Scenario 1
If you have added the VNet and Subnet of the Application Gateway to the Key Vault firewall settings, the Application Gateway can access Key Vault by enabling the Allow Trusted Services option.
If a service is not on the trusted list, it will be denied access to Key Vault regardless of whether the "Allow trusted Microsoft services" option is enabled or not. This is because the "Trusted Services" setting does not impact untrusted services.
Scenario 2
If the service is not on the Trusted Services list, enabling the "Allow Trusted Services" option will not grant the access. In this case, you need to enable a Private Endpoint for private connectivity.
I hope this helps to resolve your issue.
Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.