Azure Security built-in role

Key Vault Secrets Officer

Performs all Key Vault secret data-plane operations, including reading, creating, updating, deleting, recovering, backing up, restoring, and purging secrets, but cannot manage Azure RBAC permissions. Its control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. It works only with vaults using the Azure RBAC permission model.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b86a8fe4-44ce-4948-aee5-eccb2c155cd7

Control-plane actions (10)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the individual vault whose secret lifecycle the principal administers. Parent-scope assignments are inherited by child vaults and extend the ancillary alert-rule, deployment, and support Actions across the parent scope. Individual-secret assignment is supported only for limited exceptions; Microsoft recommends separate vaults per application and environment for ordinary isolation.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Key Vault Secrets Officer to the credential-lifecycle team at the individual vault scope, preferably as eligible human access. Use Secrets User for runtime retrieval, keep role delegation separate, and require review for backup, restore, deletion, or purge operations.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →