- Log on to the Microsoft Azure portal and select Create a resource.
- Under Key Vault, select Create.
- On the tab Basics, provide these values:
Subscription Select your subscription. Resource group Select your resource group or select Create new. Key vault name Type a name for the key vault. Region Select your region. Pricing tier Select your pricing tier. Days to retain deleted vaults Type the number of days in the retention period. Soft-delete is automatically enabled for this key vault. Therefore, during the retention period, you can recover or permanently delete this key vault and its stored secrets.
Purge protection Select to prevent users and Microsoft from permanently deleting this key vault and its stored secrets during the retention period. - Select Next.
- On the tab Access configuration, provide these values:
Permission model Accept Azure role-based access control (recommended) or select Vault access policy. Resource access Select zero or more resources. - Select Next.
- On the tab Networking, do one of the following:
- Select Enable public access and either All networks or Selected networks.
- Under Private endpoint, select + and create a private endpoint to allow a private connection to this key vault.
- Select Next.
- On the tab Tags, if you want tags, type their names and values.
- Select Next.
- On the tab Review + create, review your choices and make any corrections.
- Select Create.
- [Optional] Go to Resource groups, select the name of the resource group, select Overview, and look on the Resources tab for the key vault name.