Azure Function App Key Vault References Not Resolving ("Reference was not able to be resolved") Using User Assigned Managed Identity

Abdulfattah, Moustafa 0 Zuverlässigkeitspunkte
2026-07-23T21:16:14.62+00:00

I'm troubleshooting an Azure Function App that cannot resolve any Key Vault references from application settings.

Environment:

  • Azure Function App
  • User Assigned Managed Identity
  • Azure Key Vault
  • VNet integration enabled on the Function App
  • Key Vault access via RBAC

Symptoms:

The Function App starts, but all Key Vault references fail to resolve.

When I refresh the config references using:

az rest --method post \

--url "https://management.azure.com/<site-id>/config/configreferences/appsettings/refresh?api-version=2022-03-01"

I receive results similar to:

{

"details": "Reference was not able to be resolved.",

"identityType": "UserAssigned",

"status": "OtherReasons"

}

This occurs for every Key Vault reference, for example:

  • @Microsoft.KeyVault(SecretUri=https://<vault>.vault.azure.net/secrets/...)
  • @Microsoft.KeyVault(VaultName=<vault>;SecretName=<secret>)

Troubleshooting performed:

  1. Verified the Function App is configured to use a User Assigned Managed Identity.
  2. Restarted the Function App.
  3. Triggered a Key Vault reference refresh.
  4. Confirmed that all Key Vault references fail, not only a single secret.
  5. Verified the Function App is integrated with a VNet.
  6. Checked Key Vault RBAC assignments (still validating that the configured identity matches the identity that has access).

Questions:

  1. Does the "status": "OtherReasons" message indicate an identity/RBAC issue or a network/DNS issue?
  2. If the Key Vault is behind a Private Endpoint, can DNS resolution problems cause all references to return "Reference was not able to be resolved"?
  3. Are there additional diagnostics recommended to determine whether the failure is caused by:
  • User Assigned Managed Identity configuration
  • Key Vault RBAC permissions
  • Private Endpoint connectivity
  • DNS resolution from the Function App

Any guidance would be appreciated.

Azure-Funktionen
Azure-Funktionen

Ein Azure-Dienst, der eine ereignisgesteuerte serverlose Computeplattform bereitstellt


1 Antwort

Sortieren nach: Älteste
  1. Likhitha Sulake 105 Zuverlässigkeitspunkte Externe Microsoft-Mitarbeiter Moderator
    2026-07-24T11:31:27.5866667+00:00

    Hi @Abdulfattah, Moustafa ,

    Welcome to Microsoft Q&A, and thank you for providing the detailed troubleshooting information.

    The response you provided is a generic status indicating that the App Service platform was unable to resolve the Key Vault reference. By itself, it does not distinguish whether the failure is caused by the managed identity configuration, RBAC permissions, networking, or DNS resolution. Since all Key Vault references are failing, this typically points to an environmental or configuration issue rather than an individual secret.

    Below are the recommended areas to verify.

    1. Verify the User Assigned Managed Identity Configuration

    By default, Azure Functions/App Service uses the System Assigned Managed Identity for Key Vault references unless you explicitly configure the app to use a User Assigned Managed Identity via the keyVaultReferenceIdentity property.

    Verify that the Function App is configured to use the intended identity:

    
    

    If the property is empty or references a different identity, update it to the resource ID of the correct User Assigned Managed Identity.

    
    

    2. Verify Key Vault RBAC Permissions

    If your Key Vault is configured to use Azure RBAC, ensure that the same User Assigned Managed Identity configured in keyVaultReferenceIdentity has been assigned the appropriate role, such as:

    • Key Vault Secrets User (recommended for reading secrets)
    • Key Vault Secrets Officer (if secret management is also required)

    Also allow a few minutes for RBAC role assignments to propagate before testing again.


    3. Verify Private Endpoint Connectivity and DNS

    If the Key Vault is secured using a Private Endpoint, DNS resolution is one of the most common causes of Key Vault reference failures.

    Verify that:

    • The Function App resolves the Key Vault hostname to the private endpoint IP address.
    • The Private DNS Zone (privatelink.vaultcore.azure.net) is linked to the virtual network used by the Function App.
    • VNet integration is correctly configured and the Function App has outbound connectivity to the Key Vault.

    For Linux Function Apps (except Flex Consumption) accessing a Key Vault through a private endpoint, also ensure that Route All is enabled:

    
    

    If DNS resolution or routing is incorrect, all Key Vault references can fail with a generic "Reference was not able to be resolved" status.


    4. Verify Key Vault Network Configuration

    Review the Key Vault networking settings and confirm that:

    • Public Network Access is configured as intended.
    • If public access is disabled, the Function App can reach the Key Vault through the integrated virtual network.
    • Network Security Groups (NSGs), Azure Firewall rules, or User Defined Routes (UDRs) are not blocking outbound traffic.

    5. Review Key Vault and Function App Diagnostics

    Review the following diagnostics for additional insight:

    • Diagnose and Solve Problems for the Function App.
    • Function App platform logs.
    • Azure Activity Log.
    • Key Vault diagnostic logs (if enabled).

    The Key Vault logs can help distinguish the root cause:

    • 403 (Forbidden) events typically indicate an RBAC or firewall/network access issue.
    • No SecretGet events usually indicate that the Function App is unable to reach the Key Vault (for example, due to DNS or networking).
    • Successful SecretGet events with unresolved references may indicate an App Service/Functions configuration issue requiring further investigation.

    6. Refresh Key Vault References

    After making changes to the identity, RBAC assignments, or networking configuration, restart the Function App and refresh the Key Vault references:

    
    

    This forces App Service to refresh the cached Key Vault reference values instead of waiting for the automatic refresh interval.

    I hope this helps. Please let us know the results of the above checks, and we can assist further.

    War diese Antwort hilfreich?

    0 Kommentare Keine Kommentare

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.