Older permission model for Key Vault, now superseded by the Azure RBAC model.
Also called Key Vault.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Access policies in context, with comparison tables and the common traps.
Terms in this definition
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
Related terms
- Activity log
Record, held for 90 days, of control-plane operations in a subscription such as deployments and Policy events. Data-plane actions, Key Vault reads for example, are not captured.
- APIM named values
Reusable name/value pairs referenced from API Management policies. A value can be held in plain text, encrypted inside APIM as a secret, or pulled from Key Vault through the instance's managed identity.
- App Configuration Data Reader
Lets a signed-in identity look up key-values stored in App Configuration, purely as a data-plane permission: holding it confers nothing over the configuration store as an Azure resource. When a key points to Key Vault, that identity also needs Key Vault Secrets User on the vault before the reference resolves.
- Application Gateway v2
Present-day Application Gateway SKU, Standard_v2 or WAF_v2, offering zone redundancy, autoscaling, a static VIP, Key Vault integration and header rewrite. It requires its own subnet, ideally a /24.
- Application routing add-on
Managed NGINX ingress for AKS, deployed and run as an add-on, integrated with Azure DNS and with certificates held in Key Vault. Its NGINX version is supported only until the end of November 2026, after which the Gateway API version takes over.
- AuditEvent
Category of Key Vault resource logs that tracks each data-plane get, set or delete, noting who called, from which IP address, and whether it succeeded.
- Azure Disk Encryption
Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.
- Azure geography
Grouping of Azure regions such as United States; restoring a Key Vault backup is allowed only inside the geography it came from.