last sync: 2024-Mar-18 18:48:33 UTC

Key Vault Administrator

Azure BuiltIn RBAC Role definition

NameKey Vault Administrator
Id00482a5a-887f-4fb3-b363-3b7fe8e74483
DescriptionPerform all data plane operations on a key vault and all objects in it, including certificates, keys, and secrets. Cannot manage key vault resources or manage role assignments. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2020-05-19 17:52:46 UTC
UpdatedOn2021-11-11 20:14:30 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2020-05-19 20:42:36 add: Role 00482a5a-887f-4fb3-b363-3b7fe8e74483
Permissions summary Effective control plane and data plane operations: 126 (unique operations)
•Action: 49
•Delete: 8
•read: 63
•Write: 6

Actions: 10
Resolved control plane operations from Actions: 75
Effective control plane operations: 75
•Action: 12
•Delete: 2
•read: 58
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15054

DataActions: 1
Resolved data plane operations: 52
Effective data plane operations: 52
•action: 37
•delete: 6
•read: 6
•write: 3

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3043
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/deletedVaults/readView the properties of soft deleted key vaults
Microsoft.KeyVault/locations/*/readwildcarded / no description
Microsoft.KeyVault/operations/readLists operations available on Microsoft.KeyVault resource provider
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions
Operation Description
Microsoft.KeyVault/vaults/*wildcarded / no description
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2022-05-01-preview
Condition none