Key Vault public access and trusted Microsoft services

Andre Kanyinda 20 Reputation points
2026-10-08T15:02:54.2266667+00:00

Hi

If I disable public access when creating a key, the allow trusted Microsoft services box is disabled.

User's image

It only appears if I enable public access, then restrict it to selected networks. User's image

If I disable public access once the key vault is created, I get the option to allow trusted Microsoft services. Is this by design or a bug? Or am I not understanding the options properly?

User's image

Azure Key Vault
Azure Key Vault

An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.

0 comments No comments

Answer accepted by question author
TP 164.4K Reputation points Volunteer Moderator
2026-10-08T22:19:13.44+00:00

Hi Andre,

This is limitation of the Create Key Vault wizard. Once your key vault exists, you may navigate to Settings -- Networking and select Allow trusted Microsoft services to bypass this firewall. Please see screenshot:

User's image

Additionally, below is excerpt from documentation specifically mentioning that you can allow trusted services even with public access disabled:

...

The bypass continues to apply to trusted services when you set publicNetworkAccess to Disabled; those services don't require a private endpoint to reach the vault. However, when public network access is set to Secure by perimeter (via association with a Network Security Perimeter, the bypass is overridden and even trusted services are blocked unless an explicit perimeter access rule admits them.

Thanks.

-TP

Was this answer helpful?

1 person found this answer helpful.

Answer accepted by question author

AI answer

2026-10-08T15:03:09.2066667+00:00

Yes, this is by design.

For Azure Key Vault, the Allow trusted Microsoft services to bypass this firewall option is a firewall setting. During creation, if public access is disabled, there is no public firewall configuration to edit in that create experience, so that checkbox is not shown there.

After the vault is created, when public network access is set to Disabled, trusted services bypass can still apply. Microsoft documents that:

  • when public access is disabled, trusted services continue to reach the vault and do not require a private endpoint
  • services not on the trusted services list are still blocked
  • if the vault is associated with a Network Security Perimeter and public access is set to Secure by perimeter, that perimeter overrides the bypass unless an explicit perimeter rule allows access

So the behavior shown is consistent with the product model:

  1. At creation time: disabling public access hides the firewall exception option in that UI flow.
  2. After creation: disabling public access can still coexist with trusted Microsoft services bypass.

There is also a Microsoft Q&A example showing that if the portal blocks saving both changes together, the working sequence is:

  1. Set Public network access to Disable and save.
  2. Reopen Networking.
  3. Enable Allow trusted Microsoft services to access this resource and save.

That matches the behavior shown in the screenshots.


AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.