Permissions
The Azure CIS v2.0.0 - Section 8 - Key Vault policy pack requires 4 permissions:
microsoft.keyvault/vaults/deletemicrosoft.keyvault/vaults/keys/update/actionmicrosoft.keyvault/vaults/secrets/update/actionmicrosoft.keyvault/vaults/write