Cosmos for Apache Cassandra Managed Instance

Leandro Chiesa 21 Reputation points
2026-09-17T13:57:14.8866667+00:00

Hi,

I'm deploying some Apache Cassandra Managed Instances and I was trying to configure CMK using RBAC Key Vaults, and I wasn't able to do it, I always get the error stating that the System Managed Identity needs get, wrap and unwrap permissions.

I've found the following MS doc (https://learn.microsoft.com/en-us/azure/managed-instance-apache-cassandra/customer-managed-keys) on how to set up CMK, but this guide shows using an Access Policy Key Vault method, I'd like a confirmation/statement that Cassandra Managed Instance currently supports only Access Policy Key Vaults and if so, is there a date for supporting RBAC Key Vaults?

Regards,

Leandro Chiesa

Azure Cosmos DB
Azure Cosmos DB

An Azure NoSQL database service for app development.

0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-09-17T13:57:29.4066667+00:00

    The available guidance for Azure Managed Instance for Apache Cassandra shows CMK setup with Azure Key Vault by using a secret and does not document Azure Key Vault RBAC as a supported authorization model for this service. The documented setup path is the Key Vault access policy model.

    The retrieved documentation also does not provide any statement or timeline for RBAC Key Vault support for Azure Managed Instance for Apache Cassandra.

    Supported facts from the documentation:

    1. Azure Managed Instance for Apache Cassandra supports customer-managed keys with Azure Key Vault.
    2. The documented implementation uses Azure Key Vault setup described through the access-policy-based flow.
    3. No published support statement or ETA for RBAC Key Vaults is present in the retrieved material.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.