Bird
Raised Fist0
Azurecloud~5 mins

Storing keys and certificates in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
When you build apps or services, you often need to keep secrets like keys and certificates safe. Azure Key Vault helps you store these secrets securely so only authorized users and apps can access them.
When you want to keep API keys safe and not hard-code them in your app.
When your app needs to use SSL/TLS certificates securely for encrypted communication.
When you want to control who can access your secrets with permissions.
When you want to rotate keys or certificates without changing your app code.
When you need a central place to manage all your secrets for multiple apps.
Config File - azure-keyvault-policy.json
azure-keyvault-policy.json
{
  "properties": {
    "accessPolicies": [
      {
        "tenantId": "11111111-2222-3333-4444-555555555555",
        "objectId": "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee",
        "permissions": {
          "keys": ["get", "list", "create", "delete"],
          "secrets": ["get", "list", "set", "delete"],
          "certificates": ["get", "list", "create", "delete"]
        }
      }
    ]
  }
}

This JSON defines who can access the Key Vault and what they can do.

  • tenantId: Your Azure Active Directory tenant ID.
  • objectId: The user or app allowed to access the vault.
  • permissions: What actions are allowed on keys, secrets, and certificates.
Commands
Create a new Azure Key Vault named 'myKeyVaultExample' in the 'myResourceGroup' resource group located in East US region.
Terminal
az keyvault create --name myKeyVaultExample --resource-group myResourceGroup --location eastus
Expected OutputExpected
{ "id": "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/myResourceGroup/providers/Microsoft.KeyVault/vaults/myKeyVaultExample", "location": "eastus", "name": "myKeyVaultExample", "properties": { "vaultUri": "https://mykeyvaultexample.vault.azure.net/" }, "resourceGroup": "myResourceGroup", "type": "Microsoft.KeyVault/vaults" }
→
--name - Sets the name of the Key Vault
→
--resource-group - Specifies the resource group to create the vault in
→
--location - Sets the Azure region for the vault
Store a secret named 'ApiKey' with the value '12345-abcde-67890-fghij' in the Key Vault.
Terminal
az keyvault secret set --vault-name myKeyVaultExample --name ApiKey --value "12345-abcde-67890-fghij"
Expected OutputExpected
{ "id": "https://mykeyvaultexample.vault.azure.net/secrets/ApiKey/xxxxxxxxxxxx", "attributes": { "enabled": true, "created": 1680000000, "updated": 1680000000 } }
→
--vault-name - Specifies which Key Vault to use
→
--name - Names the secret
→
--value - Sets the secret's value
Create a new certificate named 'myCertificate' in the Key Vault using the policy defined in the JSON file.
Terminal
az keyvault certificate create --vault-name myKeyVaultExample --name myCertificate --policy @azure-keyvault-policy.json
Expected OutputExpected
{ "id": "https://mykeyvaultexample.vault.azure.net/certificates/myCertificate/xxxxxxxxxxxx", "attributes": { "enabled": true, "created": 1680000000, "updated": 1680000000 }, "policy": { "issuerParameters": { "name": "Self" }, "x509CertificateProperties": { "subject": "CN=myCertificate", "validityInMonths": 12 } } }
→
--vault-name - Specifies the Key Vault to use
→
--name - Names the certificate
→
--policy - Specifies the certificate policy file
Retrieve and display the secret named 'ApiKey' from the Key Vault to verify it was stored correctly.
Terminal
az keyvault secret show --vault-name myKeyVaultExample --name ApiKey
Expected OutputExpected
{ "id": "https://mykeyvaultexample.vault.azure.net/secrets/ApiKey/xxxxxxxxxxxx", "value": "12345-abcde-67890-fghij", "attributes": { "enabled": true, "created": 1680000000, "updated": 1680000000 } }
→
--vault-name - Specifies the Key Vault to query
→
--name - Names the secret to retrieve
Key Concept

If you remember nothing else from this pattern, remember: Azure Key Vault safely stores and controls access to your keys, secrets, and certificates so your apps stay secure.

Common Mistakes
Not setting proper access policies for users or apps.
Without permissions, you cannot read or write secrets, causing failures.
Always configure access policies with correct tenant and object IDs and needed permissions.
Hardcoding secrets directly in app code instead of using Key Vault.
This exposes secrets to anyone with code access and makes rotation hard.
Store secrets in Key Vault and fetch them securely at runtime.
Using incorrect vault name or secret name in commands.
Commands fail because the resource does not exist or is misspelled.
Double-check names and spellings before running commands.
Summary
Create an Azure Key Vault to securely store keys, secrets, and certificates.
Use CLI commands to add secrets and certificates to the vault.
Verify stored secrets by retrieving them with CLI commands.

