This might be a silly question, but does the account running pulumi have the required rights? Either the correct IAM role (if using IAM, e.g. "Key Vault Secrets User") or a relevant access policy (e.g. "Secrets Management" - or the read-only version which I can't remember the name of).