Error while creating the storage account

Hanamant S Malakagond 41 Reputation points

I have existing Subscription(AAA) ,Keyvault(BBB) - created new KEY (CCC) for keyvault BBB .
I have created managed identity(DDD) and assigned Owner role for subscription(AAA) and administrative privilege's to the keyvault(BBB).
I am creating new storage account with Encryption type as "Customer-Managed keys(CMK)"& selected keyvault BBB & key CCC for "Keyvault and key" option & selected Managed identity (DDD) for user assigned identity.
When I click on create i am getting "The operation failed because of authentication issue on the keyvault" error message anything missing here ?

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,184 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,913 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sumarigo-MSFT 45,406 Reputation points Microsoft Employee

    @Hanamant S Malakagond Welcome to Microsoft Q&A Forum, Thank you for posting your query here.

    For better understanding the issue: can you please provide the more information on your query.

    • Can you please share the screenshot of the error message?
    • I assume you are creating the azure storage account through Portal am correct? (ARM, Powershell, CLI and more)?
    • Can you also check have provided Azure Storage contributor role access in Access control (I AM) *([Key vault]1 )

    Please refer to this thread, which provides some idea on your query

    How-to use customer-managed keys with Azure Key Vault and Azure Storage encryption using ARM Template

    Key Vault :RBAC permission model will not work with CMK for storage account encryption. The recommendation is to make use of the Access Policies permission model

    Looking forward for your reply

    Please do not forget to 200693-screenshot-2021-12-10-121802.png and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.