Schedule demo

Microsoft Azure Key Vaults/Key Vault Managed HSM


Microsoft Azure Key Vaults/Key Vault Managed HSM - An Overview

Azure Key Vaults and Azure Key Vault Managed HSM (Hardware Security Module) are two essential services provided by Microsoft Azure for managing secrets, keys, and certificates. The Azure Key Vaults service is used for securely storing and managing sensitive information such as API keys, passwords, certificates, and cryptographic keys. Azure Key Vault Managed HSM provides a highly secure environment for storing and managing cryptographic keys using hardware security modules (HSMs). 

With the right Azure Key Vaults monitoring tool / Azure Key Vault Managed HSM monitoring tool, users can effectively monitor the performance, availability, and security of their service and gain actionable insights to optimize its usage, detect anomalies, and respond to security incidents promptly. Read on to learn how to do so with Applications Manager.

Creating a new Microsoft Azure Key Vaults/Azure Key Vault Managed HSM Monitor

To learn how to create a new Microsoft Azure Key Vaults/Azure Key Vault Managed HSM monitor, click here.

Monitored Parameters

Navigate to the Category View by clicking the Monitors tab. Hover over 'Child Monitors' under Microsoft Azure in the Cloud Apps table, and then select the Key Vaults (or) Key Vault Managed HSMs monitor from the displayed tooltip. This action will display the bulk configuration view for Azure Key Vaults/Azure Key Vault Managed HSM in three tabs:

  • Availability tab gives the Availability history for the past 24 hours or 30 days.
  • Performance tab gives the Health Status and events for the past 24 hours or 30 days.
  • List view enables you to perform bulk admin configurations.

The Microsoft Azure monitor provides a brief detail of the Azure Key Vaults/Azure Key Vault Managed HSM under the given subscription. Following are the list of metrics monitored in Azure Key Vaults Monitoring/Azure Key Vault Managed HSM Monitoring in their corresponding tabs:

Performance Overview

ParameterDescription
Monitor Type
Key Vaults
Key Vault Managed HSM
VAULT AVAILABILITY
Vault AvailabilityThe average availability of the vault requests between the poll interval (in %).
VAULT SATURATION
Vault SaturationThe average vault capacity used between the poll interval (in %).
SERVICE AVAILABILITY
Service AvailabilityThe average availability of the service requests between the poll interval (in %).
API LATENCY
API LatencyThe average overall latency of service API requests between the poll interval (in seconds).
API HITS
Rate of API HitsThe number of total service API hits per minute, between the poll interval (in requests/min).
Total API HitsThe number of total service API hits between the poll interval.
API RESULTS
API ResultsThe number of total service API results between the poll interval (in MB).

Configuration

Note: The metrics under RESOURCE ACCESS CONFIGURATION are only supported for the Azure Key Vaults monitor.

Parameter Description
CONFIGURATION
Resource Group NameThe name of the resource group.
LocationThe location of the resource.
Provisioning StateThe current provisioning state of the resource. Possible values: RegisteringDns, Succeeded.
SKU TierThe SKU name to specify the type of vault. Possible Values:
  • For Key Vaults: Standard/Premium
  • For Key Vault Managed HSM: Custom_B32/Custom_B6/Standard_B1
SKU FamilyThe SKU Family name.
Vault URl/HSM URlThe URl of the vault/HSM used to perform operations on keys and secrets.
Creation TimeThe timestamp of the key vault resource creation.
Creator Identity TypeThe identity type used to create the key vault resource.
Last Modified TimeThe timestamp of the key vault resource last modification.
Last Modifier Identity TypeThe type of identity that last modified the key vault resource.
ADVANCED SETTINGS
Soft DeleteProperty to specify whether the 'Soft Delete' functionality is enabled for this key vault. Possible values: Enabled/Disabled.
Soft Delete Retention DaysThe total number of Soft Delete data retention days. The possible value will be >=7 & <=90.
Purge ProtectionProperty specifying whether protection against purge is enabled for this vault. This setting is effective only if soft delete is also enabled. Possible values: Enabled/Disabled.
Public Network AccessProperty to specify whether the vault will accept traffic from the public internet. Possible values: Enabled/Disabled.
RESOURCE ACCESS CONFIGURATION 
RBAC AuthorizationProperty that controls how data actions are authorized. Possible values: Enabled/Disabled.
Virtual Machine for DeploymentProperty to specify whether the Azure Virtual Machines are permitted to retrieve certificates stored as secrets from the key vault. Possible values: Enabled/Disabled.
Resource Manager for Template DeploymentProperty to specify whether the Azure Resource Manager is permitted to retrieve secrets from the key vault. Possible values: Enabled/Disabled.
Disk Encryption for Volume EncryptionProperty to specify whether the Azure Disk Encryption is permitted to retrieve secrets from the vault and unwrap keys. Possible values: Enabled/Disabled.

Loved by customers all over the world

"Standout Tool With Extensive Monitoring Capabilities"

It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.

Reviewer Role: Research and Development

carlos-rivero
"I like Applications Manager because it helps us to detect issues present in our servers and SQL databases."
Carlos Rivero

Tech Support Manager, Lexmark

Trusted by over 6000+ businesses globally