az iot adr ns link dps

Note

This reference is part of the azure-iot extension for the Azure CLI (version 2.73.0 or higher). The extension will automatically install the first time you run an az iot adr ns link dps command. Learn more about extensions.

Command group 'iot adr ns link' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Manage DPS links (provisioning endpoints) on a Device Registry namespace.

Only one DPS may be linked per namespace today. Links live on the namespace, not on the DPS resource. After deleting the DPS resource, run link dps remove to remove its namespace endpoint.

Commands

Name Description Type Status
az iot adr ns link dps add

Link a Device Provisioning Service (DPS) to a Device Registry namespace.

Extension Preview
az iot adr ns link dps list

List DPS provisioning endpoints on a Device Registry namespace.

Extension Preview
az iot adr ns link dps remove

Remove a DPS endpoint from a Device Registry namespace.

Extension Preview
az iot adr ns link dps show

Show a single DPS provisioning endpoint on a Device Registry namespace.

Extension Preview
az iot adr ns link dps update

Update an existing DPS provisioning endpoint on a Device Registry namespace.

Extension Preview
az iot adr ns link dps wait

Wait for a DPS endpoint to link successfully.

Extension Preview
Preview

Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Link a Device Provisioning Service (DPS) to a Device Registry namespace.

Adds a DPS provisioning endpoint entry under the namespace's properties.provisioning.endpoints. Rejected if the namespace already has a linked DPS (one DPS per namespace). Exactly one of --system-assigned-mi or --user-assigned-mi must be provided. Required service-to-service roles: namespace outbound MI -> Contributor on DPS; DPS selected inbound MI -> Contributor on namespace; namespace system-assigned MI -> Azure Device Registry Administrator on namespace. The namespace must also have a system-assigned identity. It receives Azure Device Registry Administrator on its own namespace for registry-device provisioning, even when the namespace outbound identity is user-assigned. No role is granted to the signed-in caller; DPS enrollment management with --auth-type login requires separate DPS data-plane access. The command reuses inherited assignments and creates only missing assignments when run by a caller who can create role assignments (for example Owner, User Access Administrator, or Role Based Access Control Administrator). Otherwise it stops before changing the namespace and prints the exact commands to run. A newly created assignment must become visible within 180 seconds.

az iot adr ns link dps add --dps-id --dps-resource-id
                           --en --endpoint-name --name
                           --namespace --ns
                           --resource-group
                           [--acquire-policy-token]
                           [--change-reference]
                           [--interval]
                           [--mi-sa --system-assigned-mi {false, true}]
                           [--mi-ua --user-assigned-mi]
                           [--no-wait]
                           [--timeout]

Link a DPS using the DPS resource's system-assigned identity

az iot adr ns link dps add -n primary --ns myNamespace -g myResourceGroup \
  --dps-id /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Devices/provisioningServices/<dps> \
  --system-assigned-mi

Link a DPS with a user-assigned identity

az iot adr ns link dps add -n primary --ns myNamespace -g myResourceGroup \
  --dps-id /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Devices/provisioningServices/<dps> \
  --user-assigned-mi /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<id>
--dps-id --dps-resource-id

Azure resource ID of the Device Provisioning Service to link to this namespace.

--en --endpoint-name --name -n

Logical name of the provisioning endpoint entry on the namespace.

--namespace --ns

Name of the Device Registry namespace that owns the link.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--interval

Positive polling interval in seconds. Default: 30.

Property Value
Parameter group: Wait Condition Arguments
Default value: 30
--mi-sa --system-assigned-mi

Use the linked DPS resource's system-assigned identity as the inbound caller identity. DPS must have that identity enabled.

Property Value
Parameter group: Inbound Caller Identity Arguments
Default value: False
Accepted values: false, true
--mi-ua --user-assigned-mi

Resource ID of a user-assigned identity attached to the linked DPS resource.

Property Value
Parameter group: Inbound Caller Identity Arguments
--no-wait

Return after submission without observing endpoint readiness or recovering later failures.

Property Value
Default value: False
--timeout

Positive mutation/recovery budget in seconds after initial RBAC preflight. Default: 600.

Property Value
Parameter group: Wait Condition Arguments
Default value: 600
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False
Preview

Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

List DPS provisioning endpoints on a Device Registry namespace.

az iot adr ns link dps list --namespace --ns
                            --resource-group

List all DPS links on a namespace

az iot adr ns link dps list --ns myNamespace -g myResourceGroup

List endpoint names and linking states

az iot adr ns link dps list --ns myNamespace -g myResourceGroup --query "[].{name:name,linkingState:linkingState}"

List failed DPS endpoints

az iot adr ns link dps list --ns myNamespace -g myResourceGroup --query "[?linkingState=='Failed']"
--namespace --ns

Name of the Device Registry namespace that owns the link.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False
Preview

Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Remove a DPS endpoint from a Device Registry namespace.

Delete the linked DPS first; this command removes only the namespace endpoint. The namespace outbound identity needs Reader on the linked resource's resource group. A missing grant is created when you can create role assignments; it is kept after unlinking. Keep that resource group until the unlink completes. The command does not wait. Confirm removal with 'az iot adr ns show'. Avoid concurrent namespace updates while this command runs.

az iot adr ns link dps remove --en --endpoint-name --name
                              --namespace --ns
                              --resource-group
                              [--acquire-policy-token]
                              [--change-reference]
                              [--yes {false, true}]

Remove an endpoint after its linked DPS has been deleted

az iot adr ns link dps remove -n primary --ns myNamespace -g myResourceGroup --yes
--en --endpoint-name --name -n

Logical name of the provisioning endpoint entry on the namespace.

--namespace --ns

Name of the Device Registry namespace that owns the link.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--yes -y

Skip user prompts. Indicates acceptance of action. Used primarily for automation scenarios. Default: false.

