Azure Key Vault中UAT订阅WebApp选择主体时未显示的问题咨询
It's frustrating when identical setup steps work smoothly in one subscription but hit a wall in another—let's break down the key rules and constraints that could be hiding your UAT WebApp from the principal selection list:
1. System-Assigned Managed Identity Isn't Enabled on the UAT WebApp
This is the most common culprit. When you select a WebApp in the Key Vault principal picker, you're actually targeting its system-assigned managed identity (an Azure AD service principal tied directly to the app).
- Check your UAT WebApp: Navigate to Identity > System assigned in the left menu. If the status is "Off", toggle it to "On" and wait 2-3 minutes for Azure AD to propagate the identity. Refresh the Key Vault access policy page and try searching again.
2. Insufficient Permissions to View Managed Identities in UAT
Your user account might lack the required permissions to read managed identities or service principals in the UAT subscription.
- Verify your role: Ensure you have at least the Reader role on the UAT subscription, or a custom role that includes these permissions:
Microsoft.Authorization/roleAssignments/readMicrosoft.ManagedIdentity/userAssignedIdentities/readMicrosoft.Web/sites/read
- If you're using a guest account, confirm it has directory-level permissions to view service principals (Azure AD > Users > Your account > Directory role assignments).
3. Tenant Mismatch Between Key Vault and WebApp
Even across separate subscriptions, the Key Vault and WebApp must belong to the same Azure AD tenant for the principal to be visible.
- Cross-check tenant IDs:
- Go to your UAT Key Vault > Overview > Note the "Tenant ID".
- Go to your UAT WebApp > Identity > System assigned > Note the "Tenant ID".
- If they don't match, you'll need to move either resource to the same tenant, or use a user-assigned managed identity from the correct tenant.
4. Azure AD Object Propagation Delay
Newly created or enabled managed identities can take a few minutes to sync across Azure AD. If you just turned on the identity for your UAT WebApp, wait 5-10 minutes, then clear your browser cache or use an incognito window to reload the Key Vault page.
5. Filter or Search Limitations in the Principal Picker
The default principal list only shows recently used objects—don't rely on scrolling.
- In the "Select a principal" window:
- Make sure the Applications dropdown is set to "All applications" (not a filtered subset like "APIM").
- Type the full name of your WebApp in the search box (case-insensitive works). Partial names can get missed if there are many objects in the tenant.
6. User-Assigned Managed Identity Confusion
If your Dev WebApp uses a user-assigned managed identity instead of system-assigned, you'll need to replicate that setup in UAT:
- Create a user-assigned identity in UAT, assign it to the WebApp, then search for the name of that identity (not the WebApp itself) in the Key Vault principal picker.
Start with checking the system-assigned managed identity status—it's the fastest fix in most cases. If that doesn't work, work through the permission and tenant checks next.
内容的提问来源于stack exchange,提问作者Manish Joisar

