Azure Key Vault not allow to add Secrets from azure portal while in a private endpoint connection

Viewed 715

I've an azure key vault that has configured with a private endpoint in virtual network. After configuring the private endpoint, I'm not able to add any new secrets to the key vault.

Is there a way to add/edit secrets from azure portal in a key vault while it is configured with a private endpoint.

Note: I know that we can access the key vault from a virtual machine within same virtual network and add/edit secrets in the key vault.

2 Answers

There are 2 ways I can think of to get this done.

  1. As a stop gap hack , you can add your current IP as client to the key-vault , when private endpoints are enabled .Go to Key-vault networking-->firewall and vnet--> selected network-->add client IP of your machine

  2. Second way is to have Express Route connectivity to your on-premise corporate network into the private endpoint VNET (or VNet peering if you have VM in cloud). Recommendation is to use hub-spoke topology for network. Please refer below link.

Hub-spoke network topology in Azure

Related