Property Value
Accepted values: false, true
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False
Preview

Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Show a single DPS provisioning endpoint on a Device Registry namespace.

Inspect the named endpoint and decide which existing DPS Hubs to link to the namespace. When the DPS read succeeds, brownfieldHubs contains its properties.iotHubs[] list and brownfieldHubsAvailable is true. An empty list then means no Hubs are registered. If access or a service failure prevents that read, brownfieldHubs is null, brownfieldHubsAvailable is false, and a warning explains why. Namespace inspection still succeeds; unavailable data must not be treated as an empty DPS registration list.

az iot adr ns link dps show --en --endpoint-name --name
                            --namespace --ns
                            --resource-group

Show a DPS link by endpoint name (with brownfield Hubs when accessible)

az iot adr ns link dps show -n primary --ns myNamespace -g myResourceGroup

Show the endpoint linking state

az iot adr ns link dps show -n primary --ns myNamespace -g myResourceGroup --query linkingState -o tsv
--en --endpoint-name --name -n

Logical name of the provisioning endpoint entry on the namespace.

--namespace --ns

Name of the Device Registry namespace that owns the link.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False
Preview

Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Update an existing DPS provisioning endpoint on a Device Registry namespace.

Retry a Failed DPS endpoint without identity options to reuse its saved inbound identity. Pass --system-assigned-mi or --user-assigned-mi to change that identity. A healthy endpoint requires an explicit change; the target DPS cannot be changed in place. Update checks target existence, region, provisioning-state, selected identity attachment, namespace outbound principal, automatic RBAC, and assignment-visibility preflight. DPS preflight also ensures the namespace system-assigned identity has Azure Device Registry Administrator on its own namespace, independently of the namespace outbound identity. ARM assignment visibility does not guarantee that the linked service already honors access. Waited add/update commands recover only confirmed AdrMiNotAuthorized on the unchanged endpoint, rechecking required assignments and preserving identity and settings. --timeout (600 seconds) bounds mutation, polling and 30/60/120-second propagation backoff after initial RBAC preflight; --interval (30 seconds) controls polling. Success requires endpoint linkingState Succeeded. With --no-wait, use the matching link wait command to track completion. Use update, not add, for a persisted failure. Do not delete the linked DPS to retry it.

az iot adr ns link dps update --en --endpoint-name --name
                              --namespace --ns
                              --resource-group
                              [--acquire-policy-token]
                              [--change-reference]
                              [--interval]
                              [--mi-sa --system-assigned-mi {false, true}]
                              [--mi-ua --user-assigned-mi]
                              [--no-wait]
                              [--timeout]

Rotate to a system-assigned identity on an existing DPS link

az iot adr ns link dps update -n primary --ns myNamespace -g myResourceGroup --system-assigned-mi
--en --endpoint-name --name -n

Logical name of the provisioning endpoint entry on the namespace.

--namespace --ns

Name of the Device Registry namespace that owns the link.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--interval

Positive polling interval in seconds. Default: 30.

Property Value
Parameter group: Wait Condition Arguments
--mi-sa --system-assigned-mi

Use the linked DPS resource's system-assigned identity as the inbound caller identity. DPS must have that identity enabled.

Property Value
Parameter group: Inbound Caller Identity Arguments
Default value: False
Accepted values: false, true
--mi-ua --user-assigned-mi

Resource ID of a user-assigned identity attached to the linked DPS resource.

Property Value
Parameter group: Inbound Caller Identity Arguments
--no-wait

Return after submission without observing endpoint readiness or recovering later failures.

Property Value
Default value: False
--timeout

Positive mutation/recovery budget in seconds after initial RBAC preflight. Default: 600.

Property Value
Parameter group: Wait Condition Arguments
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False
Preview

Command group 'iot adr ns link dps' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus

Wait for a DPS endpoint to link successfully.

The endpoint name is required. Without an explicit wait predicate, this command polls that endpoint's linkingState and fails immediately if it reaches Failed.

az iot adr ns link dps wait --en --endpoint-name --name
                            --namespace --ns
                            --resource-group
                            [--acquire-policy-token]
                            [--change-reference]
                            [--created]
                            [--custom]
                            [--deleted]
                            [--exists]
                            [--interval]
                            [--timeout]
                            [--updated]

Wait until a DPS endpoint reaches linkingState Succeeded

az iot adr ns link dps wait -n primary --ns myNamespace -g myResourceGroup
--en --endpoint-name --name -n

Logical name of the provisioning endpoint entry on the namespace.

--namespace --ns

Name of the Device Registry namespace that owns the link.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

The following parameters are optional, but depending on the context, one or more might become required for the command to execute successfully.

--acquire-policy-token

Acquiring an Azure Policy token automatically for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--change-reference

The related change reference ID for this resource operation.

Property Value
Parameter group: Global Policy Arguments
--created

Wait until provisioningState is Succeeded.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--custom

Wait until a custom JMESPath expression evaluates to true.

Property Value
Parameter group: Wait Condition Arguments
--deleted

Wait until the resource is deleted.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--exists

Wait until the resource exists.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
--interval

Polling interval in seconds.

Property Value
Parameter group: Wait Condition Arguments
Default value: 30
--timeout

Polling budget in seconds, including GET time. An in-flight GET is bounded by transport timeouts and cannot be interrupted by this polling deadline.

Property Value
Parameter group: Wait Condition Arguments
Default value: 3600
--updated

Wait until provisioningState is Succeeded.

Property Value
Parameter group: Wait Condition Arguments
Default value: False
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

Property Value
Default value: False
--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

Property Value
Default value: False
--output -o

Output format.

Property Value
Default value: json
Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

Property Value
Default value: False