Practice

(1/5)
1. What is the main purpose of storing keys and certificates in Azure Key Vault?
easy
A. To monitor network traffic in Azure
B. To increase the speed of Azure virtual machines
C. To create backups of Azure databases automatically
D. To securely store and manage sensitive information like keys and certificates

Solution

  1. Step 1: Understand the role of Azure Key Vault

    Azure Key Vault is designed to keep sensitive data like keys and certificates safe and controlled.
  2. Step 2: Identify the correct purpose

    The options describing VM speed, database backups, and network monitoring relate to other Azure services or functions.
  3. Final Answer:

    To securely store and manage sensitive information like keys and certificates -> Option D
  4. Quick Check:

    Key Vault = Secure storage [OK]
Hint: Key Vault is for secrets, not speed or backups [OK]
Common Mistakes:
  • Confusing Key Vault with backup services
  • Thinking Key Vault speeds up VMs
  • Assuming Key Vault monitors network
2. Which Azure CLI command correctly creates a new Key Vault named MyVault in the resource group MyGroup located in eastus?
easy
A. az keyvault new --vault-name MyVault --group MyGroup --region eastus
B. az vault create --name MyVault --resource-group MyGroup --location eastus
C. az keyvault create --name MyVault --resource-group MyGroup --location eastus
D. az keyvault create --vault MyVault --resource-group MyGroup --location eastus

Solution

  1. Step 1: Recall correct Azure CLI syntax for Key Vault creation

    The correct command uses az keyvault create with parameters --name, --resource-group, and --location.
  2. Step 2: Compare options

    az keyvault create --name MyVault --resource-group MyGroup --location eastus matches the correct syntax exactly. The other options use incorrect commands like az keyvault new or az vault create, or wrong parameter names like --vault-name, --group, or --vault.
  3. Final Answer:

    az keyvault create --name MyVault --resource-group MyGroup --location eastus -> Option C
  4. Quick Check:

    Correct CLI syntax = az keyvault create --name MyVault --resource-group MyGroup --location eastus [OK]
Hint: Use 'az keyvault create' with --name, --resource-group, --location [OK]
Common Mistakes:
  • Using 'az keyvault new' instead of 'create'
  • Wrong parameter names like --vault or --group
  • Confusing 'vault' and 'keyvault' commands
3. Given this Azure CLI command sequence:
az keyvault secret set --vault-name MyVault --name ApiKey --value "12345"
What will be the result when you run az keyvault secret show --vault-name MyVault --name ApiKey?
medium
A. It will display the secret value "12345" along with metadata
B. It will return an error because secrets cannot be retrieved
C. It will show an empty secret value
D. It will delete the secret named ApiKey

Solution

  1. Step 1: Understand secret creation and retrieval

    The first command stores a secret named ApiKey with value "12345" in MyVault. The second command retrieves that secret.
  2. Step 2: Predict the output of secret show command

    The show command returns the secret's value and metadata. It does not delete or error unless permissions are missing.
  3. Final Answer:

    It will display the secret value "12345" along with metadata -> Option A
  4. Quick Check:

    Secret show returns stored value [OK]
Hint: Secret show command retrieves stored secret value [OK]
Common Mistakes:
  • Thinking secrets cannot be retrieved
  • Expecting deletion on show command
  • Assuming empty value if not specified
4. You run this command to create a certificate in Azure Key Vault:
az keyvault certificate create --vault-name MyVault --name MyCert --policy @policy.json
But you get an error saying the policy file is invalid. What is the most likely cause?
medium
A. The JSON file policy.json has syntax errors or incorrect structure
B. The vault name MyVault does not exist
C. The certificate name MyCert is already in use
D. The Azure CLI is not installed

Solution

  1. Step 1: Analyze the error message about invalid policy file

    The error points to the policy file being invalid, which usually means JSON syntax or structure issues.
  2. Step 2: Consider other options

    While vault existence or name conflicts cause errors, the message specifically mentions the policy file. CLI installation issues would prevent any command from running.
  3. Final Answer:

    The JSON file policy.json has syntax errors or incorrect structure -> Option A
  4. Quick Check:

    Invalid policy file = JSON syntax error [OK]
Hint: Check JSON file syntax if policy error occurs [OK]
Common Mistakes:
  • Ignoring JSON syntax errors
  • Assuming vault or name issues without checking file
  • Not validating JSON before use
5. You want to automate deployment of an Azure Key Vault with a certificate and restrict access so only a specific app can use the certificate. Which combination of steps is best practice?
hard
A. Create Key Vault; disable all access policies; share certificate via email
B. Create Key Vault with access policies granting the app permission; upload certificate; avoid storing secrets in code
C. Create Key Vault; upload certificate; embed certificate value directly in app code
D. Create Key Vault; store certificate value as a secret; give all users access to the vault

Solution

  1. Step 1: Securely create Key Vault and upload certificate

    Create the vault and add the certificate properly to keep it safe and managed.
  2. Step 2: Set access policies to restrict usage to the specific app and avoid secrets in code

    Grant only the app needed permissions and never put secrets or certificates directly in code to prevent leaks.
  3. Final Answer:

    Create Key Vault with access policies granting the app permission; upload certificate; avoid storing secrets in code -> Option B
  4. Quick Check:

    Restrict access + no secrets in code = Create Key Vault with access policies granting the app permission; upload certificate; avoid storing secrets in code [OK]
Hint: Use access policies and never embed secrets in code [OK]
Common Mistakes:
  • Giving broad access to all users
  • Embedding secrets directly in application code
  • Disabling access policies and sharing insecurely