Azure CLI Command Center

Understand an Azure CLI command before you run it

Search an az command, command group, or Azure task. AzureGlossary shows what the command touches, how risky it is, which concepts explain it, and what safer checks and generated safe-first paths to run first.

Microsoft Learn remains the official Azure CLI reference. This page is the plain-English command map for safety, context, operator review, and safe-first command paths.

5,357 indexed az commands 630 command groups 3,504 read-only checks 1,853 commands needing review
Command group service map

az keyvault secret

az keyvault secret commands for AI and Machine Learning; browse safety labels, operation lanes, mapped Azure concepts, and safe-first examples.

13 commands11 mapped termsAI and Machine Learning
Safety mix
read-only: 7security-impacting: 4destructive: 1mutating: 1
Operation mix
discover: 8secure: 4remove: 1
Command group map

Start with these commands in az keyvault secret

read-onlyaz keyvault secret list --vault-name <key-vault>

Inspect or list keyvault secret with the Azure CLI before making changes.

discoverlist
read-onlyaz keyvault secret list --vault-name <vault-name> --output table

List existing resources or configuration for this Azure concept.

discoverlist
read-onlyaz keyvault secret list --vault-name <vault-name> --query "[].name"

Inspect or list keyvault secret with the Azure CLI before making changes.

discoverlist
security-impactingaz keyvault secret list --vault-name <vault-name> --query "[].{name:name,enabled:attributes.enabled}" --output table

Change identity, access, policy, or security-sensitive configuration for keyvault secret.

discoverlist
read-onlyaz keyvault secret list-versions --vault-name <vault-name> --name <secret-name> --output table

Inspect or list keyvault secret with the Azure CLI before making changes.

discoverlist-versions
security-impactingaz keyvault secret set --vault-name <vault-name> --name <secret-name> --value <new-key>

Change identity, access, policy, or security-sensitive configuration for keyvault secret.

secureset
security-impactingaz keyvault secret set --vault-name <vault-name> --name <secret-name> --value <secret-value>

Create or configure this resource. Review parameters before running in production.

secureset
destructiveaz keyvault secret set --vault-name <vault> --name <secret-name> --value <key-value>

Delete or remove keyvault secret with the Azure CLI; verify scope and backup/rollback before running.

removeset
mutatingaz keyvault secret set --vault-name <vault> --name <secret-name> --value <secret-value>

Create, update, or operate keyvault secret with the Azure CLI.

secureset
security-impactingaz keyvault secret set-attributes --vault-name <vault-name> --name <secret-name> --enabled false

Change identity, access, policy, or security-sensitive configuration for keyvault secret.

secureset-attributes
read-onlyaz keyvault secret show --vault-name <vault-name> --name <secret-name>

Show details for a specific resource or setting.

discovershow
read-onlyaz keyvault secret show --vault-name <vault-name> --name <secret-name> --query "{id:id, enabled:attributes.enabled, expires:attributes.expires, created:attributes.created, updated:attributes.updated}"

Inspect or list keyvault secret with the Azure CLI before making changes.

discovershow
Command Center

Which Azure CLI command are you trying to understand?

Start with a command, group, or messy task. The Command Center gives you a briefing before you copy anything: risk, touched services, safe-first paths, related concepts, and the official Microsoft Learn reference.

Advanced filtersCommand group, safety, operation lane, service area, and relationship type
0 matching commandsSearch for a command, choose a command job, or browse a command group
Service maps

Browse by the Azure surface the command touches

Search for a command or choose a command job

Try a real command such as az role assignment list, a group such as az aks, or a task such as private endpoint. Results open as command briefing cards.

Command briefings

Mapped command results

Each card explains the command, what it touches, whether it is safe for discovery, and the safe-first path to run before risky changes.

Starter command flowsOptional guided examples for resource groups, web apps, storage, AKS, SQL, and Key Vault.

AKS operations path

Inspect AKS state, credentials, node pools, upgrades, monitoring, and destructive operations from one lane.

Data platform lifecycle

Navigate database, analytics, messaging, and AI commands from discovery to controlled mutation.

Identity and access change path

Inspect identities and assignments before making privileged RBAC, managed identity, or credential changes.

Resource group lifecycle

Start with read-only discovery, create only after context checks, then clean up deliberately.

Storage hardening and access

Discover storage accounts, then check network, identity, lifecycle, container, and destructive cleanup commands.

Web app release operations

Move from App Service discovery through deployment, slot checks, diagnostics, and guarded rollback.

Safety and operation legendReference definitions for labels used on command briefing cards.

Safety labels

Operation lanes