AES keyvault intercept logic that captures decrypted data, when keyvault write path is enabled, should be in lock-step with the AES control shadowed register configuration. That is, any changes to the operating parameters of the AES operation while decrypting key content (to place into Keyvault) shall be disallowed.