Skip to content

Add a Cloud Keystore to Azure Key Vault

Before you begin

  1. Sign in to Venafi Control Plane.
  2. Click Installations > Cloud Keystores.
  3. Click New and select Azure.
  4. Enter a Name for the new cloud keystore.
  5. Select an Owning Team. If you need to create a new team, see create a new team.
  6. Select an Authorized Team.

    Note

    • Owning Team - The Owning Team is responsible for the administration, management, and control of a designated cloud provider, with the authority to update, modify, and delete cloud provider resources.
    • Authorized Team - The Authorize Team is granted permission to use specific resources of a cloud provider. Although team members can perform tasks like creating a keystore, their permissions may be limited regarding broader modifications to the provider's configuration. Unlike the Owning Team, users may not have the authority to update and delete Cloud Providers.
  7. Select an Azure Cloud Provider.

  8. Select a Subscription Name.
  9. Select an Azure Key Vault Name.
  10. (Optional) To begin discovery once the keystore is created, an option to discover certificates on your keystore, select the toggle switches to turn on toggle "Start discovery immediately" and "Include expired certificates". After creating the keystore, refer to Set up AKV Discovery Schedule to create your schedule.
  11. Click Save. At this point you should see your saved new cloud keystore in the Cloud Keystore list.
  12. (Optional) If you didn't start discovery when creating the keystore in the above step, click the Discover Now button. You will notice a message in the top right of the pane indicating "Discovery Status: Running". Your results will begin to populate in the same pane.