Skip to Content

Microsoft Azure Key Vault Create Vault Objects activity

Introduction

A Microsoft Azure Key Vault Create Vault Objects activity, using its Microsoft Azure Key Vault connection, creates a certificate, key, or secret in Microsoft Azure Key Vault and is intended to be used as a target to consume data in an operation.

Create a Microsoft Azure Key Vault Create Vault Objects activity

An instance of a Microsoft Azure Key Vault Create Vault Objects activity is created from a Microsoft Azure Key Vault connection using its Create Vault Objects activity type.

To create an instance of an activity, drag the activity type to the design canvas or copy the activity type and paste it on the design canvas. For details, see Create an activity or tool instance in Component reuse.

An existing Microsoft Azure Key Vault Create Vault Objects activity can be edited from these locations:

Configure a Microsoft Azure Key Vault Create Vault Objects activity

Follow these steps to configure a Microsoft Azure Key Vault Create Vault Objects activity:

Step 1: Enter a name and select a vault

In this step, provide a name for the activity and select a vault. Each user interface element of this step is described below.

Microsoft Azure Key Vault Create Vault Objects configuration step 1

  • Name: Enter a name to identify the activity. The name must be unique for each Microsoft Azure Key Vault Create Vault Objects activity and must not contain forward slashes / or colons :.

  • Select a vault: This section displays vaults available in the Microsoft Azure Key Vault endpoint.

    • Selected vault: After a vault is selected, it is listed here.

    • Search: Enter any column's value into the search box to filter the list of vaults. The search is not case-sensitive. If vaults are already displayed within the table, the table results are filtered in real time with each keystroke. To reload vaults from the endpoint when searching, enter search criteria and then refresh, as described below.

    • Refresh: Click the refresh icon or the word Refresh to reload vaults from the Microsoft Azure Key Vault endpoint. This may be useful if vaults have been added to Microsoft Azure Key Vault. This action refreshes all metadata used to build the table of vaults displayed in the configuration.

    • Selecting a vault: Within the table, click anywhere on a row to select a vault. Only one vault can be selected. The information available for each vault is fetched from the Microsoft Azure Key Vault endpoint:

      • Name: The name of the vault.

      • Location: The Azure region the vault is located in.

      • Resource group: The resource group of the vault.

    Tip

    If the table does not populate with available vaults, the Microsoft Azure Key Vault connection may not be successful. Ensure you are connected by reopening the connection and retesting the credentials.

  • Optional settings: Click to expand additional optional settings:

    • Continue on error: Select to continue the activity execution if an error is encountered for a dataset in a batch request. If any errors are encountered, they are written to the operation log.
  • Save & Exit: If enabled, click to save the configuration for this step and close the activity configuration.

  • Next: Click to temporarily store the configuration for this step and continue to the next step. The configuration will not be saved until you click the Finished button on the last step.

  • Discard Changes: After making changes, click to close the configuration without saving changes made to any step. A message asks you to confirm that you want to discard changes.

Step 2: Select a vault object type

In this step, select a vault object type. Each user interface element of this step is described below.

Microsoft Azure Key Vault Create Vault Objects configuration step 2

  • Select an object type: This section displays vault object types available in the Microsoft Azure Key Vault endpoint. For more information on the supported Certificate, Key, and Store vault object types, refer to the the Microsoft Azure Key Vault REST API documentation.

    • Selected vault: The vault selected in the previous step is listed here.

    • Selected object type: After a vault object type is selected, it is listed here.

    • Search: Enter any column's value into the search box to filter the list of vault object types. The search is not case-sensitive. If vault object types are already displayed within the table, the table results are filtered in real time with each keystroke. To reload vault object types from the endpoint when searching, enter search criteria and then refresh, as described below.

    • Refresh: Click the refresh icon or the word Refresh to reload vault object types from the Microsoft Azure Key Vault endpoint. This may be useful if vault object types have been added to Microsoft Azure Key Vault. This action refreshes all metadata used to build the table of vault object types displayed in the configuration.

    • Selecting an object type: Within the table, click anywhere on a row to select a vault object type. Only one vault object type can be selected. The information available for each vault object type is fetched from the Microsoft Azure Key Vault endpoint:

      • Name: The name of the vault object type.

      • Description: The description of the vault object type.

    Tip

    If the table does not populate with available vault object types, the Microsoft Azure Key Vault connection may not be successful. Ensure you are connected by reopening the connection and retesting the credentials.

  • Back: Click to temporarily store the configuration for this step and return to the previous step.

  • Next: Click to temporarily store the configuration for this step and continue to the next step. The configuration will not be saved until you click the Finished button on the last step.

  • Discard Changes: After making changes, click to close the configuration without saving changes made to any step. A message asks you to confirm that you want to discard changes.

Step 3: Review the data schemas

Any request or response schemas are displayed. Each user interface element of this step is described below.

Microsoft Azure Key Vault Create Vault Objects configuration step 3

  • Data schema: These data schemas are inherited by adjacent transformations and are displayed again during transformation mapping.

    The Microsoft Azure Key Vault connector uses the Microsoft Azure Key Vault REST API. The required request schema fields are described below. For additional field descriptions, refer to the API documentation.

  • Refresh: Click the refresh icon or the word Refresh to regenerate schemas from the Microsoft Azure Key Vault endpoint. This action also regenerates a schema in other locations throughout the project where the same schema is referenced, such as in an adjacent transformation.

  • Back: Click to temporarily store the configuration for this step and return to the previous step.

  • Finished: Click to save the configuration for all steps and close the activity configuration.

  • Discard Changes: After making changes, click to close the configuration without saving changes made to any step. A message asks you to confirm that you want to discard changes.

Required request schema fields

  • Certificates:

    Request schema node / field Description
    createVaultObjects Node
        request Node
            item Node
            name The certificate's name. A valid certificate name matches this regular expression pattern: ^[0-9a-zA-Z-]+$.
            enabled The certificate's enablement, one of true or false.
                policy Node
                subject The certificate's subject name. Should be a valid X509 distinguished name. For example: CN=*.microsoft.com".
                keyType The JsonWebKeyType to be associated with the certificate. For example, RSA or EC.
                contentType The certificate's media type (MIME type). For example, application/x-pkcs12.
                issuerName The certificate's issuer name. For example, if self-signed, Self.
  • Keys:

    Request schema node / field Description
    createVaultObjects Node
        request Node
            item Node
            name The key's name. A valid key name matches this regular expression pattern: ^[a-zA-Z0-9-]{1,127}$.
            keyType The key's JsonWebKeyType. For example, RSA or EC.
            enabled The key's enablement, one of true or false.
  • Secrets:

    Request schema node / field Description
    createVaultObjects Node
        request Node
            item Node
            value The secret's value.
                properties Node
                name The secret's name. A valid vault name matches this regular expression pattern: ^[a-zA-Z0-9-]{1,127}$.
                enabled The secret's enablement, one of true or false.

Next steps

After configuring a Microsoft Azure Key Vault Create Vault Objects activity, complete the configuration of the operation by adding and configuring other activities, transformations, or scripts as operation steps. You can also configure the operation settings, which include the ability to chain operations together that are in the same or different workflows.

Menu actions for an activity are accessible from the project pane and the design canvas. For details, see Activity actions menu in Connector basics.

Microsoft Azure Key Vault Create Vault Objects activities can be used as a target with these operation patterns:

To use the activity with scripting functions, write the data to a temporary location and then use that temporary location in the scripting function.

When ready, deploy and run the operation and validate behavior by checking the operation logs.