last sync: 2024-Jul-17 18:20:49 UTC

Key Vault Secrets Officer

Azure BuiltIn RBAC Role definition

NameKey Vault Secrets Officer
DescriptionPerform any action on the secrets of a key vault, except manage permissions. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2020-05-19 17:52:47 UTC
UpdatedOn2021-11-11 20:14:30 UTC
Date/Time (UTC ymd) (i) Change Change detail
2020-05-19 20:42:36 add: Role b86a8fe4-44ce-4948-aee5-eccb2c155cd7
Permissions summary Effective control plane and data plane operations: 83 (unique operations)
•: 1
•Action: 18
•Delete: 3
•read: 58
•Write: 3

Actions: 10
Resolved control plane operations from Actions: 74
Effective control plane operations: 74
•: 1
•Action: 10
•Delete: 2
•read: 58
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15620

DataActions: 1
Resolved data plane operations: 9
Effective data plane operations: 9
•action: 8
•delete: 1

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3208
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/deletedVaults/readView the properties of soft deleted key vaults
Microsoft.KeyVault/locations/*/readwildcarded / no description
Microsoft.KeyVault/operations/readno description given
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
Operation Description
Microsoft.KeyVault/vaults/secrets/*wildcarded / no description
NotDataActions n/a
Used in
BuiltIn Policy
Condition none