Under the Key Vault RBAC model, this role lets an identity read the contents of secrets.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AI-200AZ-400
Each book explains Key Vault Secrets User in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- RBAC
Short for role-based access control: Azure role assignments, inherited downward through scopes, that decide who may perform which actions on resources. Resource location and size are outside its control.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- App Configuration Data Reader
Lets a signed-in identity look up key-values stored in App Configuration, purely as a data-plane permission: holding it confers nothing over the configuration store as an Azure resource. When a key points to Key Vault, that identity also needs Key Vault Secrets User on the vault before the reference resolves.
- Azure RBAC permission model
Way of authorising access to Key Vault through Azure role assignments, for instance Key Vault Secrets User, in place of vault access policies.
- Key Vault-linked variable group
Pulls fresh values of selected Key Vault secrets into a pipeline on every run, though keys and certificates are not supported. The service connection must hold Get and List, or the Key Vault Secrets User role; vaults using RBAC behind a private endpoint won't work.