Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Bicep resource definition
The contextCaches resource type can be deployed with operations that target:
- Resource groups - See resource group deployment commands
For a list of changed properties in each API version, see change log.
Resource format
To create a Microsoft.Storage/contextCaches resource, add the following Bicep to your template.
resource symbolicname 'Microsoft.Storage/contextCaches@2026-06-01' = {
identity: {
type: 'string'
}
location: 'string'
name: 'string'
properties: {
accountKind: 'string'
description: 'string'
encryption: {
customerManagedKeyEncryption: {
keyEncryptionKeyIdentity: {
delegatedIdentityClientId: 'string'
federatedClientId: 'string'
identityType: 'string'
userAssignedIdentityResourceId: 'string'
}
keyEncryptionKeyUrl: 'string'
}
infrastructureEncryption: 'string'
}
}
tags: {
{customized property}: 'string'
}
}
Property Values
Microsoft.Storage/contextCaches
| Name | Description | Value |
|---|---|---|
| identity | The managed service identities assigned to this resource. | SystemAssignedServiceIdentity |
| location | The geo-location where the resource lives | string (required) |
| name | The resource name | string Constraints: Pattern = ^[a-z0-9][a-z0-9-]{1,22}[a-z0-9]$ (required) |
| properties | The resource-specific properties for this resource. | ContextCacheProperties (required) |
| tags | Resource tags | Dictionary of tag names and values. See Tags in templates |
AzureResourceManagerCommonTypesCustomerManagedKeyEncryption
| Name | Description | Value |
|---|---|---|
| keyEncryptionKeyIdentity | All identity configuration for Customer-managed key settings defining which identity should be used to auth to Key Vault. | AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity |
| keyEncryptionKeyUrl | key encryption key Url, versioned or non-versioned. Ex: https://contosovault.vault.azure.net/keys/contosokek/562a4bb76b524a1493a6afe8e536ee78 or https://contosovault.vault.azure.net/keys/contosokek. |
string |
AzureResourceManagerCommonTypesEncryption
| Name | Description | Value |
|---|---|---|
| customerManagedKeyEncryption | All Customer-managed key encryption properties for the resource. | AzureResourceManagerCommonTypesCustomerManagedKeyEncryption |
| infrastructureEncryption | Values are enabled and disabled. | 'disabled' 'enabled' |
AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity
| Name | Description | Value |
|---|---|---|
| delegatedIdentityClientId | delegated identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups/ |
string Constraints: Min length = 36 Max length = 36 Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ |
| federatedClientId | application client identity to use for accessing key encryption key Url in a different tenant. Ex: f83c6b1b-4d34-47e4-bb34-9d83df58b540 | string Constraints: Min length = 36 Max length = 36 Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ |
| identityType | The type of identity to use. Values can be systemAssignedIdentity, userAssignedIdentity, or delegatedResourceIdentity. | 'delegatedResourceIdentity' 'systemAssignedIdentity' 'userAssignedIdentity' |
| userAssignedIdentityResourceId | User assigned identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups/ |
string |
ContextCacheProperties
| Name | Description | Value |
|---|---|---|
| accountKind | The kind of account determining storage topology. | 'DataZone' 'Global' 'Regional' (required) |
| description | Account description. | string Constraints: Max length = 250 |
| encryption | Encryption settings for the account. | AzureResourceManagerCommonTypesEncryption |
SystemAssignedServiceIdentity
| Name | Description | Value |
|---|---|---|
| type | Type of managed service identity (either system assigned, or none). | 'None' 'SystemAssigned' (required) |
TrackedResourceTags
| Name | Description | Value |
|---|
ARM template resource definition
The contextCaches resource type can be deployed with operations that target:
- Resource groups - See resource group deployment commands For a list of changed properties in each API version, see change log.
Usage Examples
Resource format
To create a Microsoft.Storage/contextCaches resource, add the following JSON to your template.
{
"type": "Microsoft.Storage/contextCaches",
"apiVersion": "2026-06-01",
"name": "string",
"identity": {
"type": "string"
},
"location": "string",
"properties": {
"accountKind": "string",
"description": "string",
"encryption": {
"customerManagedKeyEncryption": {
"keyEncryptionKeyIdentity": {
"delegatedIdentityClientId": "string",
"federatedClientId": "string",
"identityType": "string",
"userAssignedIdentityResourceId": "string"
},
"keyEncryptionKeyUrl": "string"
},
"infrastructureEncryption": "string"
}
},
"tags": {
"{customized property}": "string"
}
}
Property Values
Microsoft.Storage/contextCaches
| Name | Description | Value |
|---|---|---|
| apiVersion | The api version | '2026-06-01' |
| identity | The managed service identities assigned to this resource. | SystemAssignedServiceIdentity |
| location | The geo-location where the resource lives | string (required) |
| name | The resource name | string Constraints: Pattern = ^[a-z0-9][a-z0-9-]{1,22}[a-z0-9]$ (required) |
| properties | The resource-specific properties for this resource. | ContextCacheProperties (required) |
| tags | Resource tags | Dictionary of tag names and values. See Tags in templates |
| type | The resource type | 'Microsoft.Storage/contextCaches' |
AzureResourceManagerCommonTypesCustomerManagedKeyEncryption
| Name | Description | Value |
|---|---|---|
| keyEncryptionKeyIdentity | All identity configuration for Customer-managed key settings defining which identity should be used to auth to Key Vault. | AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity |
| keyEncryptionKeyUrl | key encryption key Url, versioned or non-versioned. Ex: https://contosovault.vault.azure.net/keys/contosokek/562a4bb76b524a1493a6afe8e536ee78 or https://contosovault.vault.azure.net/keys/contosokek. |
