Rather than storing a secret's value, a setting can point to it in Key Vault and fetch it with a managed identity. App Service and Functions use the @Microsoft.KeyVault(...) app setting syntax and refresh within a day; Container Apps use a secret holding a keyvaultref: URL, and without a pinned version they follow new versions inside half an hour.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Key Vault reference in context, with comparison tables and the common traps.
Terms in this definition
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
- Microsoft.KeyVault
Namespace of the Key Vault resource provider, with actions such as Microsoft.KeyVault/vaults/write; it is also what the Key Vault service endpoint is called.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- URL
The web address of a resource, on which URL-based routing relies.
Related terms
- Python configuration provider
A Python library for App Configuration that builds on the SDK, loading settings into an object that behaves like a dictionary and adding refresh, feature flags and Key Vault reference resolution.