# IdentityAzureAuth

> Resource IdentityAzureAuth in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource IdentityAzureAuth in pulumi-infisical.

Pulumi type: `infisical:index/identityAzureAuth:IdentityAzureAuth`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.IdentityAzureAuth("identityAzureAuth", {
  identityId: "<identityId>",
  tenantId: "<tenantId>",
})
```

## Arguments

| Property                     | Type                                              | Required | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------- | ------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accessTokenMaxTtl`          | `number`                                          | no       | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `accessTokenNumUsesLimit`    | `number`                                          | no       | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `accessTokenTrustedIps`      | `IdentityAzureAuthAccessTokenTrustedIp (input)[]` | no       | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| `accessTokenTtl`             | `number`                                          | no       | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `allowedServicePrincipalIds` | `string[]`                                        | no       | List of Azure AD service principal IDs that are allowed to authenticate with Infisical                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `identityId`                 | `string`                                          | yes      | The ID of the identity to attach the configuration onto.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `resourceUrl`                | `string`                                          | no       | The resource URL for the application registered in Azure AD. The value is expected to match the `aud` claim of the access token JWT later used in the login operation against Infisical. See the [resource](https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/how-to-use-vm-token#get-a-token-using-http) parameter for how the audience is set when requesting a JWT access token from the Azure Instance Metadata Service (IMDS) endpoint. In most cases, this value should be `https://management.azure.com/` which is the default |
| `tenantId`                   | `string`                                          | yes      | The [tenant ID](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant) for the Azure AD organization.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property                     | Type                                               | Computed | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------- | -------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accessTokenMaxTtl`          | `number`                                           | no       | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `accessTokenNumUsesLimit`    | `number`                                           | no       | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `accessTokenTrustedIps`      | `IdentityAzureAuthAccessTokenTrustedIp (output)[]` | no       | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| `accessTokenTtl`             | `number`                                           | no       | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `allowedServicePrincipalIds` | `string[]`                                         | no       | List of Azure AD service principal IDs that are allowed to authenticate with Infisical                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `identityId`                 | `string`                                           | no       | The ID of the identity to attach the configuration onto.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `resourceUrl`                | `string`                                           | no       | The resource URL for the application registered in Azure AD. The value is expected to match the `aud` claim of the access token JWT later used in the login operation against Infisical. See the [resource](https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/how-to-use-vm-token#get-a-token-using-http) parameter for how the audience is set when requesting a JWT access token from the Azure Instance Metadata Service (IMDS) endpoint. In most cases, this value should be `https://management.azure.com/` which is the default |
| `tenantId`                   | `string`                                           | no       | The [tenant ID](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant) for the Azure AD organization.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

## `IdentityAzureAuthAccessTokenTrustedIp (input)`

Input object `IdentityAzureAuthAccessTokenTrustedIp`. Fields below belong to this object, not to the parent.

| Property    | Type     | Required | Description |
| ----------- | -------- | -------- | ----------- |
| `ipAddress` | `string` | no       |             |

## `IdentityAzureAuthAccessTokenTrustedIp (output)`

Output object `IdentityAzureAuthAccessTokenTrustedIp`. Fields below belong to this object.

| Property    | Type     | Always present | Description |
| ----------- | -------- | -------------- | ----------- |
| `ipAddress` | `string` | yes            |             |
