Key Vault Certificate User
Data PlaneIAM ScopeSecurity·4 na definição · ≥ 0 efetivas
Dado verificado em · Fonte
Entradas na definição
4Actions
0NotActions
0DataActions
0Alcance efetivo
piso, não totalControl plane
0Data plane
4Na definição (nativo)
4Piso, não total: expandido contra 17.591 ações de 151 providers colhidas da documentação da Microsoft. A Azure Management API expõe mais — o número real é maior, nunca menor.
Role ID
db79e9a7-68ee-4b58-9aeb-b90e7c24fcbaCategoria
SecurityRisk Tier
Data Plane (DP)Risk Tier: Data Plane
Grants access to data stored within services (blobs, queues, secrets, keys) without management plane control.
Descrição
MicrosoftRead certificate contents. Only works for key vaults that use the 'Azure role-based access control' permission model.
Role Definition (JSON)
{"Name": "Key Vault Certificate User","Id": "db79e9a7-68ee-4b58-9aeb-b90e7c24fcba","IsCustom": false,"Description": "Read certificate contents. Only works for key vaults that use the 'Azure role-based access control' permission model.","Actions": [],"NotActions": [],"DataActions": [],"NotDataActions": [],"AssignableScopes": ["/"]
Assignable Scopes
/
PowerShell
Get-AzRoleDefinition -Name "Key Vault Certificate User"
Azure CLI
az role definition list --name "Key Vault Certificate User"