logo

Database

Azure Purge Prevention Disabled

Description

Identifies Azure Key Vaults that have purge protection disabled. When purge protection is not enabled, deleted key vaults and their contents can be permanently erased, increasing the risk of data loss through accidental deletion or malicious actions.

Weakness:

101 - Lack of protection against deletion

Category: Functionality Abuse

Detection Strategy

    Scans all Azure Key Vaults in the subscription

    Checks if the 'enable_purge_protection' property is disabled or not set

    Reports a vulnerability if purge protection is not enabled for a key vault