Azure Security built-in role

Key Vault Crypto Service Encryption User

Reads Key Vault key metadata and performs wrap and unwrap data-plane operations for service-encryption scenarios. It also manages the Event Grid subscriptions exposed by the built-in definition, has no general key lifecycle authority, and works only with vaults using Azure RBAC.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e147488a-f6f5-4113-8e2d-b22465e65bf6

Control-plane actions (3)

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the managed identity of the Azure service at the individual key or vault scope documented by that service. Parent assignments are inherited by child vaults and keys. Microsoft recommends a vault per application and environment rather than broad shared-vault access.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Crypto Service Encryption User to the documented service managed identity at the key or vault scope required by the integration. Do not use it as a general human crypto role, and validate encryption, rotation, logging, and recovery before removing prior key access.

Editorial sources (6)

Official Microsoft Learn documentation →