Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Also called Key Vault.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Secret in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
Related terms
- API key (Foundry)
Secret shared by callers of an Azure OpenAI or Microsoft Foundry endpoint, conferring full access without any role check. Passing it around eliminates separation of roles, and it offers no network isolation.
- APIM named values
Reusable name/value pairs referenced from API Management policies. A value can be held in plain text, encrypted inside APIM as a secret, or pulled from Key Vault through the instance's managed identity.
- AWS IAM
Amazon's service for controlling who can sign in and what they may do across AWS. OneLake's Amazon S3 shortcuts depend on it: the cloud connection behind such a shortcut stores an IAM user's secret access key and its key ID.
- azcmagent
CLI that ships with the Azure Connected Machine agent. Running
azcmagent connectregisters a server with Azure Arc, and supplying a service principal ID plus a secret or certificate makes that onboarding unattended. - Azure Login action
Step in a GitHub Actions workflow that authenticates to Azure, either as the service principal of an Entra app or as a user-assigned managed identity; using OpenID Connect avoids storing any secret.
- azure/login
OpenID Connect is preferred over a service principal secret when this Action signs GitHub workflows in to Azure for later PowerShell or CLI steps.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- ClientSecretCredential
Credential type in the Azure Identity library for signing in as a service principal from three values (tenant ID, client ID, client secret); the secret it depends on needs protecting and regular rotation.