Microsoft.Storage contextCaches 2026-06-01

Bicep resource definition

The contextCaches resource type can be deployed with operations that target:

For a list of changed properties in each API version, see change log.

Resource format

To create a Microsoft.Storage/contextCaches resource, add the following Bicep to your template.

resource symbolicname 'Microsoft.Storage/contextCaches@2026-06-01' = {
  identity: {
    type: 'string'
  }
  location: 'string'
  name: 'string'
  properties: {
    accountKind: 'string'
    description: 'string'
    encryption: {
      customerManagedKeyEncryption: {
        keyEncryptionKeyIdentity: {
          delegatedIdentityClientId: 'string'
          federatedClientId: 'string'
          identityType: 'string'
          userAssignedIdentityResourceId: 'string'
        }
        keyEncryptionKeyUrl: 'string'
      }
      infrastructureEncryption: 'string'
    }
  }
  tags: {
    {customized property}: 'string'
  }
}

Property Values

Microsoft.Storage/contextCaches

Name Description Value
identity The managed service identities assigned to this resource. SystemAssignedServiceIdentity
location The geo-location where the resource lives string (required)
name The resource name string

Constraints:
Pattern = ^[a-z0-9][a-z0-9-]{1,22}[a-z0-9]$ (required)
properties The resource-specific properties for this resource. ContextCacheProperties (required)
tags Resource tags Dictionary of tag names and values. See Tags in templates

AzureResourceManagerCommonTypesCustomerManagedKeyEncryption

Name Description Value
keyEncryptionKeyIdentity All identity configuration for Customer-managed key settings defining which identity should be used to auth to Key Vault. AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity
keyEncryptionKeyUrl key encryption key Url, versioned or non-versioned. Ex: https://contosovault.vault.azure.net/keys/contosokek/562a4bb76b524a1493a6afe8e536ee78 or https://contosovault.vault.azure.net/keys/contosokek. string

AzureResourceManagerCommonTypesEncryption

Name Description Value
customerManagedKeyEncryption All Customer-managed key encryption properties for the resource. AzureResourceManagerCommonTypesCustomerManagedKeyEncryption
infrastructureEncryption Values are enabled and disabled. 'disabled'
'enabled'

AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity

Name Description Value
delegatedIdentityClientId delegated identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId. Mutually exclusive with identityType systemAssignedIdentity and userAssignedIdentity - internal use only. string

Constraints:
Min length = 36
Max length = 36
Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
federatedClientId application client identity to use for accessing key encryption key Url in a different tenant. Ex: f83c6b1b-4d34-47e4-bb34-9d83df58b540 string

Constraints:
Min length = 36
Max length = 36
Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
identityType The type of identity to use. Values can be systemAssignedIdentity, userAssignedIdentity, or delegatedResourceIdentity. 'delegatedResourceIdentity'
'systemAssignedIdentity'
'userAssignedIdentity'
userAssignedIdentityResourceId User assigned identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId. Mutually exclusive with identityType systemAssignedIdentity. string

ContextCacheProperties

Name Description Value
accountKind The kind of account determining storage topology. 'DataZone'
'Global'
'Regional' (required)
description Account description. string

Constraints:
Max length = 250
encryption Encryption settings for the account. AzureResourceManagerCommonTypesEncryption

SystemAssignedServiceIdentity

Name Description Value
type Type of managed service identity (either system assigned, or none). 'None'
'SystemAssigned' (required)

TrackedResourceTags

Name Description Value

ARM template resource definition

The contextCaches resource type can be deployed with operations that target:

Usage Examples

Resource format

To create a Microsoft.Storage/contextCaches resource, add the following JSON to your template.

{
  "type": "Microsoft.Storage/contextCaches",
  "apiVersion": "2026-06-01",
  "name": "string",
  "identity": {
    "type": "string"
  },
  "location": "string",
  "properties": {
    "accountKind": "string",
    "description": "string",
    "encryption": {
      "customerManagedKeyEncryption": {
        "keyEncryptionKeyIdentity": {
          "delegatedIdentityClientId": "string",
          "federatedClientId": "string",
          "identityType": "string",
          "userAssignedIdentityResourceId": "string"
        },
        "keyEncryptionKeyUrl": "string"
      },
      "infrastructureEncryption": "string"
    }
  },
  "tags": {
    "{customized property}": "string"
  }
}

Property Values

Microsoft.Storage/contextCaches

Name Description Value
apiVersion The api version '2026-06-01'
identity The managed service identities assigned to this resource. SystemAssignedServiceIdentity
location The geo-location where the resource lives string (required)
name The resource name string

Constraints:
Pattern = ^[a-z0-9][a-z0-9-]{1,22}[a-z0-9]$ (required)
properties The resource-specific properties for this resource. ContextCacheProperties (required)
tags Resource tags Dictionary of tag names and values. See Tags in templates
type The resource type 'Microsoft.Storage/contextCaches'

AzureResourceManagerCommonTypesCustomerManagedKeyEncryption

Name Description Value
keyEncryptionKeyIdentity All identity configuration for Customer-managed key settings defining which identity should be used to auth to Key Vault. AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity
keyEncryptionKeyUrl key encryption key Url, versioned or non-versioned. Ex: https://contosovault.vault.azure.net/keys/contosokek/562a4bb76b524a1493a6afe8e536ee78 or https://contosovault.vault.azure.net/keys/contosokek. string

