Your secrets are only as safe as the vault holding them
Soft-delete, purge protection, the permission model, and public network access, ID Posture checks the configuration of the vault itself, not just what's stored inside it. A vault without soft-delete makes an accidental or malicious deletion unrecoverable; one without purge protection can still be permanently destroyed by anyone with delete rights during its own recovery window. Legacy vault access policies are all-or-nothing per vault, with none of Azure RBAC's Conditional Access or PIM integration. ID Posture checks all of this, plus a plain inventory of retention settings and network exposure, on every scan.
Five findings, checked on every scan
Ask your ID Posture contact to enable Key Vault for your tenant.
Why it matters
Without soft-delete, an accidental or malicious deletion of a vault, or a single secret inside it, is unrecoverable. Without purge protection, anyone with delete rights can still permanently destroy a vault during its own soft-delete retention window. Legacy vault access policies are all-or-nothing per vault, with no Conditional Access or PIM integration the way Azure RBAC has. And a vault reachable from any IP address on the internet is relying entirely on its permission model as the only control left. ID Posture checks all five states on every scan, plus a plain inventory of retention days, resource-access settings, and private endpoint connections.
Part of ID Posture’s broader Azure resource coverage. See the full product overview, or explore Storage Security and AKS Security.
It's optional, per tenant, and off by default until you ask for it.