Cloud Build

Microsoft Azure, 365 and all things Tech

Skip to content
  • About Me
  • Terms
  • Privacy
  • Contact Me

unable to connect storage account using system assigned identity to a KeyVault

Azure Storage Account – Your system-assigned identity does not have access to the key vault

Posted on March 9, 2024 by Imran Rashid
Reading Time: 2 minutes


You want to change the encryption configuration for an Azure Storage account from Microsoft-managed key to Customer-managed key.


You click Customer-managed keys, you select a Key Vault and click Save


But you receive the below error,

Your system-assigned identity does not have access to the key vault. You can request access to the key vault by sending your admin the object ID from Identity under Security + networking when system-assigned status is enabled.

You have an issue, you can’t grant the storage account access to the KeyVault until a System Assigned Identity has been created, however, in this case we’re receiving an error that the Storage account does not have access to your Key Vault and therefore you need to grant access.

What you’ll find, that even though you receive the error above when clicking save, a system assigned Identity is created. So the process partially completes the setup but then errors, but the system assigned Identity is created.

  1. Go to your Key Vault
  2. Click Access Control (IAM) from the left pane if using RBAC and not access policies. If using the latter, click access policies from the left pane and configure your permissions accordingly.
  3. Click Add > Add Role Assignment
  4. Search for the role you wish to assign to the storage accounts system assigned Identity
  5. Click Next
  6. Click Managed Identity and +Select members


7. Click Next
8. From the Managed Identity drop down, select Storage Accounts and you should find your storage account System Assigned Identity listed

Hope this helps. See you at the next post.

Posted in Azure
Tagged how to assign system assigned identity to Azure Storage account storage account no system assigned Identity Unable to assign system assigned identity to a storage account unable to connect storage account using system assigned identity to a KeyVault unable to link customer managed key within azure storage account get the error Your system-assigned identity does not have access to the key vault
Leave a comment

Follow Me

  • LinkedIn
  • Bluesky
  • X
  • Meetup
  • GitHub
  • RSS Feed

Search

Subscribe

Keep up to date on the latest articles. We will never spam you or forward your details to third parties.

Name

Email


Recent Posts

  • Microsoft 365 Copilot Chat and Microsoft 365 Copilot Explained
  • Obtain Free Let’s Encrypt Certificates and Store Them in Azure Key Vault: A Step by Step Guide
  • Azure Traffic Manager 404 Web Site not found
  • Be Part of HISTORY – Earn Your Free AI Skills Badge Today!
  • Part 3 – Microsoft Purview Roles and Scopes
  • How to access Azure Cloud Shell locally
  • Microsoft Purview Portal – Part 2
  • Introduction to Microsoft Purview – Part 1
  • Microsoft announces FREE GitHub Copilot for VS Code
  • User Guide: How to register passkeys in Microsoft Authenticator and physical passkeys
  • The Evilginx Threat: Protecting Your Credentials with Phishing Resistant MFA
  • Part 1 – What is a FIDO2 key and How to Set One Up for Emergency Access in Entra ID
  • Part 2 – Configure a YubiKey For An Emergency Access Account In Entra ID
  • From Nerves to Confidence: My Transformation Journey
  • Part 4 – Free Version of Microsoft Copilot
  • Part 3 – How to write Microsoft Copilot Prompts
  • Part 2 – Microsoft 365 Copilot under the hood
  • Part 1 – Save time and be more productive at work with Microsoft 365 Copilot
  • Build your own copilot with Microsoft Copilot Studio
  • Integrate Defender for Endpoint with Defender for Cloud Apps
Azure community hero
Azure learner
Cloud champion
Top azure blogs

Certifications

  • azure-solutions-architect-expert-600×600
  • azure-security-engineer-associate600x600
  • azure-administrator-associate
  • NCDA-7-Mode_352x352
  • Designing+and+Deploying+Microsoft+Exchange+Server+2016-01
  • Microsoft_Exam533
  • Microsoft_Exam534
  • MCSA-Cloud-Platform-2018
  • azure-solutions-architect-expert-600×600
  • CERT-Associate-Microsoft365-Teams-Administrator
  • MS-100-exam
  • exam-ms100_1-600×600
  • microsoft365-enterprise-adminstrator-expert-600×600
  • microsoft365-messaging-administrator-associate-600×600
  • SCI_Challange_Complete_OpenHack_600X600
  • Microsoft Certified Trainer
  • MCT-2023-2024
  • azure-network-engineer-associate-600×600
  • sc-300
  • az-900
  • SC-900
  • AI-900
  • Microsoftaiskillsfestgwrattemptbadge[full]
Azure crazy logo
Bradcuglogo

RSS Feed

  • Twitter
  • linkedin

Cloud Build

© All rights reserved.

Powered by WordPress

Subscribe to new posts

Name

Email


Recent Posts

  • Microsoft 365 Copilot Chat and Microsoft 365 Copilot Explained
  • Obtain Free Let’s Encrypt Certificates and Store Them in Azure Key Vault: A Step by Step Guide
  • Azure Traffic Manager 404 Web Site not found

Archives

  • About Me
  • Contact Me
  • Privacy
  • Terms

Subscribe

Subscribe to new tech posts.
We will never send you spam email or forward your details to third parties.


Name

Email


This will close in 0 seconds

error: Content is protected !!