last sync: 2024-Sep-19 17:51:49 UTC

Key Vault Reader

Azure BuiltIn RBAC Role definition

NameKey Vault Reader
Id21090545-7ca7-4776-b22c-e363652d74d2
DescriptionRead metadata of key vaults and its certificates, keys, and secrets. Cannot read sensitive values such as secret contents or key material. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2020-05-19 17:52:47 UTC
UpdatedOn2021-11-11 20:14:31 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2020-05-19 20:42:36 add: Role 21090545-7ca7-4776-b22c-e363652d74d2
Permissions summary Effective control plane and data plane operations: 80 (unique operations)
•: 1
•Action: 11
•Delete: 2
•read: 63
•Write: 3

Actions: 10
Resolved control plane operations from Actions: 74
Effective control plane operations: 74
•: 1
•Action: 10
•Delete: 2
•read: 58
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15721

DataActions: 2
Resolved data plane operations: 7
Effective data plane operations: 7
•action: 1
•read: 6

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3252
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/deletedVaults/readView the properties of soft deleted key vaults
Microsoft.KeyVault/locations/*/readwildcarded / no description
Microsoft.KeyVault/operations/readLists operations available on Microsoft.KeyVault resource provider
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions
Operation Description
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.KeyVault/vaults/secrets/readMetadata/actionList or view the properties of a secret, but not its value.
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition none