managed_hsms
Creates, updates, deletes, gets or lists a managed_hsms resource.
Overview
| Name | managed_hsms |
| Type | Resource |
| Id | azure.key_vault.managed_hsms |
Fields
The following fields are returned by SELECT queries:
- get
- get_deleted
- list_by_resource_group
- check_mhsm_name_availability
- list_by_subscription
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
createMode | string | The create mode to indicate whether the resource is being created or is being recovered from a deleted resource. Known values are: "recover" and "default". (recover, default) |
enablePurgeProtection | boolean | Property specifying whether protection against purge is enabled for this managed HSM pool. Setting this property to true activates protection against purge for this managed HSM pool and its content - only the Managed HSM service may initiate a hard, irrecoverable deletion. Enabling this functionality is irreversible. |
enableSoftDelete | boolean | Property to specify whether the 'soft delete' functionality is enabled for this managed HSM pool. Soft delete is enabled by default for all managed HSMs and is immutable. |
hsmUri | string | The URI of the managed hsm pool for performing operations on keys. |
identity | object | Managed service identity. |
initialAdminObjectIds | array | Array of initial administrators object ids for this managed hsm pool. |
location | string | The geo-location where the resource lives. |
networkAcls | object | Rules governing the accessibility of the key vault from specific network locations. |
privateEndpointConnections | array | List of private endpoint connections associated with the managed hsm pool. |
provisioningState | string | Provisioning state. Known values are: "Succeeded", "Provisioning", "Failed", "Updating", "Deleting", "Activated", "SecurityDomainRestore", and "Restoring". (Succeeded, Provisioning, Failed, Updating, Deleting, Activated, SecurityDomainRestore, Restoring) |
publicNetworkAccess | string | Control permission to the managed HSM from public networks. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
regions | array | List of all regions associated with the managed hsm pool. |
scheduledPurgeDate | string (date-time) | The scheduled purge date in UTC. |
securityDomainProperties | object | Managed HSM security domain properties. |
sku | object | SKU details. |
softDeleteRetentionInDays | integer | Soft deleted data retention days. When you delete an HSM or a key, it will remain recoverable for the configured retention period or for a default period of 90 days. It accepts values between 7 and 90. |
statusMessage | string | Resource Status Message. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
tenantId | string | The Azure Active Directory tenant ID that should be used for authenticating requests to the managed HSM pool. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
deletionDate | string (date-time) | The deleted date. |
location | string | The location of the original managed HSM. |
mhsmId | string | The resource id of the original managed HSM. |
purgeProtectionEnabled | boolean | Purge protection status of the original managed HSM. |
scheduledPurgeDate | string (date-time) | The scheduled purged date. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Tags of the original managed HSM. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
createMode | string | The create mode to indicate whether the resource is being created or is being recovered from a deleted resource. Known values are: "recover" and "default". (recover, default) |
enablePurgeProtection | boolean | Property specifying whether protection against purge is enabled for this managed HSM pool. Setting this property to true activates protection against purge for this managed HSM pool and its content - only the Managed HSM service may initiate a hard, irrecoverable deletion. Enabling this functionality is irreversible. |
enableSoftDelete | boolean | Property to specify whether the 'soft delete' functionality is enabled for this managed HSM pool. Soft delete is enabled by default for all managed HSMs and is immutable. |
hsmUri | string | The URI of the managed hsm pool for performing operations on keys. |
identity | object | Managed service identity. |
initialAdminObjectIds | array | Array of initial administrators object ids for this managed hsm pool. |
location | string | The geo-location where the resource lives. |
networkAcls | object | Rules governing the accessibility of the key vault from specific network locations. |
privateEndpointConnections | array | List of private endpoint connections associated with the managed hsm pool. |
provisioningState | string | Provisioning state. Known values are: "Succeeded", "Provisioning", "Failed", "Updating", "Deleting", "Activated", "SecurityDomainRestore", and "Restoring". (Succeeded, Provisioning, Failed, Updating, Deleting, Activated, SecurityDomainRestore, Restoring) |
publicNetworkAccess | string | Control permission to the managed HSM from public networks. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
regions | array | List of all regions associated with the managed hsm pool. |
scheduledPurgeDate | string (date-time) | The scheduled purge date in UTC. |
securityDomainProperties | object | Managed HSM security domain properties. |
sku | object | SKU details. |
softDeleteRetentionInDays | integer | Soft deleted data retention days. When you delete an HSM or a key, it will remain recoverable for the configured retention period or for a default period of 90 days. It accepts values between 7 and 90. |
statusMessage | string | Resource Status Message. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
tenantId | string | The Azure Active Directory tenant ID that should be used for authenticating requests to the managed HSM pool. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
message | string | An error message explaining the Reason value in more detail. |
nameAvailable | boolean | A boolean value that indicates whether the name is available for you to use. If true, the name is available. If false, the name has already been taken or is invalid and cannot be used. |
