last sync: 2025-Feb-14 18:36:54 UTC

Key Vault Reader

Azure BuiltIn RBAC Role definition

NameKey Vault Reader
DescriptionRead metadata of key vaults and its certificates, keys, and secrets. Cannot read sensitive values such as secret contents or key material. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2020-05-19 17:52:47 UTC
UpdatedOn2021-11-11 20:14:31 UTC
Date/Time (UTC ymd) (i) Change Change detail
2020-05-19 20:42:36 add: Role 21090545-7ca7-4776-b22c-e363652d74d2
Permissions summary Effective control plane and data plane operations: 82 (unique operations)
•: 1
•Action: 11
•Delete: 2
•read: 65
•Write: 3

Actions: 10
Resolved control plane operations from Actions: 76
Effective control plane operations: 76
•: 1
•Action: 10
•Delete: 2
•read: 60
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16273

DataActions: 2
Resolved data plane operations: 7
Effective data plane operations: 7
•action: 1
•read: 6

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3334
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/deletedVaults/readView the properties of soft deleted key vaults
Microsoft.KeyVault/locations/*/readwildcarded / no description
Microsoft.KeyVault/operations/readLists operations available on Microsoft.KeyVault resource provider
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/read리소스 그룹을 가져오거나 나열합니다.
Microsoft.Support/*wildcarded / no description
NotActions n/a
Operation Description
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.KeyVault/vaults/secrets/readMetadata/actionList or view the properties of a secret, but not its value.
NotDataActions n/a
Used in
BuiltIn Policy
Condition none