Welcome to Tenable for Microsoft Azure Key Vault
This document provides information and steps for integrating Tenable One Vulnerability Management, or Tenable Nessus with Microsoft Azure Key Vault. For more information, refer to the following product documentation:
Overview
The Tenable integration with Microsoft Azure Key Vault delivers a credentialed-scanning solution that lets security teams store privileged secrets in Azure Key Vault and retrieve them automatically at scan time. Sensitive passwords and SSH private keys remain centrally managed in the vault — they are never stored in the Tenable scan policy and are rotated without any manual policy update.
You can integrate Microsoft Azure Key Vault with Tenable One Vulnerability Management, or Tenable Nessus to perform credentialed scanning of SSH, Windows (SMB), and Database targets, or use them in conjunction with the VMware vCenter API, VMware ESXi SOAP API, and Nutanix Prism Central credential types.
The benefits of integrating Tenable with Microsoft Azure Key Vault include:
-
Centralized management of privileged credentials for Windows, SSH, Database, VMware, and Nutanix targets.
-
OAuth2 (client-credentials) authentication using a Microsoft Entra ID service principal, so no long-lived target passwords or SSH keys need to be stored in Tenable.
-
Support for both password- and SSH private-key-based target authentication via a single Key Vault secret.