Quick answer: To change the value of an existing Azure Key Vault secret with Azure PowerShell, use Set-AzKeyVaultSecret with a new SecureString. If the secret already exists, the cmdlet creates a new version rather than overwriting the existing version. For an Automation runbook or Azure resource, authenticate with managed identity using Connect-AzAccount -Identity. Use Update-AzKeyVaultSecret when you only need to change secret attributes such as expiration, content type, enabled state, or tags.
Prerequisites:
1. The Azure Az PowerShell module installed.
2. An Azure Key Vault containing the secret you want to change.
3. An identity with permission to set or update secrets in that Key Vault. With Azure RBAC, the identity needs an appropriate Key Vault secrets role; with the legacy access-policy model, it needs the required secret permissions.
Update an Azure Key Vault secret using PowerShell
Use Set-AzKeyVaultSecret when you want to change the secret value. The cmdlet accepts a SecureString. If the secret already exists, Azure Key Vault stores the new value as a new version of that secret.
$keyVaultName = "my-key-vault"
$secretName = "my-secret"
$secureValue = Read-Host -Prompt "Enter the new secret value" -AsSecureString
Set-AzKeyVaultSecret -VaultName $keyVaultName -Name $secretName -SecretValue $secureValue
In this example, Read-Host -AsSecureString keeps the value in a secure-string representation rather than putting the secret directly into the script. Set-AzKeyVaultSecret then creates a new version of the secret.
Authenticate to Azure first
For an interactive PowerShell session, sign in with Connect-AzAccount and select the appropriate subscription:
Connect-AzAccount
Set-AzContext -SubscriptionId "00000000-0000-0000-0000-000000000000"
For Azure Automation, a VM, or another Azure resource with a managed identity, use:
Connect-AzAccount -Identity
Set-AzContext -SubscriptionId "00000000-0000-0000-0000-000000000000"
Connect-AzAccount -Identity authenticates through the managed identity available to the execution environment, so the script does not need an Azure password, client secret, or certificate. The managed identity still needs permission to set the secret in the target Key Vault.
Available on Microsoft Store
SSRS Reports Migration Wizard
A simple Windows tool for migrating SSRS reports, data sources, and related configurations between report servers.
Update Azure Key Vault secret attributes
If you do not want to change the secret value and only need to modify attributes, use Update-AzKeyVaultSecret. Microsoft documents this cmdlet for attributes such as enabled state, expiration, not-before time, content type, and tags.
$keyVaultName = "my-key-vault"
$secretName = "my-secret"
$expires = (Get-Date).AddMonths(6).ToUniversalTime()
Update-AzKeyVaultSecret -VaultName $keyVaultName -Name $secretName -Expires $expires -Enable $true -ContentType "text/plain" -PassThru
Attributes that you do not specify remain unchanged. Use this approach when the value itself should stay the same.
Update a secret from a script or Automation runbook
For automation, avoid hard-coding the new secret value in the runbook source. Retrieve it from an approved secure source or provide it securely at runtime, convert it to a SecureString, and then call Set-AzKeyVaultSecret.
Connect-AzAccount -Identity
Set-AzContext -SubscriptionId $subscriptionId
$secureValue = ConvertTo-SecureString $newSecretValue -AsPlainText -Force
Set-AzKeyVaultSecret -VaultName $keyVaultName -Name $secretName -SecretValue $secureValue
Security note: Although ConvertTo-SecureString -AsPlainText can be useful when the value is already supplied securely by an automation system, do not place real secrets directly in source code, command history, pipeline YAML, or logs.
Troubleshooting
Access is denied
Verify which authorization model the Key Vault uses. With Azure RBAC, check the role assignment for the signed-in user or managed identity. With a legacy access policy, verify that the identity has the required secret permissions. Also confirm that the subscription and Key Vault are in the context selected by Set-AzContext.
The command creates a new version
This is expected when you change a secret value with Set-AzKeyVaultSecret. Azure Key Vault keeps previous versions rather than modifying the existing version in place. If you only need to change metadata such as expiration or tags, use Update-AzKeyVaultSecret instead.
The managed identity cannot sign in
Make sure the execution environment has a system-assigned or user-assigned managed identity and that the identity is enabled. For a user-assigned identity, specify the appropriate identity when connecting. Then verify that the identity has access to the target Key Vault.
Related Azure Key Vault guides
• Access Azure Key Vault secrets from Azure Data Factory
• Automate Azure Data Factory with managed identity
Pro tips:
1. Use Set-AzKeyVaultSecret for a new secret value and Update-AzKeyVaultSecret for secret attributes.
2. Treat every value passed to Set-AzKeyVaultSecret as sensitive and prevent it from appearing in logs.
3. Use managed identity for Azure-hosted automation instead of storing long-lived credentials.
See more
Visual Studio Marketplace
SSIS Catalog Migration Wizard
Extend Visual Studio with an easy way to migrate SSIS Catalog projects.
Kunal Rathi
With over 15 years of experience in data engineering and analytics, I've assisted countless clients in gaining valuable insights from their data. As a dedicated supporter of Data, Cloud and DevOps, I'm excited to connect with individuals who share my passion for this field. If my work resonates with you, we can talk and collaborate.






