I want to lock down my Key Vault as securely as possible. I believe access control is who can access and modify the Key Vault as a whole. Access policies are who or what can access secrets.
Our admin group should be in the access control group. Our App Service (which has a managed identity) should be in access policies. I don't think there is any need for anymore than this?