Concept and mechanism
Key Vault has management and data planes. In an RBAC vault, Key Vault Reader reads metadata, while Secrets User allows reading secret values. Contributor manages the resource and should not be treated as a direct data grant in that model. Migrating from access policies to RBAC invalidates previous permissions; inventory consumers and prepare equivalent minimum roles before cutover. Current documentation uses RBAC by default in API2026-02-01, but that does not establish existing-vault configuration and should not be projected backward onto the entire historical syllabus. Always verify the resource’s effective model.
Guided application
Soft delete supports recovery of deleted objects; purge protection prevents permanent removal during retention but does not keep a deleted secret available to the application. In Azure Policy, remediating existing resources with modify or deployIfNotExists requires the appropriate task and an authorized managed identity. An assignment created through an SDK does not automatically guarantee all execution roles. When reporting Defender for Cloud, distinguish automated assessments, manual evidence, scope, and controls still unproven. A report can support auditors without itself certifying the organization. For example,18 passed assessments out of24 applicable ones represent75% of that population rather than incident-free probability or the secure-score formula.
The administrator opens the vault, but the application receives403 after RBAC migration. Test the data action and consumer identity rather than only portal management.
Common pitfalls
Visible vault treated as readable secret; purge protection treated as availability; green dashboard treated as external certification.
Related topics: Identity and temporary privilege · Network boundaries and private access · Compute and operational access
Preserve the connection between evidence, scope, and acceptance decision.
Reference: Key Vault control and data planes and RBAC migration · AZ-500 objectives2026-01-22; retired2026-08-31