Azure Security built-in role

Key Vault Crypto User

Uses Key Vault keys for cryptographic operations. The published definition includes key read, update, backup, encrypt, decrypt, wrap, unwrap, sign, and verify DataActions, but not key creation, deletion, purge, rotation-policy management, or Azure RBAC permission management. It requires the Azure RBAC permission model.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 12338af0-0e69-4776-bea7-57ae8d297424

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (9)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the workload identity at the individual key or dedicated vault. Parent assignments are inherited by child vaults and keys. Use a separate vault per application and environment, and use object-level assignment only when the documented exception is preferable to a separate vault boundary.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Crypto User to the application managed identity at the key or dedicated vault scope only when its full published operation set is required. Use Crypto Service Encryption User for service-encryption metadata and wrap/unwrap operations, and Crypto Officer for approved key lifecycle administration.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →