Skip to content

Commit 987fba2

Browse files
authored
Update rbac-migration.md
1 parent dbe0b16 commit 987fba2

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

articles/key-vault/general/rbac-migration.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ Key Vault built-in roles for keys, certificates, and secrets access management:
2424
- Key Vault Administrator
2525
- Key Vault Reader
2626
- Key Vault Certificates Officer
27+
- Key Vault Certificate User
2728
- Key Vault Crypto Officer
2829
- Key Vault Crypto User
2930
- Key Vault Crypto Service Encryption User
@@ -65,7 +66,7 @@ Access policy predefined permission templates:
6566
| Azure Information BYOK | Keys: get, decrypt, sign | N/A<br>Custom role required|
6667

6768
> [!NOTE]
68-
> Azure App Service certificate configuration through Azure Portal does not support Key Vault RBAC permission model. You can use Azure PowerShell, Azure CLI, ARM template deployments with **Key Vault Secrets User** and **Key Vault Reader** role assignments for 'Microsoft Azure App Service' global indentity.
69+
> Azure App Service certificate configuration through Azure Portal does not support Key Vault RBAC permission model. You can use Azure PowerShell, Azure CLI, ARM template deployments with **Key Vault Certificate User** role assignments for 'Microsoft Azure App Service' global indentity.
6970
7071
## Assignment scopes mapping
7172

0 commit comments

Comments
 (0)