Key Vault Crypto Officer

Azure BuiltIn RBAC Role definition

NameKey Vault Crypto Officer
DescriptionPerform any action on the keys of a key vault, except manage permissions. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2020-05-19 17:52:47 UTC
UpdatedOn2022-01-06 23:21:17 UTC
Date/Time (UTC ymd) (i) Change Change detail
2022-01-07 18:14:37 change: DisplayName, DataActions New DisplayName: 'Key Vault Crypto Officer'
Old DisplayName: 'Key Vault Crypto Officer (preview)',
DataActions: 'add Microsoft.KeyVault/vaults/keyrotationpolicies/*'
2020-05-19 20:42:36 add: Role 14b46e9e-c2b7-41b4-b07b-48a6ebf60603
Permissions summary Effective control plane and data plane operations: 92 (unique operations)
•: 1
•Action: 25
•Delete: 3
•read: 59
•Write: 4

Actions: 10
Resolved control plane operations from Actions: 74
Effective control plane operations: 74
•: 1
•Action: 10
•Delete: 2
•read: 58
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15576

DataActions: 2
Resolved data plane operations: 19
Effective data plane operations: 19
•action: 15
•delete: 1
•read: 2
•write: 1

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3141
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/deletedVaults/readView the properties of soft deleted key vaults
Microsoft.KeyVault/locations/*/readwildcarded / no description
Microsoft.KeyVault/operations/readLists operations available on Microsoft.KeyVault resource provider
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
Operation Description
Microsoft.KeyVault/vaults/keyrotationpolicies/*wildcarded / no description
Microsoft.KeyVault/vaults/keys/*wildcarded / no description
NotDataActions n/a
Used in
BuiltIn Policy
Condition none