How to Inventory and Rotate API Keys for Remote Support Tools
Retrospective: this article looks back at events from December 2024, written in 2026 with the benefit of hindsight.
API keys for remote support and management tools can provide direct access to your devices. Here is how to inventory them and rotate them safely.
Step 1: Inventory remote access and support tools
List every tool that can connect remotely to endpoints or servers:
- Remote support (BeyondTrust, TeamViewer, ScreenConnect/ConnectWise Control, Splashtop, AnyDesk).
- RMM platforms used by IT or MSPs.
- Privileged access management tools.
- Built-in cloud tools (Azure Bastion, Run Command, AWS Systems Manager).
Include tools used by vendors and MSPs on your systems.
Step 2: Inventory keys and integrations
For each tool:
- API keys and tokens (where are they stored, who created them, what scope, when do they expire?).
- Integrations with ticketing, identity or monitoring systems.
- Local accounts in the tool.
Step 3: Reduce scope
Limit each API key to the minimum permissions and, where supported, to specific IP ranges.
Step 4: Rotate
Rotate keys on a schedule and immediately after any vendor incident or staff departure. Store keys in a vault (Azure Key Vault, AWS Secrets Manager).
Step 5: Strengthen session controls
- SSO with MFA for technicians.
- Session approval by end users or supervisors for sensitive systems.
- Session recording and logging.
- Restricted groups of endpoints per technician role.
Step 6: Monitor
Forward tool logs to your SIEM. Alert on new API keys, password resets of tool accounts and sessions outside business hours.
Step 7: Remove unused tools
Every unused remote access tool is unnecessary risk. Uninstall agents and close accounts.
- US Treasury Breached via a BeyondTrust API Key (Dec 2024) Incident Teardowns
- Detecting Stolen API Key: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Remote Support Vendors and Nation-State Risk CIO Briefings