Why does an App Service Key Vault reference fail when my account can read the secret?
0 reputation · 12 Apr 2025, 03:34 UTC
In this example, a web app has a system-assigned identity and a versionless Key Vault reference. The administrator can read the secret in the portal, but the app reports an unresolved setting. The vault uses Azure RBAC. The administrator assigned Key Vault Contributor to the app identity and assumed that included secret access. What should be checked before granting broader permissions?
- Environment
- Editorial worked example. See the question for the scenario and assumptions.