Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
Also called secret permission.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Set in context, with comparison tables and the common traps.
Terms in this definition
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- Access mode
Set on each compute resource, this controls which people can attach and what data they reach. Dedicated (once called single user) belongs to a single user or group, standard (once called shared) keeps many users apart from each other, and Auto leaves the choice to the runtime.
- Access package manager
Holders of this catalog-level entitlement management role design new access packages, alter existing ones and set their policies, drawing only on resources that are already in that catalog; bringing extra resources in is beyond them.
- Account lockout policy
Locks accounts after a set number of failed sign-ins, using domain settings for threshold, duration and counter reset. Thresholds run from 0 to 999, and 0 disables lockout.
- ACL
List of permissions set on a file or folder; examples include the POSIX-style lists in ADLS Gen2 and NTFS lists on Azure Files. Attribute conditions cannot be expressed in them.
- Active Standby
An NSX gateway HA mode where one Edge node handles traffic while a second waits to take over. Stateful services such as NAT, VPN, load balancing and the stateful firewall depend on it, and VCF Automation 9.0 expects its Tier-0 to be set up this way.
- Add-AzVirtualNetworkPeering
Az.Network cmdlet for creating a VNet peering link in a single direction. For hub-and-spoke gateway sharing, set
-AllowGatewayTransiton the link from hub to spoke and-UseRemoteGatewayson the link from spoke to hub. - ADSI
Set of COM interfaces for directory access; ADSI Edit uses them to view and modify Active Directory objects at a low level.
- Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.