Encryption Key Lifecycle Changed

Sent when an encryption key is registered, validated, fails validation, is scheduled for deletion, or is deleted.

General Information

Event ID: vdc.org_v0.kmskey_v0.lifecycle_v0

Event message details: Sent with data.lifecycle.action set to REGISTERED, VALIDATED, VALIDATION_FAILED, DELETION_SCHEDULED or DELETED.

Severity: Varies depending on data.lifecycle.action.

General Information

data.lifecycle.action

Severity

REGISTERED

Info

VALIDATED

Info

VALIDATION_FAILED

High

DELETION_SCHEDULED

High

DELETED

High

Workloads: Control Plane

Parameters

Parameters

Parameter Name

Description

Example

specversion

Event schema version.

20250815

source

System that sent the event. Possible values: CONTROLPLANE, M365.

CONTROLPLANE

timestamp

Time when the event happened, in RFC3339Nano format and the UTC time zone.

2026-08-04T09:18:42Z

type

Event ID.

vdc.org_v0.kmskey_v0.lifecycle_v0

actor.kind

Actor type that triggered the event. Possible values: user, system, service_account.

user

actor.identifier

Actor identifier.

admin@bob.networking

organizationReference.organizationId

ID of the Veeam Data Cloud organization.

org_12345

data.kmskey.keyId

Control-plane-derived key ID.

b3f1c2a4-0000-0000-0000-000000000000

data.kmskey.keyDisplayName

Display name of the key. Used as the audit target, so the action reads against a human-readable name.

Finance Org CMK Key

data.kmskey.provider

Key Management Service (KMS) provider backing the key. Possible values:AZURE_KEY_VAULT.

AZURE_KEY_VAULT

data.lifecycle.action

Key-level lifecycle transition that occurred. Possible values: REGISTERED, VALIDATED, VALIDATION_FAILED, DELETION_SCHEDULED, DELETED.

REGISTERED

data.lifecycle.status

Resulting key state after the transition. Omitted for a DELETED transition, which leaves no resulting key state. Possible values: PENDING_CUSTOMER_SETUP, READY_TO_USE, ACTIVE, VALIDATION_FAILED, PENDING_DELETION.

PENDING_CUSTOMER_SETUP

data.lifecycle.previousStatus

Key state immediately before the transition. Possible values: PENDING_CUSTOMER_SETUP, READY_TO_USE, ACTIVE, VALIDATION_FAILED, PENDING_DELETION.

ACTIVE

data.lifecycle.failureReason

Human-readable cause of a VALIDATION_FAILED transition. Never contains secrets or key material.

Wrap/unwrap denied: caller lacks Key Vault Crypto User role.

data.lifecycle.failureSource

What triggered a VALIDATION_FAILED transition. Possible values: CUSTOMER_VALIDATE, MONITOR.

MONITOR

data.lifecycle.keyIdentifier

Uniform Resource Identifier (URI) of the provider key, including the key name. Never includes key material.

https://myvault.vault.azure.net/keys/prod-cmk

data.lifecycle.keyVersion

Current key version.

a1b2c3d4e5f6

data.lifecycle.scheduledDeletionAt

Hard-delete time for a DELETION_SCHEDULED transition, 30 days out.

2026-07-16T00:00:00Z

data.org.id

ID of the Veeam Data Cloud organization.

org_12345

data.org.name

Name of the Veeam Data Cloud organization.

Alice and Bob's Networking

Event Example

{
  "specversion": "20250815",
  "source": "CONTROLPLANE",
  "timestamp": "2026-08-04T09:18:42Z",
  "type": "vdc.org_v0.kmskey_v0.lifecycle_v0",
  "actor": {
    "identifier": "admin@bob.networking",
    "kind": "user"
  },
  "organizationReference": {
    "organizationId": "org_12345"
  },
  "data": {
    "kmskey": {
      "keyId": "b3f1c2a4-0000-0000-0000-000000000000",
      "keyDisplayName": "Finance Org CMK Key",
      "provider": "AZURE_KEY_VAULT"
    },
    "lifecycle": {
      "action": "REGISTERED",
      "status": "PENDING_CUSTOMER_SETUP"
    },
    "org": {
      "id": "org_12345",
      "name": "Alice and Bob's Networking"
    }
  }
}