Operations that act on what is inside a resource, for example the secrets, keys and certificates held in a vault; in Key Vault these are authorised through data roles or access policies and filtered by the Key Vault firewall.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Data plane in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Key Vault network settings
Firewall controls on a vault that restrict data-plane access to permitted public IP ranges and VNet subnets via service endpoints, optionally letting trusted services bypass. IP rules can't contain private addresses.
Related terms
- Control plane
Management layer used to create, configure and remove resources, as distinct from the data plane where they are used. Azure Resource Manager fills this role for Azure, and in AKS Azure operates the Kubernetes control plane on your behalf.
- Foundry control plane and data plane
The two halves of Foundry's RBAC model. Control plane actions cover resource settings, networking, deployments and project creation, whereas data plane actions cover work inside a project such as building agents, running evaluations and uploading files.
- Foundry Owner
Built-in role combining control plane and data plane rights, so its holders can stand up resources and projects, look after models and also build within projects; it is among the most privileged Foundry roles.
- Search Index Data Contributor
Role on the Azure AI Search data plane that can upload and change documents in indexes, replacing admin keys with keyless access to data.
- Vault access policy
The older permission model for Key Vault's data plane. Microsoft recommends Azure RBAC instead, which new vaults use by default from API version 2026-02-01; existing vaults stay on whichever model they have.