Detecting Cosmos DB Key Misuse With Defender for Cloud and Sentinel
Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.
Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.
Signals worth watching
- Data plane requests from IP addresses outside your applications' known ranges.
- Large or unusual query volumes, especially reads across many containers.
- Key regeneration or key listing operations by unexpected identities.
- Requests authenticated with keys after you've moved applications to Entra ID.
- Defender for Azure Cosmos DB alerts (for example, access from suspicious IPs, potential SQL injection, unusual data extraction).
Where the data lives
- Cosmos DB diagnostic logs (DataPlaneRequests, QueryRuntimeStatistics) sent to Log Analytics.
- Azure Activity logs for control plane operations such as
listKeysandregenerateKey. - Defender for Cloud alerts.
A starting query
Who listed keys for Cosmos DB accounts:
AzureActivity
| where OperationNameValue has "MICROSOFT.DOCUMENTDB/DATABASEACCOUNTS/LISTKEYS"
| project TimeGenerated, Caller, CallerIpAddress, ResourceGroup, _ResourceId, ActivityStatusValue
Listing keys is required for some deployments, but should come from known automation identities.
Response
- Regenerate affected keys immediately.
- Review data plane logs for the period of exposure.
- Restrict network access and move to Entra ID authentication.
- ChaosDB (Aug 2021): A Cosmos DB Flaw Exposed Thousands of Azure Customers' Keys Incident Teardowns
- How to Rotate Cosmos DB Keys and Move to Entra ID Authentication How-To & Hardening
- CIO Brief: When the Cloud Provider's Own Service Is Vulnerable CIO Briefings