reason | string | The reason that a managed hsm name could not be used. The reason element is only returned if NameAvailable is false. Known values are: "AccountNameInvalid" and "AlreadyExists". (AccountNameInvalid, AlreadyExists) |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
createMode | string | The create mode to indicate whether the resource is being created or is being recovered from a deleted resource. Known values are: "recover" and "default". (recover, default) |
enablePurgeProtection | boolean | Property specifying whether protection against purge is enabled for this managed HSM pool. Setting this property to true activates protection against purge for this managed HSM pool and its content - only the Managed HSM service may initiate a hard, irrecoverable deletion. Enabling this functionality is irreversible. |
enableSoftDelete | boolean | Property to specify whether the 'soft delete' functionality is enabled for this managed HSM pool. Soft delete is enabled by default for all managed HSMs and is immutable. |
hsmUri | string | The URI of the managed hsm pool for performing operations on keys. |
identity | object | Managed service identity. |
initialAdminObjectIds | array | Array of initial administrators object ids for this managed hsm pool. |
location | string | The geo-location where the resource lives. |
networkAcls | object | Rules governing the accessibility of the key vault from specific network locations. |
privateEndpointConnections | array | List of private endpoint connections associated with the managed hsm pool. |
provisioningState | string | Provisioning state. Known values are: "Succeeded", "Provisioning", "Failed", "Updating", "Deleting", "Activated", "SecurityDomainRestore", and "Restoring". (Succeeded, Provisioning, Failed, Updating, Deleting, Activated, SecurityDomainRestore, Restoring) |
publicNetworkAccess | string | Control permission to the managed HSM from public networks. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
regions | array | List of all regions associated with the managed hsm pool. |
scheduledPurgeDate | string (date-time) | The scheduled purge date in UTC. |
securityDomainProperties | object | Managed HSM security domain properties. |
sku | object | SKU details. |
softDeleteRetentionInDays | integer | Soft deleted data retention days. When you delete an HSM or a key, it will remain recoverable for the configured retention period or for a default period of 90 days. It accepts values between 7 and 90. |
statusMessage | string | Resource Status Message. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
tenantId | string | The Azure Active Directory tenant ID that should be used for authenticating requests to the managed HSM pool. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | resource_group_name, name, subscription_id | Gets the specified managed HSM Pool. | |
get_deleted | select | name, location, subscription_id | Gets the specified deleted managed HSM. | |
list_by_resource_group | select | resource_group_name, subscription_id | $top | The List operation gets information about the managed HSM Pools associated with the subscription and within the specified resource group. |
check_mhsm_name_availability | select | subscription_id | Checks that the managed hsm name is valid and is not already in use. | |
list_by_subscription | select | subscription_id | $top | The List operation gets information about the managed HSM Pools associated with the subscription. |
create_or_update | insert | resource_group_name, name, subscription_id | Create or update a managed HSM Pool in the specified subscription. | |
update | update | resource_group_name, name, subscription_id | Update a managed HSM Pool in the specified subscription. | |
create_or_update | replace | resource_group_name, name, subscription_id | Create or update a managed HSM Pool in the specified subscription. | |
delete | delete | resource_group_name, name, subscription_id | Deletes the specified managed HSM Pool. | |
list_deleted | exec | subscription_id | The List operation gets information about the deleted managed HSMs associated with the subscription. | |
purge_deleted | exec | name, location, subscription_id | Permanently deletes the specified managed HSM. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
location | string | The name of the Azure region. Required. |
name | string | The name of the deleted managed HSM. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
subscription_id | string | |
$top | integer | Maximum number of results to return. Default value is None. |
SELECT examples
- get
- get_deleted
- list_by_resource_group
- check_mhsm_name_availability
- list_by_subscription
Gets the specified managed HSM Pool.
SELECT
id,
name,
createMode,
enablePurgeProtection,
enableSoftDelete,
hsmUri,
identity,
initialAdminObjectIds,
location,
networkAcls,
privateEndpointConnections,
provisioningState,
publicNetworkAccess,
regions,
scheduledPurgeDate,
securityDomainProperties,
sku,
softDeleteRetentionInDays,
statusMessage,
systemData,
tags,
tenantId,
type
FROM azure.key_vault.managed_hsms
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND name = '{{ name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets the specified deleted managed HSM.
SELECT
id,
name,
deletionDate,
location,
mhsmId,
purgeProtectionEnabled,
scheduledPurgeDate,
systemData,
tags,
type
FROM azure.key_vault.managed_hsms
WHERE name = '{{ name }}' -- required
AND location = '{{ location }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
The List operation gets information about the managed HSM Pools associated with the subscription and within the specified resource group.
SELECT
id,
name,
createMode,
enablePurgeProtection,
enableSoftDelete,
hsmUri,
identity,
initialAdminObjectIds,
location,
networkAcls,
privateEndpointConnections,
provisioningState,
publicNetworkAccess,
regions,
scheduledPurgeDate,
securityDomainProperties,
sku,
softDeleteRetentionInDays,
statusMessage,
systemData,
tags,
tenantId,
type
FROM azure.key_vault.managed_hsms
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $top = '{{ $top }}'
;
Checks that the managed hsm name is valid and is not already in use.
