last sync: 2024-May-07 17:44:27 UTC

Key Vault Certificate User

Azure BuiltIn RBAC Role definition

NameKey Vault Certificate User
Iddb79e9a7-68ee-4b58-9aeb-b90e7c24fcba
DescriptionRead certificate contents. Only works for key vaults that use the 'Azure role-based access control' permission model.
CreatedOn2024-01-11 16:37:07 UTC
UpdatedOn2024-01-11 16:37:07 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2024-01-11 18:35:40 add: Role db79e9a7-68ee-4b58-9aeb-b90e7c24fcba
Permissions summary Effective control plane and data plane operations: 4 (unique operations)
•action: 2
•read: 2

Actions: 0
Resolved control plane operations from Actions: 0
Effective control plane operations: 0

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15621

DataActions: 4
Resolved data plane operations: 4
Effective data plane operations: 4
•action: 2
•read: 2

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3076
Actions n/a
NotActions n/a
DataActions
Operation Description
Microsoft.KeyVault/vaults/certificates/readList certificates in a specified key vault, or get information about a certificate.
Microsoft.KeyVault/vaults/keys/readList keys in the specified vault, or read properties and public material of a key. For asymmetric keys, this operation exposes public key and includes ability to perform public key algorithms such as encrypt and verify signature. Private keys and symmetric keys are never exposed.
Microsoft.KeyVault/vaults/secrets/getSecret/actionGets the value of a secret.
Microsoft.KeyVault/vaults/secrets/readMetadata/actionList or view the properties of a secret, but not its value.
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition none