az iot adr ns link dps
Note
This reference is part of the azure-iot extension for the Azure CLI (version 2.73.0 or higher). The extension will automatically install the first time you run an az iot adr ns link dps command. Learn more about extensions.
Command group 'iot adr ns link' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Manage DPS links (provisioning endpoints) on a Device Registry namespace.
Only one DPS may be linked per namespace today. Links live on the namespace, not on the DPS resource. After deleting the DPS resource, run link dps remove to remove its namespace endpoint.
Commands
| Name | Description | Type | Status |
|---|---|---|---|
| az iot adr ns link dps add |
Link a Device Provisioning Service (DPS) to a Device Registry namespace. |
Extension | Preview |
| az iot adr ns link dps list |
List DPS provisioning endpoints on a Device Registry namespace. |
Extension | Preview |
| az iot adr ns link dps remove |
Remove a DPS endpoint from a Device Registry namespace. |
Extension | Preview |
| az iot adr ns link dps show |
Show a single DPS provisioning endpoint on a Device Registry namespace. |
Extension | Preview |
| az iot adr ns link dps update |
Update an existing DPS provisioning endpoint on a Device Registry namespace. |
Extension | Preview |
| az iot adr ns link dps wait |
Wait for a DPS endpoint to link successfully. |
Extension | Preview |
az iot adr ns link dps add
Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Link a Device Provisioning Service (DPS) to a Device Registry namespace.
Adds a DPS provisioning endpoint entry under the namespace's properties.provisioning.endpoints. Rejected if the namespace already has a linked DPS (one DPS per namespace). Exactly one of --system-assigned-mi or --user-assigned-mi must be provided. Required service-to-service roles: namespace outbound MI -> Contributor on DPS; DPS selected inbound MI -> Contributor on namespace; namespace system-assigned MI -> Azure Device Registry Administrator on namespace. The namespace must also have a system-assigned identity. It receives Azure Device Registry Administrator on its own namespace for registry-device provisioning, even when the namespace outbound identity is user-assigned. No role is granted to the signed-in caller; DPS enrollment management with --auth-type login requires separate DPS data-plane access. The command reuses inherited assignments and creates only missing assignments when run by a caller who can create role assignments (for example Owner, User Access Administrator, or Role Based Access Control Administrator). Otherwise it stops before changing the namespace and prints the exact commands to run. A newly created assignment must become visible within 180 seconds.
az iot adr ns link dps add --dps-id --dps-resource-id
--en --endpoint-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--interval]
[--mi-sa --system-assigned-mi {false, true}]
[--mi-ua --user-assigned-mi]
[--no-wait]
[--timeout]
Examples
Link a DPS using the DPS resource's system-assigned identity
az iot adr ns link dps add -n primary --ns myNamespace -g myResourceGroup \
--dps-id /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Devices/provisioningServices/<dps> \
--system-assigned-mi
Link a DPS with a user-assigned identity
az iot adr ns link dps add -n primary --ns myNamespace -g myResourceGroup \
--dps-id /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Devices/provisioningServices/<dps> \
--user-assigned-mi /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<id>
Required Parameters
Azure resource ID of the Device Provisioning Service to link to this namespace.
Logical name of the provisioning endpoint entry on the namespace.
Name of the Device Registry namespace that owns the link.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Positive polling interval in seconds. Default: 30.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 30 |
Use the linked DPS resource's system-assigned identity as the inbound caller identity. DPS must have that identity enabled.
| Property | Value |
|---|---|
| Parameter group: | Inbound Caller Identity Arguments |
| Default value: | False |
| Accepted values: | false, true |
Resource ID of a user-assigned identity attached to the linked DPS resource.
| Property | Value |
|---|---|
| Parameter group: | Inbound Caller Identity Arguments |
Return after submission without observing endpoint readiness or recovering later failures.
| Property | Value |
|---|---|
| Default value: | False |
Positive mutation/recovery budget in seconds after initial RBAC preflight. Default: 600.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 600 |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns link dps list
Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
List DPS provisioning endpoints on a Device Registry namespace.
az iot adr ns link dps list --namespace --ns
--resource-group
Examples
List all DPS links on a namespace
az iot adr ns link dps list --ns myNamespace -g myResourceGroup
List endpoint names and linking states
az iot adr ns link dps list --ns myNamespace -g myResourceGroup --query "[].{name:name,linkingState:linkingState}"
List failed DPS endpoints
az iot adr ns link dps list --ns myNamespace -g myResourceGroup --query "[?linkingState=='Failed']"
Required Parameters
Name of the Device Registry namespace that owns the link.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns link dps remove
Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Remove a DPS endpoint from a Device Registry namespace.
Delete the linked DPS first; this command removes only the namespace endpoint. The namespace outbound identity needs Reader on the linked resource's resource group. A missing grant is created when you can create role assignments; it is kept after unlinking. Keep that resource group until the unlink completes. The command does not wait. Confirm removal with 'az iot adr ns show'. Avoid concurrent namespace updates while this command runs.
az iot adr ns link dps remove --en --endpoint-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--yes {false, true}]
Examples
Remove an endpoint after its linked DPS has been deleted
az iot adr ns link dps remove -n primary --ns myNamespace -g myResourceGroup --yes
Required Parameters
Logical name of the provisioning endpoint entry on the namespace.
Name of the Device Registry namespace that owns the link.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.
| Property | Value |
|---|---|
| Accepted values: | false, true |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns link dps show
Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Show a single DPS provisioning endpoint on a Device Registry namespace.
Inspect the named endpoint and decide which existing DPS Hubs to link to the namespace. When the DPS read succeeds, brownfieldHubs contains its properties.iotHubs[] list and brownfieldHubsAvailable is true. An empty list then means no Hubs are registered. If access or a service failure prevents that read, brownfieldHubs is null, brownfieldHubsAvailable is false, and a warning explains why. Namespace inspection still succeeds; unavailable data must not be treated as an empty DPS registration list.
az iot adr ns link dps show --en --endpoint-name --name
--namespace --ns
--resource-group
Examples
Show a DPS link by endpoint name (with brownfield Hubs when accessible)
az iot adr ns link dps show -n primary --ns myNamespace -g myResourceGroup
Show the endpoint linking state
az iot adr ns link dps show -n primary --ns myNamespace -g myResourceGroup --query linkingState -o tsv
Required Parameters
Logical name of the provisioning endpoint entry on the namespace.
Name of the Device Registry namespace that owns the link.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns link dps update
Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Update an existing DPS provisioning endpoint on a Device Registry namespace.
Retry a Failed DPS endpoint without identity options to reuse its saved inbound identity. Pass --system-assigned-mi or --user-assigned-mi to change that identity. A healthy endpoint requires an explicit change; the target DPS cannot be changed in place. Update checks target existence, region, provisioning-state, selected identity attachment, namespace outbound principal, automatic RBAC, and assignment-visibility preflight. DPS preflight also ensures the namespace system-assigned identity has Azure Device Registry Administrator on its own namespace, independently of the namespace outbound identity. ARM assignment visibility does not guarantee that the linked service already honors access. Waited add/update commands recover only confirmed AdrMiNotAuthorized on the unchanged endpoint, rechecking required assignments and preserving identity and settings. --timeout (600 seconds) bounds mutation, polling and 30/60/120-second propagation backoff after initial RBAC preflight; --interval (30 seconds) controls polling. Success requires endpoint linkingState Succeeded. With --no-wait, use the matching link wait command to track completion. Use update, not add, for a persisted failure. Do not delete the linked DPS to retry it.
az iot adr ns link dps update --en --endpoint-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--interval]
[--mi-sa --system-assigned-mi {false, true}]
[--mi-ua --user-assigned-mi]
[--no-wait]
[--timeout]
Examples
Rotate to a system-assigned identity on an existing DPS link
az iot adr ns link dps update -n primary --ns myNamespace -g myResourceGroup --system-assigned-mi
Required Parameters
Logical name of the provisioning endpoint entry on the namespace.
Name of the Device Registry namespace that owns the link.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Positive polling interval in seconds. Default: 30.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
Use the linked DPS resource's system-assigned identity as the inbound caller identity. DPS must have that identity enabled.
| Property | Value |
|---|---|
| Parameter group: | Inbound Caller Identity Arguments |
| Default value: | False |
| Accepted values: | false, true |
Resource ID of a user-assigned identity attached to the linked DPS resource.
| Property | Value |
|---|---|
| Parameter group: | Inbound Caller Identity Arguments |
Return after submission without observing endpoint readiness or recovering later failures.
| Property | Value |
|---|---|
| Default value: | False |
Positive mutation/recovery budget in seconds after initial RBAC preflight. Default: 600.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |
az iot adr ns link dps wait
Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
Wait for a DPS endpoint to link successfully.
The endpoint name is required. Without an explicit wait predicate, this command polls that endpoint's linkingState and fails immediately if it reaches Failed.
az iot adr ns link dps wait --en --endpoint-name --name
--namespace --ns
--resource-group
[--acquire-policy-token]
[--change-reference]
[--created]
[--custom]
[--deleted]
[--exists]
[--interval]
[--timeout]
[--updated]
Examples
Wait until a DPS endpoint reaches linkingState Succeeded
az iot adr ns link dps wait -n primary --ns myNamespace -g myResourceGroup
Required Parameters
Logical name of the provisioning endpoint entry on the namespace.
Name of the Device Registry namespace that owns the link.
Name of resource group. You can configure the default group using az configure --defaults group=<name>.
Optional Parameters
The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.
Acquiring an Azure Policy token automatically for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
The related change reference ID for this resource operation.
| Property | Value |
|---|---|
| Parameter group: | Global Policy Arguments |
Wait until provisioningState is Succeeded.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Wait until a custom JMESPath expression evaluates to true.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
Wait until the resource is deleted.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Wait until the resource exists.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Polling interval in seconds.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 30 |
Polling budget in seconds, including GET time. An in-flight GET is bounded by transport timeouts and cannot be interrupted by this polling deadline.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | 3600 |
Wait until provisioningState is Succeeded.
| Property | Value |
|---|---|
| Parameter group: | Wait Condition Arguments |
| Default value: | False |
Global Parameters
Increase logging verbosity to show all debug logs.
| Property | Value |
|---|---|
| Default value: | False |
Show this help message and exit.
Only show errors, suppressing warnings.
| Property | Value |
|---|---|
| Default value: | False |
Output format.
| Property | Value |
|---|---|
| Default value: | json |
| Accepted values: | json, jsonc, none, table, tsv, yaml, yamlc |
JMESPath query string. See http://jmespath.org/ for more information and examples.
Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.
Increase logging verbosity. Use --debug for full debug logs.
| Property | Value |
|---|---|
| Default value: | False |