Azure Security built-in role

Key Vault Data Access Administrator

Creates and deletes Azure RBAC role assignments for a fixed set of eight Key Vault data-plane roles. The built-in role definition includes an ABAC condition that limits which role definition IDs can be assigned or removed. It has no DataActions and does not itself read keys, secrets, or certificates, but it can create and manage deployments and support tickets.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8b54135c-b56d-4d72-a534-26097cfdc8d8

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign at the individual vault whenever possible. The delegation applies at the selected Azure scope and inherited child scopes, so a resource-group or subscription assignment can administer Key Vault data access for every child vault and also create deployments and support tickets across that scope. The built-in condition limits role types but does not replace narrow assignment scope or principal governance.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Data Access Administrator on the individual vault to a dedicated access administrator. Verify that every needed delegated role is in the built-in eight-role allowlist, retain the condition, audit assignment changes, and use broader Owner or User Access Administrator authority only when this conditioned role cannot perform the required task.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →