Key Vault Forbidden 🔷 Azure

Key Vault: (Forbidden) The user, group or application does not have secrets get permission on key vault

The caller authenticated but has no permission on the vault — missing access policy or RBAC role, or the vault’s firewall blocks it.

Seen on: Azure

Meaning

Vaults use either access policies or Azure RBAC (Key Vault Secrets User/Officer). Using the wrong model, granting on the wrong scope, or network rules (ForbiddenByFirewall) cause 403s.

Common causes

  • No access policy/RBAC role for the identity
  • Vault uses RBAC but access policy was added (or vice versa)
  • Key Vault firewall/private endpoint blocks the caller (ForbiddenByFirewall)
  • Wrong identity (system vs user-assigned)

⚡ Quick fix

  1. Grant Key Vault Secrets User (RBAC) or a Get/List access policy
  2. Check the vault’s permission model
  3. Allow the network or use a private endpoint

Detailed fix by platform

Azure CLI

  1. bash
    az keyvault show -n kv-app --query properties.enableRbacAuthorization
    az role assignment create --assignee <object-id> --role "Key Vault Secrets User" --scope $(az keyvault show -n kv-app --query id -o tsv)

How to diagnose

  1. Model — RBAC or access policies
  2. Identity — Object ID in the error
  3. Network — ForbiddenByFirewall?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.