Bird
Raised Fist0
Azurecloud~5 mins

Key Vault creation in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Sometimes you need a safe place to store secrets like passwords or keys so only authorized apps or people can use them. Azure Key Vault is a service that helps you keep these secrets safe and easy to manage.
When you want to store database passwords securely instead of hardcoding them in your app.
When you need to manage encryption keys for your cloud applications.
When you want to control access to sensitive information with strict permissions.
When you want to audit who accessed your secrets and when.
When you want to centralize secret management for multiple applications.
Config File - main.tf
main.tf
provider "azurerm" {
  features {}
}

resource "azurerm_resource_group" "example" {
  name     = "example-resources"
  location = "eastus"
}

resource "azurerm_key_vault" "example" {
  name                        = "examplekeyvault12345"
  location                    = azurerm_resource_group.example.location
  resource_group_name         = azurerm_resource_group.example.name
  tenant_id                   = "00000000-0000-0000-0000-000000000000"
  sku_name                    = "standard"
  soft_delete_enabled         = true
  purge_protection_enabled    = false

  access_policy {
    tenant_id = "00000000-0000-0000-0000-000000000000"
    object_id = "11111111-1111-1111-1111-111111111111"

    secret_permissions = [
      "get",
      "list",
      "set"
    ]
  }
}

This Terraform file creates an Azure resource group and a Key Vault inside it.

provider: sets up Azure provider.

resource_group: creates a group to hold resources.

key_vault: creates the Key Vault with a unique name, location, and access policies.

tenant_id and object_id specify who can access the vault.

sku_name sets the pricing tier.

soft_delete_enabled keeps deleted vaults recoverable for safety.

Commands
This command initializes Terraform, downloads the Azure provider plugin, and prepares the working directory.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding latest version of hashicorp/azurerm... - Installing hashicorp/azurerm v3.64.0... - Installed hashicorp/azurerm v3.64.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure. All Terraform commands should now work.
This command shows what Terraform will create or change in Azure before applying it.
Terminal
terraform plan
Expected OutputExpected
An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # azurerm_resource_group.example will be created + resource "azurerm_resource_group" "example" { + id = (known after apply) + location = "eastus" + name = "example-resources" } # azurerm_key_vault.example will be created + resource "azurerm_key_vault" "example" { + id = (known after apply) + location = "eastus" + name = "examplekeyvault12345" + resource_group_name = "example-resources" + sku_name = "standard" + soft_delete_enabled = true + tenant_id = "00000000-0000-0000-0000-000000000000" + purge_protection_enabled = false + access_policy = [ + { + object_id = "11111111-1111-1111-1111-111111111111" + secret_permissions = ["get", "list", "set"] + tenant_id = "00000000-0000-0000-0000-000000000000" }, ] } Plan: 2 to add, 0 to change, 0 to destroy. ───────────────────────────────────────────────────────────────────────────── Note: You didn't specify an "-out" parameter to save this plan, so Terraform can't guarantee that exactly these actions will be performed if "terraform apply" is subsequently run.
This command applies the planned changes and creates the resource group and Key Vault in Azure automatically without asking for confirmation.
Terminal
terraform apply -auto-approve
Expected OutputExpected
azurerm_resource_group.example: Creating... azurerm_resource_group.example: Creation complete after 2s [id=/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-resources] azurerm_key_vault.example: Creating... azurerm_key_vault.example: Creation complete after 15s [id=/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-resources/providers/Microsoft.KeyVault/vaults/examplekeyvault12345] Apply complete! Resources: 2 added, 0 changed, 0 destroyed.
→
-auto-approve - Skips manual approval to apply changes immediately
This Azure CLI command retrieves details about the created Key Vault to verify it exists and check its properties.
Terminal
az keyvault show --name examplekeyvault12345 --resource-group example-resources
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-resources/providers/Microsoft.KeyVault/vaults/examplekeyvault12345", "location": "eastus", "name": "examplekeyvault12345", "properties": { "sku": { "family": "A", "name": "standard" }, "tenantId": "00000000-0000-0000-0000-000000000000", "accessPolicies": [ { "tenantId": "00000000-0000-0000-0000-000000000000", "objectId": "11111111-1111-1111-1111-111111111111", "permissions": { "secrets": [ "get", "list", "set" ] } } ], "enabledForDeployment": false, "enabledForDiskEncryption": false, "enabledForTemplateDeployment": false }, "resourceGroup": "example-resources", "type": "Microsoft.KeyVault/vaults" }
→
--name - Specifies the Key Vault name to show
→
--resource-group - Specifies the resource group where the Key Vault is located
Key Concept

If you remember nothing else from this pattern, remember: Azure Key Vault securely stores secrets and you create it by defining its settings and access rules, then applying them to your cloud environment.

Common Mistakes
Using a Key Vault name that is not globally unique.
Azure requires Key Vault names to be unique across all subscriptions, so creation fails if the name is taken.
Choose a unique name by adding random numbers or your company prefix.
Not specifying the correct tenant_id or object_id in access policies.
Without correct IDs, no one can access the secrets, making the vault unusable.
Use Azure CLI or portal to find your tenant and object IDs and set them properly.
Skipping terraform init before terraform apply.
Terraform won't have the Azure provider plugin ready, causing errors.
Always run terraform init first to prepare the environment.
Summary
Write a Terraform file to define an Azure resource group and a Key Vault with access policies.
Run 'terraform init' to prepare Terraform and download providers.
Use 'terraform plan' to preview changes and 'terraform apply -auto-approve' to create the Key Vault.
Verify the Key Vault creation with Azure CLI using 'az keyvault show'.

