Microsoft disclosed on July 16 2026 that a misconfigured key rotation service exposed Azure storage account keys for 18000 tenants between July 5 and July 16. The keys provided read access to blob storage containing logs and telemetry. The company revoked all affected keys within four hours of discovery.
Microsoft stated the incident originated from an automated script that failed to rotate keys after a July 5 region failover. Internal telemetry showed no evidence of external access to the exposed keys during the 11-day window.
The company notified affected customers via the Azure portal and offered 90 days of complimentary security monitoring. This marks the second Azure key incident in 2026 after a March certificate error.
Security researchers noted the incident highlights persistent challenges in managing secrets at hyperscale despite widespread adoption of managed identities.
Why this matters
The breach underscores that even mature cloud providers remain vulnerable to automation errors in key management pipelines. Enterprises using Azure for sensitive workloads may accelerate migration to customer-managed keys or third-party vaults.
Regulators in the EU and US are expected to request detailed post-incident reports within 30 days.
Microsoft committed to publishing a full root-cause analysis by July 31 2026.