[KeyVault] Fix az keyvault role assignment create/list AccessDenied when caller lacks root-scope permissions#33465
Draft
Copilot wants to merge 2 commits into
Draft
[KeyVault] Fix az keyvault role assignment create/list AccessDenied when caller lacks root-scope permissions#33465Copilot wants to merge 2 commits into
az keyvault role assignment create/list AccessDenied when caller lacks root-scope permissions#33465Copilot wants to merge 2 commits into
Conversation
❌AzureCLI-FullTest
|
️✔️AzureCLI-BreakingChangeTest
|
Copilot
AI
changed the title
[WIP] Fix az cli access denial for RBAC assignment
[KeyVault] Fix May 28, 2026
az keyvault role assignment create/list AccessDenied when caller lacks root-scope permissions
Collaborator
|
KeyVault |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related command
az keyvault role assignment create/az keyvault role assignment listDescription
When a principal holds a Managed HSM role scoped to a specific key (e.g.,
/keys/my-key) rather than root/,az keyvault role assignment create --scope /keys/my-keyfails with:Root cause: After creating/listing role assignments, both
create_role_assignmentandlist_role_assignmentscalledlist_role_definitions(client)with no scope, which defaults to root (''). This forces a read at/regardless of the requested scope.Fix: Pass the operation's scope through to
list_role_definitions:create_role_assignment:list_role_definitions(client)→list_role_definitions(client, scope=scope)list_role_assignments:list_role_definitions(client)→list_role_definitions(client, scope=query_scope)Role definitions are HSM-wide and are returned for any scope the caller can read, so scoping this call to the requested scope is both correct and sufficient.
Testing Guide
History Notes
[KeyVault]
az keyvault role assignment create: Fix AccessDenied error when creating role assignments with a key-scoped--scopeusing a principal that lacks root-level read permissionsThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.