Azure Security built-in role

Key Vault Certificates Officer

Performs certificate data-plane lifecycle operations in a Key Vault, including certificate, issuer, and contact management, but cannot manage Azure RBAC permissions. Its control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. It works only with vaults using the Azure RBAC permission model and does not grant general secret or key administration.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a4417e6f-fecd-4de8-b567-7b0420556985

Control-plane actions (10)

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the individual vault whose certificate lifecycle the principal owns. Parent-scope assignments are inherited by all child vaults and also extend the ancillary alert-rule, deployment, and support Actions across the parent scope. Object-level assignments do not cover vault-wide issuer, contact, monitoring, or administrative workflows. Microsoft recommends separate vaults by application and environment.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Certificates Officer at the vault scope to the team responsible for certificate issuance and renewal. Keep runtime certificate retrieval on Key Vault Certificate User, retain permission delegation with a separate administrator, and use eligible access for human officers where available.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →