Key Vault Crypto Service Encryption User
ContributorIAM ScopeSecurity·6 na definição · ≥ 3 efetivas
Dado verificado em · Fonte
Entradas na definição
6Actions
0NotActions
0DataActions
0Alcance efetivo
piso, não totalControl plane
3Data plane
3Na definição (nativo)
6Piso, não total: expandido contra 17.591 ações de 151 providers colhidas da documentação da Microsoft. A Azure Management API expõe mais — o número real é maior, nunca menor.
Role ID
e147488a-f6f5-4113-8e2d-b22465e65bf6Categoria
SecurityRisk Tier
Contributor (CTB)Risk Tier: Contributor
Grants full write access to create and manage all resources but cannot assign roles or manage access to others.
Descrição
MicrosoftRead metadata of keys and perform wrap/unwrap operations. Only works for key vaults that use the 'Azure role-based access control' permission model.
Role Definition (JSON)
{"Name": "Key Vault Crypto Service Encryption User","Id": "e147488a-f6f5-4113-8e2d-b22465e65bf6","IsCustom": false,"Description": "Read metadata of keys and perform wrap/unwrap operations. Only works for key vaults that use the 'Azure role-based access control' permission model.","Actions": [],"NotActions": [],"DataActions": [],"NotDataActions": [],"AssignableScopes": ["/"]
Assignable Scopes
/
PowerShell
Get-AzRoleDefinition -Name "Key Vault Crypto Service Encryption User"
Azure CLI
az role definition list --name "Key Vault Crypto Service Encryption User"