Forbidden
Key Vault returned 403
Key Vault โ access denied
What the error looks like
- Error code
- WHO โ identity
- WHAT โ action
- WHERE โ scope
- Policy
- Correlation / trace
Status: 403HTTP (ForbiddenCODE)
ErrorCode: ForbiddenCODE
Content:
{"error":{"code":"ForbiddenCODE","message":"Caller is not authorized to perform action on resource.\r\nIf role assignments, deny assignments or role definitions were changed recently, please observe propagation time.\r\nCaller: appid=c3d4e5f6-0000-4000-8000-000000000003WHO;oid=d4e5f6a7-0000-4000-8000-000000000004WHO;iss=https://sts.windows.net/99999999-8888-4777-8666-555555555555TENANT/\r\nAction: 'Microsoft.KeyVault/vaults/secrets/getSecret/actionWHAT'\r\nResource: '/subscriptions/00000000-1111-4222-8333-444444444444/resourcegroups/rg-sec/providers/microsoft.keyvault/vaults/kv-prod-001/secrets/sql-passwordWHERE'\r\nAssignment: (not found)\r\nVault: kv-prod-001;location=westeurope\r\n","innererror":{"code":"ForbiddenByRbacCODE"}}}What you told me
โKey Vault lost my secret.โ
you ยท just now
Let's read it.
RTFE ยท seen
What it actually says
The secret is fine. The caller was refused. The inner error code tells you which gate refused it: RBAC, access policy, Azure Policy, or the network firewall.
Azure outage? No. Key Vault is guarding the secret, as configured.
Which gate refused you?
ForbiddenByRbacVault uses Azure RBAC and the caller has no data-plane role.
โ Assign e.g. Key Vault Secrets User on the vault (or secret).
ForbiddenByPolicyVault uses access policies and the caller has none (or lacks the permission).
โ Add an access policy with the needed secret permissions โ or migrate to RBAC.
ForbiddenByFirewallThe request came from an IP/network not allowed by the vault firewall.
โ Allow the network, use a private endpoint, or run from an allowed agent.
ForbiddenByConnectionPublic network access is disabled.
โ Connect through the private endpoint / VNet integration.
The fix
- 01Find the inner error code (innererror.code).
- 02Use the table: it decides whether this is an identity problem or a network problem.
- 03Note the appid / oid in the 'Caller' line โ that is WHO.
az role assignment create \
--assignee-object-id <object-id> \
--assignee-principal-type ServicePrincipal \
--role "Key Vault Secrets User" \
--scope <key-vault-resource-id>Read it faster next time
Owner on the subscription does not give you secret read on an RBAC vault. Data plane is separate.