Firewall controls on a vault that restrict data-plane access to permitted public IP ranges and VNet subnets via service endpoints, optionally letting trusted services bypass. IP rules can't contain private addresses.
Also called Key Vault firewall.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Key Vault network settings in context, with comparison tables and the common traps.
Terms in this definition
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Trusted services
An ACR option, on by default, letting chosen Azure services, for instance ACR import, Container Instances and Defender for Cloud, get past a registry's firewall rules or private endpoint. App Service isn't covered.
Related terms
- Data plane
Operations that act on what is inside a resource, for example the secrets, keys and certificates held in a vault; in Key Vault these are authorised through data roles or access policies and filtered by the Key Vault firewall.
- Trusted Microsoft services
An exception in the Key Vault firewall that lets approved services, among them Azure Backup, Azure Disk Encryption and Resource Manager template deployment, access the vault regardless of network.