Namespace of the Key Vault resource provider, with actions such as Microsoft.KeyVault/vaults/write; it is also what the Key Vault service endpoint is called.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft.KeyVault in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Resource provider
Service offering Azure resource types within a namespace, for example Microsoft.Network or Microsoft.Compute. Role actions take the form namespace/resourceType/operation.
- Service endpoint
Sends a subnet's traffic to an Azure service's public endpoint across the Microsoft backbone, identifying the subnet as the source. It is free, uses no subnet IP addresses and cannot be used from on-premises networks.
Related terms
- Key Vault reference
Rather than storing a secret's value, a setting can point to it in Key Vault and fetch it with a managed identity. App Service and Functions use the @Microsoft.KeyVault(...) app setting syntax and refresh within a day; Container Apps use a secret holding a
keyvaultref:URL, and without a pinned version they follow new versions inside half an hour. - Key Vault references
With app settings written as
@Microsoft.KeyVault(...), App Service and Azure Functions pull secret values from Key Vault, so no code change is needed.