Note

Access to this page requires authorization. You can try signing in or .

Access to this page requires authorization. You can try .

Get-AzStorageAccountKey

Gets the access keys for an Azure Storage account.

Syntax

Default (Default)

Get-AzStorageAccountKey
 [-ResourceGroupName] <String>
 [-Name] <String>
 [-ListKerbKey]
 [-DefaultProfile <IAzureContextContainer>]
 [<CommonParameters>]

Description

The Get-AzStorageAccountKey cmdlet gets the access keys for an Azure Storage account.

Examples

Example 1: Get the access keys for a Storage account

Get-AzStorageAccountKey -ResourceGroupName "RG01" -Name "mystorageaccount"

This command gets the keys for the specified Azure Storage account.

Example 2: Get a specific access key for a Storage account

This command gets a specific key for a Storage account.
(Get-AzStorageAccountKey -ResourceGroupName "RG01" -Name "mystorageaccount")| Where-Object {$_.KeyName -eq "key1"}

KeyName Value Permissions CreationTime
------- ----- ----------- ------------
key1 <KeyValue> Full

This command gets a specific key value for a Storage account.
(Get-AzStorageAccountKey -ResourceGroupName "RG01" -Name "mystorageaccount")[0].Value

<KeyValue>

Example 3: Lists the access keys for a Storage account, include the Kerberos keys (if active directory enabled)

Get-AzStorageAccountKey -ResourceGroupName "RG01" -Name "mystorageaccount" -ListKerbKey

This command gets the keys for the specified Azure Storage account.

Parameters

-DefaultProfile

The credentials, account, tenant, and subscription used for communication with Azure.

Parameter properties

Type:IAzureContextContainer
Default value:None
Supports wildcards:False
DontShow:False
Aliases:AzContext, AzureRmContext, AzureCredential

Parameter sets

-ListKerbKey

Lists the Kerberos keys (if active directory enabled) for the specified storage account. Kerberos key is generated per storage account for Azure Files identity based authentication either with Microsoft Entra Domain Service (Microsoft Entra Domain Services) or Active Directory Domain Service (AD DS). It is used as the password of the identity registered in the domain service that represents the storage account. Kerberos key does not provide access permission to perform any control or data plane read or write operations against the storage account.

Parameter properties

Type:SwitchParameter
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-Name

Specifies the name of the Storage account for which this cmdlet gets keys.

Parameter properties

Type:String
Default value:None
Supports wildcards:False
DontShow:False
Aliases:StorageAccountName, AccountName

Parameter sets

-ResourceGroupName

Specifies the name of the resource group that contains the Storage account.

Parameter properties

Type:String
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable, -ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

Inputs

String

Outputs

StorageAccountKey

Related Links


Feedback

Was this page helpful?