---
title: arpio-config:admin-password-secret
description: Provide a reference to the Azure Key Vault location where the administrator password is stored.
---

[Skip to content](https://docs.arpio.io/azure/arpio-configadmin-password-secret#main-content)

English

Show submenu for translations

[Customer ticket portal](https://docs.arpio.io/tickets-view?hsLang=en)

- Home
- Products
- Pricing
- Blog
- Company

Open main navigation

Close main navigation

- Home
- Products
- Pricing
- Blog
- Company
- English
  
  Show submenu for translations
- [Customer ticket portal](https://docs.arpio.io/tickets-view)

 Welcome to Arpio Technical Docs

- There are no suggestions because the search field is empty.

1. [Arpio Documentation](https://docs.arpio.io/?hsLang=en)
2. [Azure Reference Guides](https://docs.arpio.io/azure-reference-guides?hsLang=en)
3. [Azure Configuration Tags](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-configuration-tags)

# arpio-config:admin-password-secret

### Provide a reference to the Azure Key Vault location where the administrator password is stored.

```
arpio-config:admin-password-secret = <keyvault-secret-location>
```

#### <keyvault-secret-location>

The URL associated with the key vault secret that contains the password value to be used. Should be in the following format:  https://<keyvault-name>.vault.azure.net/secrets/<secret-name>

#### Supported Resources

- Azure SQL Virtual Server
- Virtual Machine Scale Sets (VMSS)

#### Description

Some Azure resource types are secured using passwords instead of Entra/AD RBAC rules and permissions. These passwords are "write-only" properties of the resource and cannot be retrieved by Azure.  Instead, these must be stored in Azure Key Vault so they can be retrieved and used by Arpio to protect the resource. 

When working with Azure SQL Database or Azure SQL Managed Instance servers  that use SQL Authentication this tag must be placed on the primary SQL server.   The value is required for Arpio to be able to restore the server with the same password in the recovery environment. The administrative username is returned by the Azure resource API’s so no tag is needed. Note that the Arpio service does not directly access or store this password - it is only accessed by the recovery delegate.

This tag must also be used with Azure Virtual Machine Scale Sets. These are stateless resources and the tag is necessary to ensure that the recovered instances use the same password that was used for the primary instances.

#### Examples

| **Tag** | **Value** |
| --- | --- |
| ``` arpio-config:admin-password-secret ``` | ``` https://my-key-vault.vault.azure.net/secrets/sql-admin-password ``` |

 

- [Getting Started](https://docs.arpio.io/getting-started?hsLang=en#main-content)
  
  
  
  
  
    - [New Account Setup](https://docs.arpio.io/getting-started?hsLang=en#new-account-setup)
    - [New Application Setup](https://docs.arpio.io/getting-started?hsLang=en#new-application-setup)
- [Arpio Fundamentals](https://docs.arpio.io/arpio-fundamentals?hsLang=en#main-content)
  
  
  
  
  
    - [Platform Fundamentals](https://docs.arpio.io/arpio-fundamentals?hsLang=en#platform-fundamentals)
    - [Platform Features](https://docs.arpio.io/arpio-fundamentals?hsLang=en#platform-features)
- [Arpio Reference Guides](https://docs.arpio.io/arpio-reference-guides?hsLang=en#main-content)
  
  
  
  
  
    - [Arpio API](https://docs.arpio.io/arpio-reference-guides?hsLang=en#arpio-api)
    - [Lifecycle Events](https://docs.arpio.io/arpio-reference-guides?hsLang=en#lifecycle-events)
    - [Role-Based Access Controls (RBAC)](https://docs.arpio.io/arpio-reference-guides?hsLang=en#role-based-access-controls-rbac)
    - [Single Sign-On (SSO) Integration](https://docs.arpio.io/arpio-reference-guides?hsLang=en#single-sign-on-sso-integration)
    - [Test Planning](https://docs.arpio.io/arpio-reference-guides?hsLang=en#test-planning)
    - [Test & Recovery How-To](https://docs.arpio.io/arpio-reference-guides?hsLang=en#test-recovery-how-to)
- [AWS Reference Guides](https://docs.arpio.io/aws-reference-guides?hsLang=en#main-content)
  
  
  
  
  
    - [AWS Resource Reference](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-resource-reference)
    - [AWS Configuration Tags](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-configuration-tags)
    - [AWS Access](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-access)
    - [AWS Testing](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-testing)
    - [AWS Solutions](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-solutions)
- [Azure Reference Guides](https://docs.arpio.io/azure-reference-guides?hsLang=en#main-content)
  
  
  
  
  
    - [Azure Resource Reference](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-resource-reference)
    - [Azure Configuration Tags](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-configuration-tags)
    - [Azure Scenarios](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-scenarios)
- [FAQ](https://docs.arpio.io/faq?hsLang=en#main-content)
  
  
  
  
  
    - [AWS FAQ](https://docs.arpio.io/faq?hsLang=en#aws-faq)
    - [Contact Support](https://docs.arpio.io/faq?hsLang=en#contact-support)
    - [License & Billing](https://docs.arpio.io/faq?hsLang=en#license-billing)
    - [Tests and Recoveries](https://docs.arpio.io/faq?hsLang=en#tests-and-recoveries)

- Home
- Products
- Pricing
- Blog
- Company

[![bubble-wand-tight.64](https://docs.arpio.io/hs-fs/hubfs/bubble-wand-tight.64.png?width=64&height=64&name=bubble-wand-tight.64.png "bubble-wand-tight.64")](https://arpio.io)

Copyright © 2026, Arpio