You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ARM模板配置Key Vault权限报错:accessPolicies值无效及ObjectID异常

Fixing "An invalid value was provided for 'accessPolicies'" & ObjectID Retrieval Issue for Function App Key Vault Permissions

Let's break down and fix the issues you're facing step by step:

1. Correct the Managed Identity Resource ID Construction

Your identityResourceId variable has a small syntax error in the resourceId function - you added an extra trailing slash in the resource type. This leads to an invalid resource ID, which breaks the reference call later.

Fixed variable definition:

"variables": {
  "identityResourceId": "[concat(resourceId('Microsoft.Web/sites', variables('functionAppName')), '/providers/Microsoft.ManagedIdentity/Identities/default')]"
}

2. Update the Reference API Version

The 2015-08-31-PREVIEW API version is outdated for managed identities. Using a newer, stable version ensures you can reliably fetch the principalId.

Fixed outputs section:

"outputs": {
  "AppObjectId": {
    "type": "string",
    "value": "[reference(variables('identityResourceId'), '2018-11-30').principalId]"
  }
}

(You can also use newer versions like 2023-01-31 if preferred - just ensure it's compatible with your Azure resource provider version.)

3. Verify System-Assigned Identity is Enabled

Make sure your Function App has system-managed identity turned on in its resource definition. Without this, the managed identity resource won't exist, and you'll never get a valid principalId:

"resources": [
  {
    "type": "Microsoft.Web/sites",
    "name": "[variables('functionAppName')]",
    "apiVersion": "2022-09-01",
    "identity": {
      "type": "SystemAssigned" // This line enables the managed identity
    },
    // Rest of your Function App configuration...
  }
]

4. Ensure Deployment Order & Dependencies

To avoid race conditions where Key Vault tries to fetch the identity before the Function App is created, add a dependsOn clause in your Key Vault resource:

{
  "type": "Microsoft.KeyVault/vaults",
  "name": "[variables('keyVaultName')]",
  "apiVersion": "2023-02-01",
  "dependsOn": [
    "[resourceId('Microsoft.Web/sites', variables('functionAppName'))]" // Wait for Function App to deploy
  ],
  "properties": {
    "accessPolicies": [
      {
        "tenantId": "[subscription().tenantId]",
        "objectId": "[reference(variables('identityResourceId'), '2018-11-30').principalId]",
        "permissions": {
          "secrets": ["Get", "List"], // Adjust permissions to your needs
          "keys": [],
          "certificates": []
        }
      }
    ],
    // Rest of your Key Vault configuration...
  }
}

After applying these fixes, you should be able to retrieve the correct principalId and resolve the "invalid accessPolicies" error, since the Key Vault will now reference a valid identity object ID.

内容的提问来源于stack exchange,提问作者ssashok10

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:47:23