Skip to content
RTFE_
Error library
Key VaultKey VaultKnown error

Forbidden

Key Vault returned 403

Key Vault โ€” access denied

What the error looks like

  • Error code
  • WHO โ€” identity
  • WHAT โ€” action
  • WHERE โ€” scope
  • Policy
  • Correlation / trace
Status: 403HTTP (ForbiddenCODE)
ErrorCode: ForbiddenCODE

Content:
{"error":{"code":"ForbiddenCODE","message":"Caller is not authorized to perform action on resource.\r\nIf role assignments, deny assignments or role definitions were changed recently, please observe propagation time.\r\nCaller: appid=c3d4e5f6-0000-4000-8000-000000000003WHO;oid=d4e5f6a7-0000-4000-8000-000000000004WHO;iss=https://sts.windows.net/99999999-8888-4777-8666-555555555555TENANT/\r\nAction: 'Microsoft.KeyVault/vaults/secrets/getSecret/actionWHAT'\r\nResource: '/subscriptions/00000000-1111-4222-8333-444444444444/resourcegroups/rg-sec/providers/microsoft.keyvault/vaults/kv-prod-001/secrets/sql-passwordWHERE'\r\nAssignment: (not found)\r\nVault: kv-prod-001;location=westeurope\r\n","innererror":{"code":"ForbiddenByRbacCODE"}}}

What you told me

โ€œKey Vault lost my secret.โ€

you ยท just now

Let's read it.

RTFE ยท seen

What it actually says

The secret is fine. The caller was refused. The inner error code tells you which gate refused it: RBAC, access policy, Azure Policy, or the network firewall.

Azure outage? No. Key Vault is guarding the secret, as configured.

Which gate refused you?

ForbiddenByRbac

Vault uses Azure RBAC and the caller has no data-plane role.

โ†’ Assign e.g. Key Vault Secrets User on the vault (or secret).

ForbiddenByPolicy

Vault uses access policies and the caller has none (or lacks the permission).

โ†’ Add an access policy with the needed secret permissions โ€” or migrate to RBAC.

ForbiddenByFirewall

The request came from an IP/network not allowed by the vault firewall.

โ†’ Allow the network, use a private endpoint, or run from an allowed agent.

ForbiddenByConnection

Public network access is disabled.

โ†’ Connect through the private endpoint / VNet integration.

The fix

  1. 01Find the inner error code (innererror.code).
  2. 02Use the table: it decides whether this is an identity problem or a network problem.
  3. 03Note the appid / oid in the 'Caller' line โ€” that is WHO.
Azure CLI โ€” RBAC vault
az role assignment create \
  --assignee-object-id <object-id> \
  --assignee-principal-type ServicePrincipal \
  --role "Key Vault Secrets User" \
  --scope <key-vault-resource-id>

Read it faster next time

Owner on the subscription does not give you secret read on an RBAC vault. Data plane is separate.

Further reading

Open Microsoft Learn

Related errors