Unable to View Certificates on Key Vault with Permissions added

Gaurav Sitaram Bansode 40 Reputation points Microsoft Employee
2026-06-03T01:49:36+00:00

User's image

Here I see that I have access, but when I try to view the certificates I see below error.User's image

It has been long time since the access was granted.

Azure Key Vault
Azure Key Vault

An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.


Answer accepted by question author
Shubham Sharma 17,930 Reputation points Microsoft External Staff Moderator
2026-06-04T05:40:26.2133333+00:00

Hello Gaurav Sitaram Bansode

As discussed on teams

It assigned a management-plane role (Contributor/Reader) on the Key Vault resource, but viewing certificates is a data-plane operation—and that requires either:

  1. An Azure RBAC Key Vault Certificates Officer (or Certificate User/Reader) role on the vault, or
  2. A legacy Key Vault Access Policy granting your principal get/list permissions on certificates.

Here’s how to fix it:

  1. Go to your Key Vault in the portal and open Access Configuration.
    • Make sure the Permission model is set to Azure role-based access control if you want to use RBAC.
    • If it’s set to Vault access policy, you’ll need to use the Access policies blade instead.
  2. If using Azure RBAC: a. Open Access Control (IAM) → + Add → Add role assignment. b. Select Key Vault Certificates Officer (or Key Vault Certificate User if you only need read access). c. Assign it to your user or group at the vault scope.
  3. If using Access Policies (legacy): a. Open the Access policies blade → + Add Access Policy. b. Under Certificate Permissions, check List and Get. c. Choose your principal and hit Save.
  4. Wait ~5–10 minutes for the new permissions to propagate, then hit Refresh on the Certificates page—you should now see your certificates.

References:

https://learn.microsoft.com/azure/key-vault/certificates/certificate-access-control?wt.mc_id=knowledgesearch_inproduct_azure-cxp-community-insider#grant-access-to-certificates

https://learn.microsoft.com/azure/key-vault/general/rbac-guide?wt.mc_id=knowledgesearch_inproduct_azure-cxp-community-insider#azure-built-in-roles-for-key-vault-data-plane-operations

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

Answer accepted by question author
Keerthana PK 250 Reputation points Microsoft Employee
2026-06-03T05:32:18.8433333+00:00

Hi Gaurav,

Thank you for asking this question on the Microsoft Q&A Platform. Contributor or reader access will not grant permission to access key vault secrets certificates or keys.

Key Vault Certificates Officer

Read/list certificates

Create/import/update/delete certificates

Scope:

Key Vault level


Key Vault Certificate User

Read/list certificates and public portions

Cannot:

Manage or modify certificates

Scope:

Key Vault level


If you want to manage other key vault components like keys and secrets as well then go for Key vault administrator role.

This role can:

  • Create/read/update/delete:
    • Secrets
    • Keys
    • Certificates
    • Backup/restore/recover vault objects
  • Manage certificate policies

https://learn.microsoft.com/en-us/azure/key-vault/certificates/certificate-access-control

https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide?tabs=azure-cli

Please Accept the answer if the information helped you. This will help us and others in the community as well!!!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.