The connection to data plane failed. Please refresh and try again.

Gomolemo 85 Reputation points
2025-10-09T11:52:15.24+00:00

Unable to access keyvault data plane when trying to access secrets, keys and certificate.

Using private endpoint, private link configured not sure why I cant access the data plane.

The connection to data plane failed. Please refresh and try again. If Private Links are enabled on the vault and the issue persists please follow the steps in the following link https://go.microsoft.com/fwlink/?linkid=2156688

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
{count} votes

3 answers

Sort by: Most helpful
  1. Alex Burlachenko 18,570 Reputation points Volunteer Moderator
    2025-10-09T12:55:59.1033333+00:00

    hi Gomolemo,

    you've set up the private link, but the data plane is still unreachable. this almost always comes down to a dns or network configuration problem.

    the error message is helpful because it points to the troubleshooting guide, but let's break down the most common culprits. check the dns resolution. the key vault's data plane url, like yourvault.vault.azure.net, must resolve to the private ip address of your private endpoint, not the public one. you can test this from a virtual machine inside your vnet using nslookup yourvault.vault.azure.net. if it returns a public ip, your private dns zone isn't linked correctly.

    verify the private dns zone. you should have a private dns zone named privatelink.vaultcore.azure.net that is linked to your virtual network. inside this zone, there should be an a record for your key vault name pointing to the private ip address.

    also, check the network security groups on your subnet. they must allow outbound traffic to the key vault's private ip on port 443. an overly restrictive nsg can block the connection even if the dns is correct.

    use nslookup to confirm your vault's name resolves to a private ip. if it doesn't, check your private dns zone configuration and its link to the vnet.

    regards,

    Alex

    and "yes" if you would follow me at Q&A - personaly thx.
    P.S. If my answer help to you, please Accept my answer
    

    https://ctrlaltdel.blog/


  2. Aditya N 945 Reputation points Microsoft External Staff Moderator
    2025-10-09T13:45:42.5266667+00:00

    Hello @Gomolemo Matsunyane

    Thank you for reaching out to Microsoft Q&A.

    I see your comment mentioning that you have requested your firewall team in order to set rules to allow onpremise network to access the keyvault on azure.

    Please reach out to us in case issue persists post checking with your firewall team. We're happy to help.


  3. Gomolemo 85 Reputation points
    2025-11-19T08:39:40.3866667+00:00

    Access to key vault was granted from on-premise. Issue has been resolved.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.