Mods
Azure

IAM Role: Azure/Key Vault/operator

PermissionGrant
microsoft.keyvault/hsmpools/joinvault/actionoperator
microsoft.keyvault/locations/deletedvaults/purge/actionoperator
microsoft.keyvault/register/actionoperator
microsoft.keyvault/unregister/actionoperator
microsoft.keyvault/vaults/deploy/actionoperator
microsoft.keyvault/checknameavailability/readmetadata
microsoft.keyvault/deletedvaults/readmetadata
microsoft.keyvault/hsmpools/readmetadata
microsoft.keyvault/locations/deletedvaults/readmetadata
microsoft.keyvault/locations/operationresults/readmetadata
microsoft.keyvault/operations/readmetadata
microsoft.keyvault/vaults/eventgridfilters/readmetadata
microsoft.keyvault/vaults/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.keyvault/vaults/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.keyvault/vaults/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.keyvault/vaults/readmetadata
microsoft.keyvault/vaults/secrets/readmetadata
microsoft.resources/deployments/operations/readmetadata
microsoft.resources/deployments/readmetadata
microsoft.resources/subscriptions/resourcegroups/readmetadata