Configure the Azure Key Vault provider
Step 2 of 5 in Connect Azure KMS with BYOK and BYOC.
Collect the HTTPS vault or Managed HSM URI, the Microsoft Entra tenant id, the workload client id and the Azure role assignments before starting. Wrong role assignments surface as a validation failure, not as a configuration error.
For a tenant-owned vault, create the resource with kind: AZURE_KEY_VAULT and the vault coordinates.
The response returns a handle, a resourceVersion and a credentialSecretRef.
Attach the Azure client secret against that handle and version. The secret is write-only and is stored in the tenant secret store; the value never travels back.
Validation proves the provider can reach the vault with the configured identity. Treat anything other than a successful validation as a stop.
For a platform-owned shared vault, the platform operator offers the provider and the tenant enables
it instead of creating a second resource. The operator either creates that provider through these
calls on the platform tenant or declares it in the deployment configuration, as described in
Cloud KMS providers. Sharing the provider does not share every key: each Azure
object a tenant may use must carry the tag sphereon-tenant-id=<tenant id>.
Next
Continue with step 3, Register an existing Azure key (BYOK).