author | ms.service | ms.subservice | ms.topic | ms.date | ms.author |
---|---|---|---|---|---|
msmbaldwin |
key-vault |
B2C |
include |
07/20/2020 |
msmbaldwin |
Create an access policy for your key vault that grants permission to your service principal by passing clientId
to the az keyvault set-policy command. Give the service principal get, list, and set permissions for both keys and secrets.
az keyvault set-policy -n <your-unique-keyvault-name> --spn <clientId-of-your-service-principal> --secret-permissions delete get list set --key-permissions create decrypt delete encrypt get list unwrapKey wrapKey