-
Notifications
You must be signed in to change notification settings - Fork 3.3k
Open
Labels
Auto-AssignAuto assign by botAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamGraphaz adaz adpotential-pruningquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
Milestone
Description
Related command
az ad sp create-for-rbac
Is your feature request related to a problem? Please describe.
Currently, only integer --years is supported which is too rough:
> az ad sp create-for-rbac -h
...
Credential Arguments
--years : Number of years for which the credentials will be valid.
Default: 1 year.
The minimum expiry time is 1 year which is against the security best practice of setting expiry time as short as possible.
Caution
If there is a policy in the tenant that forbids expiry time >= 1 year, az ad sp create-for-rbac will fail.
Describe the solution you'd like
- Support
--end-datesimilar to that fromaz ad app credential resetandaz ad app create. - Support
--dayslike Azure Portal:
Describe alternatives you've considered
Drop --year as it encourages imprecise expiry time and it also causes ambiguity in leap years (#28520).
Metadata
Metadata
Assignees
Labels
Auto-AssignAuto assign by botAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamGraphaz adaz adpotential-pruningquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that