Azure Security built-in role

Key Vault Crypto Officer

Performs all Key Vault key data-plane operations and manages key rotation policies, but cannot manage Azure RBAC permissions. Its control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. It works only with vaults using the Azure RBAC permission model and does not grant secret or certificate administration.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 14b46e9e-c2b7-41b4-b07b-48a6ebf60603

Control-plane actions (10)

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the individual vault for the key-management team. Parent-scope assignments are inherited by child vaults and extend the ancillary alert-rule, deployment, and support Actions across the parent scope. Key-level assignment is supported for exceptional isolation cases, but Microsoft recommends vault-per-application boundaries and vault-level role assignments for ordinary administration.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Crypto Officer only to key lifecycle administrators at the vault scope. Use Key Vault Crypto User or Crypto Service Encryption User for workload operations, keep permission delegation separate, and require review for backup, restore, purge, or rotation-policy changes.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →