Key Vault option, shown as Azure Resource Manager for template deployment, allowing ARM to fetch secrets while deploying. Whoever deploys must also hold Microsoft.KeyVault/vaults/deploy/action.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains enabledForTemplateDeployment in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- ARM
Short for Azure Resource Manager, the control plane Azure uses for deploying and managing resources.
- Model deployment
Inside a resource, each deployment is a named copy of a Foundry model with its own TPM quota and deployment type. Requests identify the model by this deployment name.
- Microsoft.KeyVault/vaults/deploy/action
Before a template deployment can pull in a secret from Key Vault, whoever runs it needs this permission. Both Contributor and Owner already grant it.