az cosmosdb identity

This command group is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Manage Azure Cosmos DB managed service identities.

Commands

Name Description Type Status
az cosmosdb identity assign

Assign SystemAssigned identity for an Azure Cosmos DB database account.

Core Preview
az cosmosdb identity remove

Remove SystemAssigned identity for an Azure Cosmos DB database account.

Core Preview
az cosmosdb identity show

Show the identities for an Azure Cosmos DB database account.

Core Preview

az cosmosdb identity assign

Preview

Command group 'cosmosdb identity' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Assign SystemAssigned identity for an Azure Cosmos DB database account.

az cosmosdb identity assign [--acquire-policy-token]
                            [--change-reference]
                            [--identities]
                            [--ids]
                            [--name]
                            [--resource-group]
                            [--subscription]

Examples

Assign SystemAssigned identity for an Azure Cosmos DB database account.

az cosmosdb identity assign --name MyCosmosDBDatabaseAccount --resource-group MyResourceGroup

Assign one UserAssigned identity for an Azure Cosmos DB database account.

az cosmosdb identity assign --name MyCosmosDBDatabaseAccount --resource-group MyResourceGroup --identities /subscriptions/00000000-0000-0000-0000-00000000/resourcegroups/MyRG/providers/Microsoft.ManagedIdentity/userAssignedIdentities/MyID

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--identities

Space-separated identities to assign. Use '[system]' to refer to the system assigned identity. Default: '[system]'.

--ids

One or more resource IDs (space-delimited). It should be a complete resource ID containing all information of 'Resource Id' arguments. You should provide either --ids or other 'Resource Id' arguments.

Property Value
Parameter group: Resource Id Arguments
--name -n

Name of the Cosmos DB database account.

Property Value
Parameter group: Resource Id Arguments
--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Property Value
Parameter group: Resource Id Arguments
--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

Property Value
Parameter group: Resource Id Arguments
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az cosmosdb identity remove

Preview

Command group 'cosmosdb identity' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Remove SystemAssigned identity for an Azure Cosmos DB database account.

az cosmosdb identity remove [--acquire-policy-token]
                            [--change-reference]
                            [--identities]
                            [--ids]
                            [--name]
                            [--resource-group]
                            [--subscription]

Examples

Remove SystemAssigned identity for an Azure Cosmos DB database account.

az cosmosdb identity remove --name MyCosmosDBDatabaseAccount --resource-group MyResourceGroup

Remove a UserAssigned identity for an Azure Cosmos DB database account.

az cosmosdb identity remove --name MyCosmosDBDatabaseAccount --resource-group MyResourceGroup --identities /subscriptions/00000000-0000-0000-0000-00000000/resourcegroups/MyRG/providers/Microsoft.ManagedIdentity/userAssignedIdentities/MyID

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--identities

Space-separated identities to remove. Use '[system]' to refer to the system assigned identity. Default: '[system]'.

--ids

One or more resource IDs (space-delimited). It should be a complete resource ID containing all information of 'Resource Id' arguments. You should provide either --ids or other 'Resource Id' arguments.

Property Value
Parameter group: Resource Id Arguments
--name -n

Name of the Cosmos DB database account.

Property Value
Parameter group: Resource Id Arguments
--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Property Value
Parameter group: Resource Id Arguments
--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

Property Value
Parameter group: Resource Id Arguments
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az cosmosdb identity show

Preview

Command group 'cosmosdb identity' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Show the identities for an Azure Cosmos DB database account.

az cosmosdb identity show [--ids]
                          [--name]
                          [--resource-group]
                          [--subscription]

Examples

Show the identities for an Azure Cosmos DB database account.

az cosmosdb identity show --name MyCosmosDBDatabaseAccount --resource-group MyResourceGroup

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--ids

One or more resource IDs (space-delimited). It should be a complete resource ID containing all information of 'Resource Id' arguments. You should provide either --ids or other 'Resource Id' arguments.

Property Value
Parameter group: Resource Id Arguments
--name -n

Name of the Cosmos DB database account.

Property Value
Parameter group: Resource Id Arguments
--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Property Value
Parameter group: Resource Id Arguments
--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

Property Value
Parameter group: Resource Id Arguments
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False