diff --git a/modules/azure/service-principal/buildingblock/README.md b/modules/azure/service-principal/buildingblock/README.md
index 21ff17a..40454a0 100644
--- a/modules/azure/service-principal/buildingblock/README.md
+++ b/modules/azure/service-principal/buildingblock/README.md
@@ -251,8 +251,8 @@ No modules.
| [application\_object\_id](#output\_application\_object\_id) | Object ID of the Entra ID application |
| [authentication\_method](#output\_authentication\_method) | Authentication method for the service principal |
| [azure\_role](#output\_azure\_role) | Azure role assigned to the service principal |
-| [client\_secret](#output\_client\_secret) | Client secret for the service principal (null if create\_client\_secret is false) |
-| [secret\_expiration\_date](#output\_secret\_expiration\_date) | Date when the service principal secret will expire (null if create\_client\_secret is false) |
+| [client\_secret](#output\_client\_secret) | Client secret for the service principal ("null" if create\_client\_secret is false) |
+| [secret\_expiration\_date](#output\_secret\_expiration\_date) | Date when the service principal secret will expire ("null" if create\_client\_secret is false) |
| [service\_principal\_id](#output\_service\_principal\_id) | Client ID of the service principal (same as application\_id) |
| [service\_principal\_object\_id](#output\_service\_principal\_object\_id) | Object ID of the service principal |
| [subscription\_id](#output\_subscription\_id) | Azure Subscription ID where role assignment was created |
diff --git a/modules/azure/service-principal/buildingblock/outputs.tf b/modules/azure/service-principal/buildingblock/outputs.tf
index 4eb83b6..3c276b7 100644
--- a/modules/azure/service-principal/buildingblock/outputs.tf
+++ b/modules/azure/service-principal/buildingblock/outputs.tf
@@ -19,8 +19,8 @@ output "service_principal_object_id" {
}
output "client_secret" {
- description = "Client secret for the service principal (null if create_client_secret is false)"
- value = var.create_client_secret ? azuread_application_password.main[0].value : null
+ description = "Client secret for the service principal (\"null\" if create_client_secret is false)"
+ value = var.create_client_secret ? azuread_application_password.main[0].value : "null"
sensitive = true
}
@@ -40,8 +40,8 @@ output "azure_role" {
}
output "secret_expiration_date" {
- description = "Date when the service principal secret will expire (null if create_client_secret is false)"
- value = var.create_client_secret ? azuread_application_password.main[0].end_date : null
+ description = "Date when the service principal secret will expire (\"null\" if create_client_secret is false)"
+ value = var.create_client_secret ? azuread_application_password.main[0].end_date : "null"
}
output "authentication_method" {