Scan Results Review
This section helps users interpret the results of their scans.
Plugin families and plugins
The Microsoft Azure Key Vault integration is used to gather credentials for target authentication during credentialed scans via SMB (Windows), SSH, Database, VMware vCenter, VMware ESXi, or Nutanix Prism Central. The following Tenable plugins are relevant when reviewing scan results:
Misc. plugin family:
-
Plugin #204872: Integration Status: When using one of Tenable's integrations with any PAM integration, the Integration Status plugin confirms whether credential retrieval was a success or failure.
-
Plugin #160185: Nutanix Data Collection: Reports data collected from Nutanix Prism Central via its REST APIs after the Azure Key Vault integration retrieves the credentials used to authenticate to the target.
Settings plugin family:
-
Plugin #14273: SSH settings: Reads the SSH PAM credential configuration and calls the Azure Key Vault integration to retrieve credentials for SSH targets. This plugin is not indicative of authentication issues by itself; authentication failures are reported by the credential-status plugins below.
-
Plugin #10870: Login configurations: Reads Windows (SMB) credential configuration and calls the Azure Key Vault integration to retrieve credentials for Windows targets.
-
Plugin #33815: Database settings: Reads database credential configuration and calls the Azure Key Vault integration to retrieve credentials for database targets.
-
Plugin #19506: Nessus Scan Information: Reports scan metadata including whether credentialed checks succeeded. Check this plugin first when investigating authentication issues.
-
Plugin #91822: Database Authentication Failure(s) for Provided Credentials: Indicates that the database credentials retrieved from Azure Key Vault could not authenticate to the target database. Check that the Secret Name resolves to a JSON object containing a valid username and password for the target database.
-
Plugin #141118: Target Credential Status by Authentication Protocol – Valid Credentials Provided: Confirms credential validity by successfully authenticating to the remote target. Look for "Proto: SMB" or "Proto: SSH" in the output.
-
Plugin #110095: Target Credential Issues by Authentication Protocol – No Issues Found: Indicates that credentials were provided and authentication succeeded for all targeted protocols.
-
Plugin #104410: Target Credential Status by Authentication Protocol – Failure for Provided Credentials: Indicates that credentials were provided but authentication to the target failed — the values retrieved from Azure Key Vault may be incorrect or lack sufficient permission on the target.
-
Plugin #110723: Target Credential Status by Authentication Protocol – No Credentials Provided: Indicates that no credentials were available for the targeted protocol. If this appears when an Azure Key Vault credential is configured, the integration likely failed to retrieve the secret.
-
Plugin #117885: Target Credential Issues by Authentication Protocol – Intermittent Authentication Failure: Indicates that authentication succeeded for some targets but not others — may point to per-target credential differences or intermittent Key Vault connectivity.
VMWare ESX Local Security Checks family:
-
Plugin #57400 (Scan Results Review): VMware vSphere installed VIBs: Reports the installed VIBs collected on a VMware ESXi or vCenter host after the Azure Key Vault integration retrieves the credentials used to authenticate to the target.