简体   繁体   中英

Do I need to add app on access policy of key vault if the app is already the owner on subscription level

If I give owner access to an app on subscription level, do I still need to add the app on access policy in key vault so that the app can retrieve the secret value from azure key vault through http GET method?

The answer is yes, if you use the Vault access policy permission model.

However, the answer is no, if you use the Azure role-based access control permission model - but then you would have to assign an appropriate RBAC role since the Owner role would not have access.

Reference: Provide access to Key Vault keys, certificates, and secrets with an Azure role-based access control (preview)

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM