2020-10-19 · With Azure role-based access control (RBAC) for Azure Key Vault on data plane, you can achieve unified management and access control across Azure Resources. With this capability, you can now manage RBAC for Key Vault keys, certificates, and secrets with roles assignment scope available from management group to individual key, certificate, and secret.



Key Vault-tjänsten bevarar hemligheter som krypteras med en HSM-skyddad nyckel och förser dem med ett lager för åtkomstkontroll. Förutom nycklar och hemligheter kan du också lagra och hantera SSL/TLS-certifikat som du har köpt från publika certifikatutfärdare, och automatiskt registrera eller förnya dem via Key Vault om den publika certifikatutfärdaren stöds av Key Vault. Azure Key Vault enables Azure subscribers to safeguard and control cryptographic keys and other secrets used by cloud apps and services. Encrypt keys and small secrets like passwords using keys in Hardware Security Modules (HSMs); Import or generate your keys in HSMs certified to FIPS 140-2 level 2 (vaults) and FIPS 140-2 level 3 (managed HSM pools) standards for added assurance, so that your keys remain within the HSM boundary. Author a deployment template to reference the secureStrings in the Key Vault. Note also, the user performing the deployment will need Read permissions to the secrets in the vault. So if you're using a service principal to deploy in an automated workflow, that service principal will need access to the secrets you want to use.