Forum Discussion
New Microsoft Azure Key Vault Integration
Summary
We are pleased to announce that Tenable's credentialed scanning now supports Microsoft Azure Key Vault as a Privileged Access Management (PAM) integration. This will be available in Tenable One Vulnerability Management and Tenable Nessus Immediately.
Change
Tenable's credentialed scanning has been updated to include Microsoft Azure Key Vault as a new authentication method. Security teams can now store privileged credentials in Azure Key Vault and have Tenable retrieve them automatically at scan time using OAuth2 client-credentials authentication with a Microsoft Entra ID service principal. Credentials such as sensitive passwords and SSH private keys are maintained centrally inside the vault, they are never stored in Tenable scan policies and can be rotated seamlessly without requiring manual policy updates.
The Azure Key Vault integration supports the following credential types:
- SSH
- Windows (SMB)
- Database (Oracle, SQL Server, MySQL, PostgreSQL, DB2, MongoDB)
- VMware ESXi SOAP API
- VMware vCenter API
- Nutanix Prism Central
Each Key Vault secret is expected to hold a JSON object containing one or more of the fields username, password, ssh_key, ssh_keyphrase, and domain, so a single secret can drive both password and SSH private-key-based target authentication. For SSH targets, privilege escalation may optionally reference a separate Key Vault secret whose password field is used as the sudo/su password.
For more information see our Microsoft Azure Key Vault Integration user documentation:
https://docs.tenable.com/Integrations.htm
Impact
No impact to current scans are expected; If customers encounter issues with this integration, please open a ticket with Technical Support.
Release Date
September 3, 2026 for Tenable One Vulnerability Management and Nessus
TBD for Tenable Security Center