Skip to content
Security kv

Key vault naming convention

The CAF abbreviation for Key vault is kv. Names can be 3 to 24 characters long and allow alphanumerics and hyphens. The name must be globally unique across all of Azure.

Naming rules

CAF abbreviation kv
Length 3 to 24 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9), hyphens
Scope of uniqueness Global (must be unique across all of Azure)
CAF pattern kv-{workload}-{environment}-{region}-{instance}
Worth knowing: Globally unique name. Start with a letter; no consecutive hyphens.

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Naming Security resources

Key Vault has its own guide covering its strict 24 character global uniqueness and soft delete name reservation. Managed identities are cheap to create and usually provisioned per app or per function rather than shared, so unlike most of this list, their naming should tie tightly to the specific workload they are attached to.

VPN Gateway and Bastion resources are typically one per hub or region rather than one per environment, name them for the network boundary they protect. The common mistake is naming managed identities generically, id-prod for example, when dozens end up in the same subscription and it becomes impossible to tell which resource an identity actually belongs to.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production kv-payments-prod-eus-001 24/24
Web app, development kv-webapp-dev-weu-002 21/24
Analytics with company prefix kv-analytics-stage-001
Dropped company, region to fit the 24-char limit.
22/24

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment. The 24-character limit is enforced in the expression.

Terraform
locals {
  key_vault_name = substr("kv-${var.workload}-${var.environment}-${var.region}-001", 0, 24)
}
Bicep
var keyVaultName = take('kv-${workload}-${environment}-${region}-001', 24)

Generate Key vault names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Security resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.