az iot adr ns device auth

Note

This reference is part of the azure-iot extension for the Azure CLI (version 2.73.0 or higher). The extension will automatically install the first time you run an az iot adr ns device auth command. Learn more about extensions.

Command group 'iot adr ns device' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Inspect service-materialized authentication profiles.

Profiles are read-only metadata; use the provisioning service to issue credentials.

Commands

Name Description Type Status
az iot adr ns device auth list

List authentication profile metadata, not plaintext keys.

Extension Preview
az iot adr ns device auth revoke-certs

Revoke certificates for a CA-signed X.509 profile.

Extension Preview
az iot adr ns device auth show

Get authentication profile metadata.

Extension Preview
az iot adr ns device auth show-keys

Retrieve plaintext keys for a SymmetricKey profile.

Extension Preview
az iot adr ns device auth wait

Wait for authentication profile materialization or a specified condition.

Extension Preview

az iot adr ns device auth list

Preview

Command group 'iot adr ns device auth' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

List authentication profile metadata, not plaintext keys.

az iot adr ns device auth list --device-name --dn --rdn --registry-device-name
                               --namespace --ns
                               --resource-group

Examples

Discover profile names.

az iot adr ns device auth list --rdn my-device --ns my-ns -g MyRG

Required Parameters

--device-name --dn --rdn --registry-device-name

Name of the parent Registry Device.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns device auth revoke-certs

Preview

Command group 'iot adr ns device auth' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Revoke certificates for a CA-signed X.509 profile.

Requires CertificateAuthoritySignedX509Certificate authentication. Self-signed X.509 and symmetric-key profiles are rejected. This action is destructive.

az iot adr ns device auth revoke-certs --apn --auth-profile-name --name
                                       --device-name --dn --rdn --registry-device-name
                                       --namespace --ns
                                       --resource-group
                                       [--acquire-policy-token]
                                       [--change-reference]
                                       [--no-wait]
                                       [--yes {false, true}]

Examples

Revoke certificates for an owned CA-issued profile.

az iot adr ns device auth revoke-certs -n my-profile --rdn my-device --ns my-ns -g MyRG --yes

Required Parameters

--apn --auth-profile-name --name -n

Name of the Registry Device auth.

--device-name --dn --rdn --registry-device-name

Name of the parent Registry Device.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--no-wait

Do not wait for the long-running operation to finish.

Property Value
Default value: False
--yes -y

Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.

Property Value
Accepted values: false, true
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns device auth show

Preview

Command group 'iot adr ns device auth' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Get authentication profile metadata.

az iot adr ns device auth show --apn --auth-profile-name --name
                               --device-name --dn --rdn --registry-device-name
                               --namespace --ns
                               --resource-group

Examples

Inspect a discovered profile.

az iot adr ns device auth show -n my-profile --rdn my-device --ns my-ns -g MyRG

Required Parameters

--apn --auth-profile-name --name -n

Name of the Registry Device auth.

--device-name --dn --rdn --registry-device-name

Name of the parent Registry Device.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns device auth show-keys

Preview

Command group 'iot adr ns device auth' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Retrieve plaintext keys for a SymmetricKey profile.

Output contains secrets. Store it securely; avoid shared logs. Other authentication types are rejected. List and show do not call the key action.

az iot adr ns device auth show-keys --apn --auth-profile-name --name
                                    --device-name --dn --rdn --registry-device-name
                                    --namespace --ns
                                    --resource-group
                                    [--acquire-policy-token]
                                    [--change-reference]

Examples

Retrieve keys for a discovered symmetric-key profile.

az iot adr ns device auth show-keys -n my-profile --rdn my-device --ns my-ns -g MyRG

Required Parameters

--apn --auth-profile-name --name -n

Name of the Registry Device auth.

--device-name --dn --rdn --registry-device-name

Name of the parent Registry Device.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False

az iot adr ns device auth wait

Preview

Command group 'iot adr ns device auth' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Wait for authentication profile materialization or a specified condition.

By default waits for GET to succeed. Profiles have no provisioningState; --created and --updated are not profile materialization predicates.

az iot adr ns device auth wait --apn --auth-profile-name --name
                               --device-name --dn --rdn --registry-device-name
                               --namespace --ns
                               --resource-group
                               [--acquire-policy-token]
                               [--change-reference]
                               [--created]
                               [--custom]
                               [--deleted]
                               [--exists]
                               [--interval]
                               [--timeout]
                               [--updated]

Examples

Wait for a discovered authentication profile.

az iot adr ns device auth wait -n my-profile --rdn my-device --ns my-ns -g MyRG --timeout 600 --interval 10

Required Parameters

--apn --auth-profile-name --name -n

Name of the Registry Device auth.

--device-name --dn --rdn --registry-device-name

Name of the parent Registry Device.

--namespace --ns

Name of the Device Registry namespace.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--created

Wait until provisioningState is Succeeded.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--custom

Wait until a custom JMESPath expression evaluates to true.

Property Value
Parameter group: Wait Condition Arguments
--deleted

Wait until the resource is deleted.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--exists

Wait until the resource exists.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--interval

Polling interval in seconds.

Property Value
Parameter group: Wait Condition Arguments
Default value: 30
--timeout

Polling budget in seconds, including GET time. An in-flight GET is bounded by transport timeouts and cannot be interrupted by this polling deadline.

Property Value
Parameter group: Wait Condition Arguments
Default value: 3600
--updated

Wait until provisioningState is Succeeded.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False