Failed to sync the certificate.: The service does not have access to '…vault' Key Vault

JRP_Mike 126 Reputation points
2021-03-15T18:38:15.857+00:00

This has been asked before but is apparently still an issue. I just renewed and validated my certificate and now it won't sync. How do I fix this? If I have to buy a new certificate as in the linked post, how do I get it paid for by MS?
(failed-to-sync-the-certificate-the-service-does-not-have-access-to-vault-key-vault

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,633 questions
0 comments No comments
{count} votes

Accepted answer
  1. JRP_Mike 126 Reputation points
    2021-03-16T18:05:27.09+00:00

    I was missing the "Key Vault" "Access Policy" for the Microsoft Azure App Service and Microsoft.Azure.CertificateRegistration. I added them as below and the cert synced. It still doesn't show up in the key vault.

    Check the required permissions on Key Vault: |Service Principal|Secret Permissions|Certificates| |--|--|--| |Microsoft Azure App Service|Get|Get| |Microsoft.Azure.CertificateRegistration|Get,List,Set,Delete|Get,List|


0 additional answers

Sort by: Most helpful