Event that Key Vault publishes to Event Grid 30 days ahead of a secret's expiry. Since secrets lack a built-in rotation policy, a Logic App or function typically reacts to it to rotate them.
Also called Microsoft.KeyVault.SecretNearExpiry.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SecretNearExpiry in context, with comparison tables and the common traps.
Terms in this definition
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Event Grid
Routes events, Key Vault SecretNearExpiry for example, by pushing them to handlers such as Azure Functions. It stores nothing and cannot receive Entra diagnostic settings.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- Key rotation policy
Automatic rotation of a Key Vault key, either a fixed interval after creation or ahead of expiry, plus a setting for when to notify. Secrets can't have one; only keys can.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.