Your organization uses Azure DevOps and Azure Key Vault to manage secrets. You have a pipeline that deploys a web app to Azure App Service. The pipeline uses a variable group linked to Key Vault to retrieve the database connection string. Recently, the build started failing with the error: 'Access to Key Vault is denied. Please ensure the service connection has Get and List permissions on secrets.' The service connection uses a service principal. You have verified that the service principal has the correct Key Vault access policy with Get and List permissions. What is the most likely cause of the failure?
Trap 1: The service connection is configured to use the wrong Azure…
The subscription is used for targeting Azure resources, not for Key Vault access.
Trap 2: The secret name in the variable group does not match the secret…
A mismatch would cause 'secret not found', not 'access denied'.
Trap 3: The service principal used by the service connection does not have…
Key Vault uses access policies, not Azure RBAC (unless configured), and the error is about secrets, not the vault itself.
- A
The service connection is configured to use the wrong Azure subscription.
Why it fails: The subscription is used for targeting Azure resources, not for Key Vault access.
- B
The secret name in the variable group does not match the secret name in Key Vault.
Why it fails: A mismatch would cause 'secret not found', not 'access denied'.
- C
The service principal used by the service connection does not have Contributor role on the Key Vault.
Why it fails: Key Vault uses access policies, not Azure RBAC (unless configured), and the error is about secrets, not the vault itself.
- D
The build service identity does not have Get and List permissions on the Key Vault secrets.
The build service identity (project collection or project level) must be granted access to Key Vault for variable group resolution.