Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Page does not indicate if the other higher credentials roles can perform these actions. #122397

Open
mth11 opened this issue May 10, 2024 · 3 comments

Comments

@mth11
Copy link

mth11 commented May 10, 2024

It is unclear if Owner, or Global admin account can perform these actions. They are not listed in the table and it is not clear if they are able to handle the same key vault operations as the accounts that are listed in the table.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

@TPavanBalaji
Copy link

@mth11
Thanks for your feedback! We will investigate and update as appropriate.

@PesalaPavan PesalaPavan removed the cxp label May 15, 2024
@PesalaPavan
Copy link
Contributor

@mth11
Thanks for your feedback! I've assigned this issue to the author who will investigate and update as appropriate.

@jlichwa
Copy link
Contributor

jlichwa commented May 21, 2024

@mth11
These are specific data plane operations (secrets, certificates, keys), Owner, Contributor etc.. are for accessing management plane only and Global Admin is for managing Entra Id objects.

Those are all Roles provided by Key Vault team to manage secrets, certificates, keys.

Any team can create any role with any actions desired we will have no control of it. Not sure what is the scenario here with this question.

Please let us know if there is more clarification needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants