# Refresh a key-based Azure Function action after rotating its access key

> What must change in an action group when the key saved for its Azure Function endpoint is rotated?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-005-refresh-a-key-based-azure-function-action-after-rotating-its-access-key/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:51+00:00
- Modified: 2026-09-10T00:31:59+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

What must change in an action group when the key saved for its Azure Function endpoint is rotated?

## Potentially affected

Azure Monitor action groups invoking Azure Functions through a saved endpoint and access key.

## DSE recommendation

Include recreation and testing of the function action in the approved key-rotation procedure.

## Article

## Source facts

For the documented key-based Function action, Azure Monitor saves the HTTP-trigger endpoint and its access key in the action definition. Microsoft instructs administrators to remove and recreate that action after changing the Function key. The endpoint must accept HTTP POST. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups).

An action group must be saved before testing, including after edits. Its test provides Success or Failed status and error details when unsuccessful. Closing the running test window stops the test and prevents results from being returned. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups).

## Applicability

Use this procedure for Azure Monitor action groups invoking Azure Functions through a saved endpoint and access key. It is not a procedure for the separately documented managed-identity preview. Identify the authentication actually configured before choosing a rotation path.

## DSE recommendation

DSE recommends adding the dependent function action to the key owner’s rotation record. Arrange a safe test payload and notify the workflow owner before recreating it. Keep secrets out of tickets and screenshots; record only the action identity, change reference and outcome. Do not assume that changing the Function key automatically updates an existing action definition.

## Verification

Save the replacement action, run the selected action-group test and leave its result view open. Correlate the reported outcome with the Function owner’s observed invocation and intended downstream result. Retain sanitized errors if either observation fails, and keep the change open until the two sides agree.

## Official references

[Microsoft Learn: Action groups](https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups).

## Primary reference

- Name: Create and manage action groups in Azure Monitor - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Refresh a key-based Azure Function action after rotating its access key,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-005-refresh-a-key-based-azure-function-action-after-rotating-its-access-key/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