Practice

(1/5)
1. What is the primary purpose of an Azure Key Vault?
easy
A. To host virtual machines
B. To manage Azure subscriptions
C. To securely store secrets, keys, and certificates
D. To monitor network traffic

Solution

  1. Step 1: Understand Azure Key Vault's role

    Azure Key Vault is designed to securely store sensitive information like secrets, keys, and certificates.
  2. Step 2: Compare with other Azure services

    Hosting VMs, managing subscriptions, and monitoring traffic are done by other Azure services, not Key Vault.
  3. Final Answer:

    To securely store secrets, keys, and certificates -> Option C
  4. Quick Check:

    Key Vault = Secure storage for secrets [OK]
Hint: Key Vault is for secrets and keys storage only [OK]
Common Mistakes:
  • Confusing Key Vault with VM hosting
  • Thinking Key Vault manages subscriptions
  • Assuming Key Vault monitors network
2. Which Azure CLI command correctly creates a Key Vault named myVault in the resource group myResourceGroup located in eastus?
easy
A. az keyvault create --name myVault --resource-group myResourceGroup --location eastus
B. az keyvault new --vault-name myVault --group myResourceGroup --region eastus
C. az vault create --name myVault --resource-group myResourceGroup --location eastus
D. az keyvault create --vault myVault --resource myResourceGroup --location eastus

Solution

  1. Step 1: Identify correct Azure CLI syntax

    The correct command uses az keyvault create with parameters --name, --resource-group, and --location.
  2. Step 2: Check each option's parameters

    az keyvault create --name myVault --resource-group myResourceGroup --location eastus matches the correct syntax exactly. Options B, C, and D use incorrect commands or parameter names.
  3. Final Answer:

    az keyvault create --name myVault --resource-group myResourceGroup --location eastus -> Option A
  4. Quick Check:

    Correct CLI syntax = az keyvault create --name myVault --resource-group myResourceGroup --location eastus [OK]
Hint: Use 'az keyvault create' with --name and --resource-group [OK]
Common Mistakes:
  • Using 'az keyvault new' instead of 'create'
  • Wrong parameter names like --vault or --group
  • Omitting required parameters
3. Given this Azure CLI command:
az keyvault create --name testVault --resource-group testGroup --location westus --enable-soft-delete false

What will be the state of soft delete on the created Key Vault?
medium
A. Soft delete will be enabled by default
B. Soft delete will be disabled as specified
C. Soft delete will be enabled only if the region supports it
D. Command will fail due to invalid parameter

Solution

  1. Step 1: Check parameter validity

    The parameter --enable-soft-delete is deprecated and cannot be set to false; soft delete is always enabled now.
  2. Step 2: Understand command behavior

    Setting --enable-soft-delete false causes the command to fail because disabling soft delete is not allowed.
  3. Final Answer:

    Command will fail due to invalid parameter -> Option D
  4. Quick Check:

    Soft delete cannot be disabled now = Command will fail due to invalid parameter [OK]
Hint: Soft delete is always enabled; disabling causes error [OK]
Common Mistakes:
  • Assuming soft delete can be turned off
  • Ignoring deprecation of --enable-soft-delete
  • Thinking soft delete depends on region
4. You run this command to create a Key Vault:
az keyvault create --name vault123 --resource-group group123 --location eastus

But you get an error: ResourceGroupNotFound. What is the most likely fix?
medium
A. Change the location to westus
B. Create the resource group group123 before creating the Key Vault
C. Use a different Key Vault name
D. Add --enable-soft-delete true to the command

Solution

  1. Step 1: Understand the error

    ResourceGroupNotFound means the specified resource group does not exist.
  2. Step 2: Fix by creating the resource group

    You must create the resource group group123 first using az group create before creating resources inside it.
  3. Final Answer:

    Create the resource group group123 before creating the Key Vault -> Option B
  4. Quick Check:

    Resource group must exist before Key Vault creation [OK]
Hint: Create resource group first to avoid ResourceGroupNotFound [OK]
Common Mistakes:
  • Trying to change location instead of creating group
  • Changing vault name without checking group
  • Adding unrelated parameters to fix error
5. You want to create an Azure Key Vault with these requirements:
- Name: secureVault
- Resource group: prodGroup
- Location: centralus
- Enable soft delete
- Set access policy to allow user with object ID 1234abcd to get and list secrets

Which Azure CLI command sequence correctly achieves this?
hard
A. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list
B. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list
C. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list
D. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list

Solution

  1. Step 1: Create Key Vault with default soft delete enabled

    Soft delete is enabled by default and cannot be disabled, so no need to specify it.
  2. Step 2: Set access policy with correct syntax

    Use az keyvault set-policy with --object-id and --secret-permissions get list to allow the user to get and list secrets.
  3. Step 3: Verify command correctness

    az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list uses correct commands and parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list incorrectly uses comma between permissions. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list uses invalid parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list tries to disable soft delete, which is invalid.
  4. Final Answer:

    az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list -> Option A
  5. Quick Check:

    Create then set-policy with correct permissions = az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list [OK]
Hint: Create vault first, then set access policy with correct permissions [OK]
Common Mistakes:
  • Trying to disable soft delete
  • Using wrong parameter names for access policy
  • Combining all settings in one invalid command