Why does an App Service Key Vault reference fail when my account can read the secret?
In this example, a web app has a system-assigned identity and a versionless Key Vault reference. The administrator can read the secret in the portal, but the app reports an unresolved setting. The vault uses Azure RBAC. The administrator assigned Key Vault Contributor to the app identity and assumed that included secret access. What should be checked before