Azure Security built-in role

Key Vault Administrator

Performs all Key Vault data-plane operations on a vault and every key, secret, and certificate in it. It cannot write the Key Vault resource or Azure RBAC role assignments, but its control-plane Actions can create and manage classic metric alerts, deployments, and support tickets. It works only on vaults that use the Azure RBAC permission model.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 00482a5a-887f-4fb3-b363-3b7fe8e74483

Control-plane actions (10)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft recommends a vault per application and environment with data-plane roles assigned at the vault scope. Azure RBAC assignments at a parent scope are inherited by child vaults. At resource-group or broader scope, the ancillary alert-rule, deployment, and support Actions also apply throughout that scope. Object-level assignments are supported only for limited scenarios and are not a substitute for a separate vault security boundary.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Administrator only at the vault scope and only when one principal must administer all three object types. Prefer Certificates Officer, Crypto Officer, Secrets Officer, or a runtime user role for narrower duties, and keep Key Vault Contributor and role-assignment authority separate.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →