Azure Key Vault is where applications store their passwords, connection strings, signing keys, and TLS certificates, so a vault you can read is a direct line into the environment's secrets. Access is governed either by legacy access policies or by Azure RBAC, both on the vault's data plane at https://<vault>.vault.azure.net; a managed-identity token for https://vault.azure.net or a user with a data-plane role reads it.
What folds in here#
- Secrets: listing and dumping stored secret values.
- Keys and certificates: extracting or using keys and downloading certificates with their private key.
- Access policy: granting yourself vault access when you hold management-plane rights but not data-plane.