azure-purview-scan-credential-reference

Scan definitions reveal which stored credential or managed identity is used and the target scope.

azurehigh service: azure:purview emits ContainsSecret

Where it sits

locationPurview Scan properties.credential reference and collection
location kindconfig_field
data kindscredential sensitive_data
emits edgeContainsSecret
serviceMicrosoft Purview (azure:purview)

Collection recipe

access modedata_plane
operationScans - Get
response pathproperties.credential
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Purview/accounts/scan/read

References

move · open · esc close