string |
AzureResourceManagerCommonTypesEncryption
| Name | Description | Value |
|---|---|---|
| customerManagedKeyEncryption | All Customer-managed key encryption properties for the resource. | AzureResourceManagerCommonTypesCustomerManagedKeyEncryption |
| infrastructureEncryption | Values are enabled and disabled. | 'disabled' 'enabled' |
AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity
| Name | Description | Value |
|---|---|---|
| delegatedIdentityClientId | delegated identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups/ |
string Constraints: Min length = 36 Max length = 36 Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ |
| federatedClientId | application client identity to use for accessing key encryption key Url in a different tenant. Ex: f83c6b1b-4d34-47e4-bb34-9d83df58b540 | string Constraints: Min length = 36 Max length = 36 Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ |
| identityType | The type of identity to use. Values can be systemAssignedIdentity, userAssignedIdentity, or delegatedResourceIdentity. | 'delegatedResourceIdentity' 'systemAssignedIdentity' 'userAssignedIdentity' |
| userAssignedIdentityResourceId | User assigned identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups/ |
string |
ContextCacheProperties
| Name | Description | Value |
|---|---|---|
| accountKind | The kind of account determining storage topology. | 'DataZone' 'Global' 'Regional' (required) |
| description | Account description. | string Constraints: Max length = 250 |
| encryption | Encryption settings for the account. | AzureResourceManagerCommonTypesEncryption |
SystemAssignedServiceIdentity
| Name | Description | Value |
|---|---|---|
| type | Type of managed service identity (either system assigned, or none). | 'None' 'SystemAssigned' (required) |
TrackedResourceTags
| Name | Description | Value |
|---|
Terraform (AzAPI provider) resource definition
The contextCaches resource type can be deployed with operations that target:
- Resource groups For a list of changed properties in each API version, see change log.
Resource format
To create a Microsoft.Storage/contextCaches resource, add the following Terraform to your template.
resource "azapi_resource" "symbolicname" {
type = "Microsoft.Storage/contextCaches@2026-06-01"
name = "string"
parent_id = "string"
identity {
type = "string"
identity_ids = [
"string"
]
}
location = "string"
tags = {
{customized property} = "string"
}
body = {
properties = {
accountKind = "string"
description = "string"
encryption = {
customerManagedKeyEncryption = {
keyEncryptionKeyIdentity = {
delegatedIdentityClientId = "string"
federatedClientId = "string"
identityType = "string"
userAssignedIdentityResourceId = "string"
}
keyEncryptionKeyUrl = "string"
}
infrastructureEncryption = "string"
}
}
}
}
Property Values
Microsoft.Storage/contextCaches
| Name | Description | Value |
|---|---|---|
| identity | The managed service identities assigned to this resource. | SystemAssignedServiceIdentity |
| location | The geo-location where the resource lives | string (required) |
| name | The resource name | string Constraints: Pattern = ^[a-z0-9][a-z0-9-]{1,22}[a-z0-9]$ (required) |
| properties | The resource-specific properties for this resource. | ContextCacheProperties (required) |
| tags | Resource tags | Dictionary of tag names and values. |
| type | The resource type | "Microsoft.Storage/contextCaches@2026-06-01" |
AzureResourceManagerCommonTypesCustomerManagedKeyEncryption
| Name | Description | Value |
|---|---|---|
| keyEncryptionKeyIdentity | All identity configuration for Customer-managed key settings defining which identity should be used to auth to Key Vault. | AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity |
| keyEncryptionKeyUrl | key encryption key Url, versioned or non-versioned. Ex: https://contosovault.vault.azure.net/keys/contosokek/562a4bb76b524a1493a6afe8e536ee78 or https://contosovault.vault.azure.net/keys/contosokek. |
string |
AzureResourceManagerCommonTypesEncryption
| Name | Description | Value |
|---|---|---|
| customerManagedKeyEncryption | All Customer-managed key encryption properties for the resource. | AzureResourceManagerCommonTypesCustomerManagedKeyEncryption |
| infrastructureEncryption | Values are enabled and disabled. | 'disabled' 'enabled' |
AzureResourceManagerCommonTypesKeyEncryptionKeyIdentity
| Name | Description | Value |
|---|---|---|
| delegatedIdentityClientId | delegated identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups/ |
string Constraints: Min length = 36 Max length = 36 Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ |
| federatedClientId | application client identity to use for accessing key encryption key Url in a different tenant. Ex: f83c6b1b-4d34-47e4-bb34-9d83df58b540 | string Constraints: Min length = 36 Max length = 36 Pattern = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ |
| identityType | The type of identity to use. Values can be systemAssignedIdentity, userAssignedIdentity, or delegatedResourceIdentity. | 'delegatedResourceIdentity' 'systemAssignedIdentity' 'userAssignedIdentity' |
| userAssignedIdentityResourceId | User assigned identity to use for accessing key encryption key Url. Ex: /subscriptions/fa5fc227-a624-475e-b696-cdd604c735bc/resourceGroups/ |
string |
ContextCacheProperties
| Name | Description | Value |
|---|---|---|
| accountKind | The kind of account determining storage topology. | 'DataZone' 'Global' 'Regional' (required) |
| description | Account description. | string Constraints: Max length = 250 |
| encryption | Encryption settings for the account. | AzureResourceManagerCommonTypesEncryption |
SystemAssignedServiceIdentity
| Name | Description | Value |
|---|---|---|
| type | Type of managed service identity (either system assigned, or none). | 'None' 'SystemAssigned' (required) |
TrackedResourceTags
| Name | Description | Value |
|---|