Cosmos DB keys don't expire on their own
A leaked Cosmos DB master key grants full read and write access to every database in that account, with zero identity-based control attached to it: no Conditional Access, no MFA, no audit trail tied to a real person. Disabling local (key-based) authentication is a single setting, but until someone deliberately flips it, those keys keep working exactly as well as they always have, whether they're rotated regularly or sitting untouched in a forgotten .env file or an old CI/CD pipeline. ID Posture checks whether that door has actually been closed, on every scan.
One finding, checked on every scan
Ask your ID Posture contact to enable Cosmos DB Security for your tenant.
Why it matters
Cosmos DB's disableLocalAuth setting is a single switch, but until someone flips it, primary and secondary account keys work exactly as well as Entra ID does, no Conditional Access, no MFA, no audit trail tied to a real identity. A key in a forgotten .env file or an old CI/CD pipeline is a permanent, silent risk until this is disabled. ID Posture checks it on every scan.
Part of ID Posture’s broader Azure resource coverage. See the full product overview, or explore Redis Security and Networking.
It's optional, per tenant, and off by default until you ask for it.