Layer of Azure operations that act on a resource itself, such as changing a key vault's properties, firewall or access policies. Azure RBAC authorises it, and it gives no access to the data inside the resource.
Also called control plane.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Management plane in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
Related terms
- Storage Account Contributor
Manages storage accounts at the management plane, yet because listKeys is among its permissions it can reach every piece of data via Shared Key. For data access, that is broader than least privilege.