last sync: 2024-Mar-18 18:48:33 UTC

Key Vault Secrets Officer

Azure BuiltIn RBAC Role definition

NameKey Vault Secrets Officer
Idb86a8fe4-44ce-4948-aee5-eccb2c155cd7
DescriptionPerform any action on the secrets of a key vault, except manage permissions. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2020-05-19 17:52:47 UTC
UpdatedOn2021-11-11 20:14:30 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2020-05-19 20:42:36 add: Role b86a8fe4-44ce-4948-aee5-eccb2c155cd7
Permissions summary Effective control plane and data plane operations: 84 (unique operations)
•Action: 20
•Delete: 3
•read: 58
•Write: 3

Actions: 10
Resolved control plane operations from Actions: 75
Effective control plane operations: 75
•Action: 12
•Delete: 2
•read: 58
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15054

DataActions: 1
Resolved data plane operations: 9
Effective data plane operations: 9
•action: 8
•delete: 1

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3086
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.KeyVault/checkNameAvailability/readChecks that a key vault name is valid and is not in use
Microsoft.KeyVault/deletedVaults/readView the properties of soft deleted key vaults
Microsoft.KeyVault/locations/*/readwildcarded / no description
Microsoft.KeyVault/operations/readLists operations available on Microsoft.KeyVault resource provider
Microsoft.KeyVault/vaults/*/readwildcarded / no description
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions
Operation Description
Microsoft.KeyVault/vaults/secrets/*wildcarded / no description
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2022-05-01-preview
Condition none