> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports/azure-entities/azure-resource-management/keyvault.md).

# KeyVault

The **KeyVault** entity represents an Azure Key Vault resource used to safeguard cryptographic keys, secrets, and certificates.

| Field                        | Type    | Possible Operators                                                 | Description                                              |
| ---------------------------- | ------- | ------------------------------------------------------------------ | -------------------------------------------------------- |
| Guid                         | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Unique identifier for the entity in Forestall            |
| ObjectID                     | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure Object ID of the Key Vault                         |
| FSName                       | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name used in Forestall                           |
| DisplayName                  | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Display name of the Key Vault                            |
| EnableRbacAuthorization      | BOOLEAN | True / False                                                       | Whether RBAC authorization is enabled for the Key Vault  |
| EnableSoftDelete             | BOOLEAN | True / False                                                       | Whether soft delete is enabled                           |
| EnabledForDeployment         | BOOLEAN | True / False                                                       | Whether the Key Vault is enabled for deployment          |
| EnabledForDiskEncryption     | BOOLEAN | True / False                                                       | Whether the Key Vault is enabled for disk encryption     |
| EnabledForTemplateDeployment | BOOLEAN | True / False                                                       | Whether the Key Vault is enabled for template deployment |
| SoftDeleteRetentionInDays    | NUMBER  | Equal, Between, Smaller, Larger, Smaller or Equal, Larger or Equal | Number of days soft-deleted items are retained           |
| Location                     | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure region where the Key Vault is located              |
| TenantID                     | TEXT    | Like, Not Like, Equal, Not Equal, Is Empty                         | Azure AD Tenant ID the Key Vault belongs to              |