AzureResourceManagerCommonTypesEncryption

Name Description Value
customerManagedKeyEncryption All Customer-managed key encryption properties for the resource. AzureResourceManagerCommonTypesCustomerManagedKeyEncryption
infrastructureEncryption Values are enabled and disabled. 'disabled'
'enabled'

AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity

Name Description Value
delegatedIdentityClientId delegated identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId. Mutually exclusive with identityType systemAssignedIdentity and userAssignedIdentity - internal use only. string

Constraints:
Min length = 36
Max length = 36
Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
federatedClientId application client identity to use for accessing key encryption key Url in a different tenant. Ex: f83c6b1b-4d34-47e4-bb34-9d83df58b540 string

Constraints:
Min length = 36
Max length = 36
Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
identityType The type of identity to use. Values can be systemAssignedIdentity, userAssignedIdentity, or delegatedResourceIdentity. 'delegatedResourceIdentity'
'systemAssignedIdentity'
'userAssignedIdentity'
userAssignedIdentityResourceId User assigned identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId. Mutually exclusive with identityType systemAssignedIdentity. string

ContextCacheProperties

Name Description Value
accountKind The kind of account determining storage topology. 'DataZone'
'Global'
'Regional' (required)
description Account description. string

Constraints:
Max length = 250
encryption Encryption settings for the account. AzureResourceManagerCommonTypesEncryption

SystemAssignedServiceIdentity

Name Description Value
type Type of managed service identity (either system assigned, or none). 'None'
'SystemAssigned' (required)

TrackedResourceTags

Name Description Value

Terraform (AzAPI provider) resource definition

The contextCaches resource type can be deployed with operations that target:

  • Resource groups For a list of changed properties in each API version, see change log.

Resource format

To create a Microsoft.Storage/contextCaches resource, add the following Terraform to your template.

resource "azapi_resource" "symbolicname" {
  type = "Microsoft.Storage/contextCaches@2026-06-01"
  name = "string"
  parent_id = "string"
  identity {
    type = "string"
    identity_ids = [
      "string"
    ]
  }
  location = "string"
  tags = {
    {customized property} = "string"
  }
  body = {
    properties = {
      accountKind = "string"
      description = "string"
      encryption = {
        customerManagedKeyEncryption = {
          keyEncryptionKeyIdentity = {
            delegatedIdentityClientId = "string"
            federatedClientId = "string"
            identityType = "string"
            userAssignedIdentityResourceId = "string"
          }
          keyEncryptionKeyUrl = "string"
        }
        infrastructureEncryption = "string"
      }
    }
  }
}

Property Values

Microsoft.Storage/contextCaches

Name Description Value
identity The managed service identities assigned to this resource. SystemAssignedServiceIdentity
location The geo-location where the resource lives string (required)
name The resource name string

Constraints:
Pattern = ^[a-z0-9][a-z0-9-]{1,22}[a-z0-9]$ (required)
properties The resource-specific properties for this resource. ContextCacheProperties (required)
tags Resource tags Dictionary of tag names and values.
type The resource type "Microsoft.Storage/contextCaches@2026-06-01"

AzureResourceManagerCommonTypesCustomerManagedKeyEncryption

Name Description Value
keyEncryptionKeyIdentity All identity configuration for Customer-managed key settings defining which identity should be used to auth to Key Vault. AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity
keyEncryptionKeyUrl key encryption key Url, versioned or non-versioned. Ex: https://contosovault.vault.azure.net/keys/contosokek/562a4bb76b524a1493a6afe8e536ee78 or https://contosovault.vault.azure.net/keys/contosokek. string

AzureResourceManagerCommonTypesEncryption

Name Description Value
customerManagedKeyEncryption All Customer-managed key encryption properties for the resource. AzureResourceManagerCommonTypesCustomerManagedKeyEncryption
infrastructureEncryption Values are enabled and disabled. 'disabled'
'enabled'

AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity

Name Description Value
delegatedIdentityClientId delegated identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId. Mutually exclusive with identityType systemAssignedIdentity and userAssignedIdentity - internal use only. string

Constraints:
Min length = 36
Max length = 36
Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
federatedClientId application client identity to use for accessing key encryption key Url in a different tenant. Ex: f83c6b1b-4d34-47e4-bb34-9d83df58b540 string

Constraints:
Min length = 36
Max length = 36
Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
identityType The type of identity to use. Values can be systemAssignedIdentity, userAssignedIdentity, or delegatedResourceIdentity. 'delegatedResourceIdentity'
'systemAssignedIdentity'
'userAssignedIdentity'
userAssignedIdentityResourceId User assigned identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/myId. Mutually exclusive with identityType systemAssignedIdentity. string

ContextCacheProperties

Name Description Value
accountKind The kind of account determining storage topology. 'DataZone'
'Global'
'Regional' (required)
description Account description. string

Constraints:
Max length = 250
encryption Encryption settings for the account. AzureResourceManagerCommonTypesEncryption

SystemAssignedServiceIdentity

Name Description Value
type Type of managed service identity (either system assigned, or none). 'None'
'SystemAssigned' (required)

TrackedResourceTags

Name Description Value