Single entry in the legacy Key Vault model that gives one user, group, app or managed identity chosen operations on keys, secrets or certificates, applying to the entire vault.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Key Vault access policy in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
Related terms
- Azure Disk Encryption for volume encryption
Key Vault access policy setting (enabled-for-disk-encryption) without which Azure Disk Encryption can't store keys and secrets in the vault; the vault also has to be in the same region as the VM.
- Enable access to Azure Virtual Machines for deployment
Advanced Key Vault access policy that allows virtual machines to fetch certificates held as secrets. Azure Disk Encryption does not require it.