Key Vault: (Forbidden) The user, group or application does not have secrets get permission on key vault
The caller authenticated but has no permission on the vault — missing access policy or RBAC role, or the vault’s firewall blocks it.
Seen on:
Azure
Meaning
Vaults use either access policies or Azure RBAC (Key Vault Secrets User/Officer). Using the wrong model, granting on the wrong scope, or network rules (ForbiddenByFirewall) cause 403s.
Common causes
- No access policy/RBAC role for the identity
- Vault uses RBAC but access policy was added (or vice versa)
- Key Vault firewall/private endpoint blocks the caller (ForbiddenByFirewall)
- Wrong identity (system vs user-assigned)
⚡ Quick fix
- Grant Key Vault Secrets User (RBAC) or a Get/List access policy
- Check the vault’s permission model
- Allow the network or use a private endpoint
Detailed fix by platform
Azure CLI
- bash
az keyvault show -n kv-app --query properties.enableRbacAuthorization az role assignment create --assignee <object-id> --role "Key Vault Secrets User" --scope $(az keyvault show -n kv-app --query id -o tsv)
How to diagnose
- Model — RBAC or access policies
- Identity — Object ID in the error
- Network — ForbiddenByFirewall?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026