Azure Key Vault
Publishes and manages certificates in Azure Key Vaults. Can be created manually via the Stores screen or automatically via Azure Discovery.
Create via the Stores screen
Step 1 — Provider
Select Azure Key Vault.
Step 2 — Integration
Select the Azure integration registered in Integrations.
Step 3 — Configuration
Select the target Resource Group and Key Vault. The CLM displays the vault URL for confirmation.
Step 4 — Review
Set the Repository Name (e.g. Azure KeyVault - qa4-kv-clm), confirm the settings, and click Create Repository.
Store details
After creating it, the details screen displays:
| Card | Description |
|---|---|
| Total | Total certificates in the Key Vault |
| Expiring | Certificates nearing expiration |
Azure Integration Section (Read-only) — displays the data from the linked integration (Tenant ID, Subscription ID, Client ID). To change the account, you must create a new repository.
Key Vault Settings Section (Read-only) — displays Resource Group, Key Vault Name, and Vault URL. Automatically retrieved from Azure.
Metadata Section — editable fields for organization:
| Field | Description |
|---|---|
| Tags | Free-form, comma-separated tags, e.g. production, critical, azure |
| Owner | Name of the person responsible for the Store |
| Department | Responsible department or team |
Logs and Audit Section — configure the log level (Info, Warning, and Error) and retention (default: 90 days).
Install a certificate
On the details screen, click Install Certificate, select the certificate from the inventory, and confirm. The CLM publishes the certificate to the Key Vault automatically.
The Installed Certificates list shows all certificates present in the vault with issuer, issuance date, validity, bind status, and the result of the last deploy.