Azure Security built-in role

Key Vault Crypto Officer

Performs all Key Vault key data-plane operations and manages key rotation policies, but cannot manage Azure RBAC permissions. Its control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. It works only with vaults using the Azure RBAC permission model and does not grant secret or certificate administration.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 14b46e9e-c2b7-41b4-b07b-48a6ebf60603

Control-plane actions (10)

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the individual vault for the key-management team. Parent-scope assignments are inherited by child vaults and extend the ancillary alert-rule, deployment, and support Actions across the parent scope. Key-level assignment is supported for exceptional isolation cases, but Microsoft recommends vault-per-application boundaries and vault-level role assignments for ordinary administration.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Crypto Officer only to key lifecycle administrators at the vault scope. Use Key Vault Crypto User or Crypto Service Encryption User for workload operations, keep permission delegation separate, and require review for backup, restore, purge, or rotation-policy changes.

Related roles (2)

Common questions

When should I assign the Key Vault Crypto Officer Azure role?

Assign Key Vault Crypto Officer when you need to: Create, import, rotate, enable, disable, back up, restore, delete, recover, or purge cryptographic keys.; and Manage key rotation policies and perform approved encrypt, decrypt, wrap, unwrap, sign, or verify operations during key administration.. Practical scope: Assign at the individual vault for the key-management team. Parent-scope assignments are inherited by child vaults and extend the ancillary alert-rule, deployment, and support Actions across the parent scope. Key-level assignment is supported for exceptional isolation cases, but Microsoft recommends vault-per-application boundaries and vault-level role assignments for ordinary administration.

What permissions does the Key Vault Crypto Officer Azure role grant?

The role definition grants 12 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.Resources/deployments/*; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Support/*; and Microsoft.KeyVault/checkNameAvailability/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Key Vault Crypto Officer Azure role?

Key considerations when assigning Key Vault Crypto Officer: The role can decrypt, unwrap, sign, back up, restore, delete, and purge keys, affecting confidentiality, integrity, and service availability.; A restored key backup is independent of the original, so disabling or deleting the source key does not invalidate a restored copy.; and Key deletion or disablement can make dependent encrypted services unavailable; broad assignment also permits classic-alert, deployment, and support-ticket changes outside the key data plane.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →