Note

Access to this page requires authorization. You can try signing in or .

Access to this page requires authorization. You can try .

Add-AzKeyVaultNetworkRule

Adds a rule meant to restrict access to a key vault based on the client's internet address.

Syntax

ByVaultName (Default)

Add-AzKeyVaultNetworkRule
 [-VaultName] <String>
 [[-ResourceGroupName] <String>]
 [-IpAddressRange <String[]>]
 [-VirtualNetworkResourceId <String[]>]
 [-PassThru]
 [-DefaultProfile <IAzureContextContainer>]
 [-WhatIf]
 [-Confirm]
 [-SubscriptionId <String>]
 [<CommonParameters>]

ByInputObject

Add-AzKeyVaultNetworkRule
 [-InputObject] <PSKeyVault>
 [-IpAddressRange <String[]>]
 [-VirtualNetworkResourceId <String[]>]
 [-PassThru]
 [-DefaultProfile <IAzureContextContainer>]
 [-WhatIf]
 [-Confirm]
 [-SubscriptionId <String>]
 [<CommonParameters>]

ByResourceId

Add-AzKeyVaultNetworkRule
 [-ResourceId] <String>
 [-IpAddressRange <String[]>]
 [-VirtualNetworkResourceId <String[]>]
 [-PassThru]
 [-DefaultProfile <IAzureContextContainer>]
 [-WhatIf]
 [-Confirm]
 [-SubscriptionId <String>]
 [<CommonParameters>]

Description

The Add-AzKeyVaultNetworkRule cmdlet grants or restricts access to a key vault to a set of caller designated by their IP addresses or the virtual network to which they belong. The rule has the potential to restrict access for other users, applications, or security groups which have been granted permissions via the access policy.

Please note that any IP range inside 10.0.0.0-10.255.255.255 (private IP addresses) cannot be used to add network rules.

Examples

Example 1

$frontendSubnet = New-AzVirtualNetworkSubnetConfig -Name frontendSubnet -AddressPrefix "10.0.1.0/24" -ServiceEndpoint Microsoft.KeyVault
$virtualNetwork = New-AzVirtualNetwork -Name myVNet -ResourceGroupName myRG -Location westus -AddressPrefix "10.0.0.0/16" -Subnet $frontendSubnet
$myNetworkResId = (Get-AzVirtualNetwork -Name myVNet -ResourceGroupName myRG).Subnets[0].Id
Add-AzKeyVaultNetworkRule -VaultName myvault -IpAddressRange "124.56.78.0/24" -VirtualNetworkResourceId $myNetworkResId -PassThru
Vault Name : myvault
Resource Group Name : myRG
Location : westus
Resource ID : /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxx/resourceGroups/myRG/providers
 /Microsoft.KeyVault/vaults/myvault
Vault URI : https://myvault.vault.azure.net/
Tenant ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxx
SKU : Standard
Enabled For Deployment? : True
Enabled For Template Deployment? : True
Enabled For Disk Encryption? : False
Soft Delete Enabled? : True
Access Policies :
 Tenant ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxx
 Object ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxx
 Application ID :
 Display Name : User Name (username@microsoft.com)
 Permissions to Keys : get, create, delete, list, update,
 import, backup, restore, recover
 Permissions to Secrets : get, list, set, delete, backup,
 restore, recover
 Permissions to Certificates : get, delete, list, create, import,
 update, deleteissuers, getissuers, listissuers, managecontacts, manageissuers,
 setissuers, recover
 Permissions to (Key Vault Managed) Storage : delete, deletesas, get, getsas, list,
 listsas, regeneratekey, set, setsas, update


Network Rule Set :
 Default Action : Allow
 Bypass : AzureServices
 IP Rules : 124.56.78.0/24
 Virtual Network Rules : /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-
 xxxxxxxxxxxxx/resourcegroups/myRG/providers/microsoft.network/virtualnetworks/myvn
 et/subnets/frontendsubnet

Tags :

This command adds a network rule to the specified vault, allowing access to the specified IP address from the virtual network identified by $myNetworkResId.

Parameters

-Confirm

Prompts you for confirmation before running the cmdlet.

Parameter properties

Type:SwitchParameter
Default value:None
Supports wildcards:False
DontShow:False
Aliases:cf

Parameter sets

-DefaultProfile

The credentials, account, tenant, and subscription used for communication with Azure.

Parameter properties

Type:IAzureContextContainer
Default value:None
Supports wildcards:False
DontShow:False
Aliases:AzContext, AzureRmContext, AzureCredential

Parameter sets

-InputObject

KeyVault object

Parameter properties

Type:PSKeyVault
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-IpAddressRange

Specifies allowed network IP address range of network rule.

Parameter properties

Type:

String[]

Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-PassThru

This Cmdlet does not return an object by default. If this switch is specified, it returns the updated key vault object.

Parameter properties

Type:SwitchParameter
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-ResourceGroupName

Specifies the name of the resource group associated with the key vault whose network rule is being modified.

Parameter properties

Type:String
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-ResourceId

KeyVault Resource Id

Parameter properties

Type:String
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-SubscriptionId

The ID of the subscription. By default, cmdlets are executed in the subscription that is set in the current context. If the user specifies another subscription, the current cmdlet is executed in the subscription specified by the user. Overriding subscriptions only take effect during the lifecycle of the current cmdlet. It does not change the subscription in the context, and does not affect subsequent cmdlets.

Parameter properties

Type:String
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-VaultName

Specifies the name of a key vault whose network rule is being modified.

Parameter properties

Type:String
Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-VirtualNetworkResourceId

Specifies allowed virtual network resource identifier of network rule.

Parameter properties

Type:

String[]

Default value:None
Supports wildcards:False
DontShow:False

Parameter sets

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Parameter properties

Type:SwitchParameter
Default value:None
Supports wildcards:False
DontShow:False
Aliases:wi

Parameter sets

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable, -ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

Inputs

PSKeyVault

String

Outputs

PSKeyVault


Feedback

Was this page helpful?