An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
Hello Gaurav Sitaram Bansode
As discussed on teams
It assigned a management-plane role (Contributor/Reader) on the Key Vault resource, but viewing certificates is a data-plane operation—and that requires either:
- An Azure RBAC Key Vault Certificates Officer (or Certificate User/Reader) role on the vault, or
- A legacy Key Vault Access Policy granting your principal
get/listpermissions on certificates.
Here’s how to fix it:
- Go to your Key Vault in the portal and open Access Configuration.
- Make sure the Permission model is set to Azure role-based access control if you want to use RBAC.
- If it’s set to Vault access policy, you’ll need to use the Access policies blade instead.
- If using Azure RBAC: a. Open Access Control (IAM) → + Add → Add role assignment. b. Select Key Vault Certificates Officer (or Key Vault Certificate User if you only need read access). c. Assign it to your user or group at the vault scope.
- If using Access Policies (legacy): a. Open the Access policies blade → + Add Access Policy. b. Under Certificate Permissions, check List and Get. c. Choose your principal and hit Save.
- Wait ~5–10 minutes for the new permissions to propagate, then hit Refresh on the Certificates page—you should now see your certificates.
References: