote anything in the vault for the month.
The single signal this rule trusts
Azure Monitor’s ServiceApiHit metric is the only input. For the vault to be flagged, the metric
must be present and both its average and its maximum must be zero over the trailing 30 days. Tags
are never used as a substitute.
Missing data and young vaults
If ZopNight has metrics for other resources but none for this vault, that gap suppresses the finding, and if no metrics are available at all, nothing fires. A vault created less than 30 days ago is skipped, because a vault that was just provisioned has not had a chance to be used yet. When the creation time is unknown, the vault is still evaluated, so a genuinely stale vault with a missing timestamp is not hidden.
Why the saving is often $0
saving = the vault's priced monthly cost, which is usually $0 for an idle standard vaultThis rule reports the idle state regardless of the dollar figure. Treat it as a security and hygiene cleanup rather than a cost win.
Retiring a vault safely
- Check the vault’s activity log and access configuration to find who owned it and what used to read from it.
- Search app settings, pipelines and infrastructure code for the vault’s URI before deleting.
- Delete it:
az keyvault delete --name <vault> --resource-group <rg>. - Deleted vaults stay recoverable for the soft-delete retention period. Use
az keyvault list-deletedto see them andaz keyvault purge --name <vault>only once you are sure.