Azure Security built-in role

Key Vault Crypto Service Release User

Performs the Key Vault key release data-plane operation for Secure Key Release to an attested trusted execution environment. It works only with Azure RBAC-enabled vaults and does not grant ordinary encrypt, decrypt, wrap, unwrap, sign, key lifecycle, or role-assignment operations.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 08bbd89e-9f13-488c-ac41-acfcb10c90ab

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the confidential workload identity at the individual exportable key when practical, or at the dedicated vault only when it must release multiple approved keys. Parent assignments are inherited. Secure Key Release is supported for Key Vault Premium and Managed HSM, but Managed HSM data-plane authorization uses its separate local RBAC model.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Crypto Service Release User only to the confidential workload identity and preferably on one exportable key. Verify the Microsoft Azure Attestation claims and release policy, monitor KeyRelease events, and remove the assignment when the confidential workload is decommissioned.

Editorial sources (7)

Official Microsoft Learn documentation →