Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
Also called Key Vault.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Certificate in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- AIA
A certificate extension pointing to where a CA's parent certificates can be fetched. Microsoft Cloud PKI provides an AIA endpoint per issuing CA, and that endpoint, like the CRL, keeps responding even while the CA is paused.
- APNs
The Apple service Intune relies on to reach enrolled Apple devices. It requires an Apple MDM push certificate that lasts 365 days, has a 30-day grace period and has to be renewed, rather than replaced, using the Apple ID that created it.
- App Service custom domain
Host name bound to an App Service app once the service has confirmed an asuid TXT record and an A or CNAME record. Serving it over HTTPS also requires binding a TLS certificate.
- Authentication binding policy
Rules in this certificate-based authentication setting, matched on certificate issuer or policy OID, can lift a certificate from the tenant default (single-factor, low affinity) to multifactor or to high affinity binding.
- Authentication certificate
How Application Gateway v1 trusted backends: the public key (.cer) of the backend's certificate was uploaded into backend settings. On v2, trusted root certificates take its place.
- azcmagent
CLI that ships with the Azure Connected Machine agent. Running
azcmagent connectregisters a server with Azure Arc, and supplying a service principal ID plus a secret or certificate makes that onboarding unattended. - BitLocker Network Unlock
Lets domain-joined servers reboot without anyone typing a PIN: when they're on a trusted wired network, a WDS server holding the Network Unlock certificate unlocks the system drive.
- BYOC
Option for HTTPS on a Front Door custom domain in which your own certificate sits in Azure Key Vault, read through a managed identity or registered service principal; direct upload isn't possible and the chain must come from a Microsoft Trusted CA.