SELECT
message,
nameAvailable,
reason
FROM azure.key_vault.managed_hsms
WHERE subscription_id = '{{ subscription_id }}' -- required
;
The List operation gets information about the managed HSM Pools associated with the subscription.
SELECT
id,
name,
createMode,
enablePurgeProtection,
enableSoftDelete,
hsmUri,
identity,
initialAdminObjectIds,
location,
networkAcls,
privateEndpointConnections,
provisioningState,
publicNetworkAccess,
regions,
scheduledPurgeDate,
securityDomainProperties,
sku,
softDeleteRetentionInDays,
statusMessage,
systemData,
tags,
tenantId,
type
FROM azure.key_vault.managed_hsms
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $top = '{{ $top }}'
;
INSERT examples
- create_or_update
- Manifest
Create or update a managed HSM Pool in the specified subscription.
INSERT INTO azure.key_vault.managed_hsms (
properties,
sku,
identity,
location,
tags,
resource_group_name,
name,
subscription_id
)
SELECT
'{{ properties }}',
'{{ sku }}',
'{{ identity }}',
'{{ location }}',
'{{ tags }}',
'{{ resource_group_name }}',
'{{ name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
identity,
location,
properties,
sku,
systemData,
tags,
type
;
# Description fields are for documentation purposes
- name: managed_hsms
props:
- name: resource_group_name
value: "{{ resource_group_name }}"
description: Required parameter for the managed_hsms resource.
- name: name
value: "{{ name }}"
description: Required parameter for the managed_hsms resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the managed_hsms resource.
- name: properties
description: |
Properties of the managed HSM.
value:
tenantId: "{{ tenantId }}"
initialAdminObjectIds:
- "{{ initialAdminObjectIds }}"
hsmUri: "{{ hsmUri }}"
enableSoftDelete: {{ enableSoftDelete }}
softDeleteRetentionInDays: {{ softDeleteRetentionInDays }}
enablePurgeProtection: {{ enablePurgeProtection }}
createMode: "{{ createMode }}"
statusMessage: "{{ statusMessage }}"
provisioningState: "{{ provisioningState }}"
networkAcls:
bypass: "{{ bypass }}"
defaultAction: "{{ defaultAction }}"
ipRules:
- value: "{{ value }}"
serviceTags:
- tag: "{{ tag }}"
virtualNetworkRules:
- id: "{{ id }}"
regions:
- name: "{{ name }}"
provisioningState: "{{ provisioningState }}"
isPrimary: {{ isPrimary }}
privateEndpointConnections:
- id: "{{ id }}"
etag: "{{ etag }}"
properties:
privateEndpoint:
id: "{{ id }}"
privateLinkServiceConnectionState:
status: "{{ status }}"
description: "{{ description }}"
actionsRequired: "{{ actionsRequired }}"
provisioningState: "{{ provisioningState }}"
publicNetworkAccess: "{{ publicNetworkAccess }}"
scheduledPurgeDate: "{{ scheduledPurgeDate }}"
securityDomainProperties:
activationStatus: "{{ activationStatus }}"
activationStatusMessage: "{{ activationStatusMessage }}"
- name: sku
description: |
SKU details.
value:
family: "{{ family }}"
name: "{{ name }}"
- name: identity
description: |
Managed service identity.
value:
principalId: "{{ principalId }}"
tenantId: "{{ tenantId }}"
type: "{{ type }}"
userAssignedIdentities: "{{ userAssignedIdentities }}"
- name: location
value: "{{ location }}"
description: |
The geo-location where the resource lives.
- name: tags
value: "{{ tags }}"
description: |
Resource tags.
UPDATE examples
- update
Update a managed HSM Pool in the specified subscription.
UPDATE azure.key_vault.managed_hsms
SET
properties = '{{ properties }}',
sku = '{{ sku }}',
identity = '{{ identity }}',
location = '{{ location }}',
tags = '{{ tags }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND name = '{{ name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
identity,
location,
properties,
sku,
systemData,
tags,
type;
REPLACE examples
- create_or_update
Create or update a managed HSM Pool in the specified subscription.
REPLACE azure.key_vault.managed_hsms
SET
properties = '{{ properties }}',
sku = '{{ sku }}',
identity = '{{ identity }}',
location = '{{ location }}',
tags = '{{ tags }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND name = '{{ name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
identity,
location,
properties,
sku,
systemData,
tags,
type;
DELETE examples
- delete
Deletes the specified managed HSM Pool.
DELETE FROM azure.key_vault.managed_hsms
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND name = '{{ name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
Lifecycle Methods
- list_deleted
- purge_deleted
The List operation gets information about the deleted managed HSMs associated with the subscription.
EXEC azure.key_vault.managed_hsms.list_deleted
@subscription_id='{{ subscription_id }}' --required
;
Permanently deletes the specified managed HSM.
EXEC azure.key_vault.managed_hsms.purge_deleted
@name='{{ name }}' --required,
@location='{{ location }}' --required,
@subscription_id='{{ subscription_id }}' --required
;