Ein Azure-Dienst, der eine ereignisgesteuerte serverlose Computeplattform bereitstellt
Welcome to Microsoft Q&A, and thank you for providing the detailed troubleshooting information.
The response you provided is a generic status indicating that the App Service platform was unable to resolve the Key Vault reference. By itself, it does not distinguish whether the failure is caused by the managed identity configuration, RBAC permissions, networking, or DNS resolution. Since all Key Vault references are failing, this typically points to an environmental or configuration issue rather than an individual secret.
Below are the recommended areas to verify.
1. Verify the User Assigned Managed Identity Configuration
By default, Azure Functions/App Service uses the System Assigned Managed Identity for Key Vault references unless you explicitly configure the app to use a User Assigned Managed Identity via the keyVaultReferenceIdentity property.
Verify that the Function App is configured to use the intended identity:
If the property is empty or references a different identity, update it to the resource ID of the correct User Assigned Managed Identity.
2. Verify Key Vault RBAC Permissions
If your Key Vault is configured to use Azure RBAC, ensure that the same User Assigned Managed Identity configured in keyVaultReferenceIdentity has been assigned the appropriate role, such as:
- Key Vault Secrets User (recommended for reading secrets)
- Key Vault Secrets Officer (if secret management is also required)
Also allow a few minutes for RBAC role assignments to propagate before testing again.
3. Verify Private Endpoint Connectivity and DNS
If the Key Vault is secured using a Private Endpoint, DNS resolution is one of the most common causes of Key Vault reference failures.
Verify that:
- The Function App resolves the Key Vault hostname to the private endpoint IP address.
- The Private DNS Zone (
privatelink.vaultcore.azure.net) is linked to the virtual network used by the Function App. - VNet integration is correctly configured and the Function App has outbound connectivity to the Key Vault.
For Linux Function Apps (except Flex Consumption) accessing a Key Vault through a private endpoint, also ensure that Route All is enabled:
If DNS resolution or routing is incorrect, all Key Vault references can fail with a generic "Reference was not able to be resolved" status.
4. Verify Key Vault Network Configuration
Review the Key Vault networking settings and confirm that:
- Public Network Access is configured as intended.
- If public access is disabled, the Function App can reach the Key Vault through the integrated virtual network.
- Network Security Groups (NSGs), Azure Firewall rules, or User Defined Routes (UDRs) are not blocking outbound traffic.
5. Review Key Vault and Function App Diagnostics
Review the following diagnostics for additional insight:
- Diagnose and Solve Problems for the Function App.
- Function App platform logs.
- Azure Activity Log.
- Key Vault diagnostic logs (if enabled).
The Key Vault logs can help distinguish the root cause:
- 403 (Forbidden) events typically indicate an RBAC or firewall/network access issue.
- No
SecretGetevents usually indicate that the Function App is unable to reach the Key Vault (for example, due to DNS or networking). - Successful
SecretGetevents with unresolved references may indicate an App Service/Functions configuration issue requiring further investigation.
6. Refresh Key Vault References
After making changes to the identity, RBAC assignments, or networking configuration, restart the Function App and refresh the Key Vault references:
This forces App Service to refresh the cached Key Vault reference values instead of waiting for the automatic refresh interval.
I hope this helps. Please let us know the results of the above checks, and we can assist further.