Azure - setting tags on VMs using Powershell - azure

I'm using the following Powershell code to set tags on a bunch of Azure VMs but it doesn't seem to be working. It does not give me an error message, so it appears to run correctly, but it does not set the tags as expected. Any help would be great, perhaps it may be something easy I'm overlooking.
$group = Get-AzResourceGroup -Name my-rg
$resource = Get-AzResource -ResourceName myserver -ResourceGroupName my-rg
Set-AzResource -ResourceId $resource.ResourceId -Tag $group.Tags -Force
I'm only doing a few VMs which I'll probably put on a loop once this works. There are no tags on most of these VMs which may be overwritten.


How to add tags to existing azure resources using PowerShell

I have created number of resources in azure via portal. how to add the tags to each existing resource using PowerShell or CLI?
To add new tag you use New-AzTag.
New-AzTag -ResourceId $ -Tag $tags
To add tags to a resource that already has tags, use Update-AzTag.
Update-AzTag -ResourceId $ -Tag
The az tag create replaces all tags on the resource, resource group, or subscription.
az tag create --resource-id $resource --tags
To add tags to a resource that already has tags, use az tag update.
az tag update --resource-id $resource --operation Merge --tags Dept=Finance Status=Normal
This document gives you more details.
You can use the PowerShell script to update the tag to the resource which are null
$resources=Get-AzResource | Where-Object Tags -eq $null ##list all the resource whose tags are empty
$resources=Get-AzResourceGroup | Where-Object Tags -eq $null ##list all the resources at resource group level whose tags are empty
$resources | ForEach-Object { New-AzTag -Tag #{ "Env"="test" } -ResourceId $_.ResourceId }

Any way to get rid of an obsolete parameter in Azure PowerShell script (AzureRM to Az changing)

As you may know, MSFT is getting rid of AzureRM cmdlets in favor of Az.
There are a lot of issues regarding this since the proposed native aliases "Enable-AzureRmAlias" seems to stop being updated.
I have a script based on AzureRM in one repo, that triggers by Azure DevOps release pipeline step function (Azure PowerShell based),
that has the following piece of code:
$var = (Get-AzureKeyVaultSecret -VaultName $vaultName-Name $Key).SecretValueText
"Enable-AzureRmAlias" command activated as well..., that converts the code like this:
$var = (Get-AzKeyVaultSecret -VaultName $vaultName-Name $Key).SecretValueText
The problem is, that ".SecretValueText" was deprecated a while ago. Instead of it, a new parameter has been added to the Get-AzKeyVaultSecret cmdlet - "-AsPlainText"
so... theoretically the final construction has to be like this:
$var = Get-AzKeyVaultSecret -VaultName $vaultName-Name $Key -AsPlainText
I can't upgrade the original script in the repo to Az due to the necessity of back-compatibility.
The only way to solve it - is to create some kind of alias in Azure PowerShell inline script (that triggers the main script in the repo)
I stuck with this ".SecretValueText"
My original idea to put the following into the inline script doesn't seem to be working:
function Get-AzKeyVaultSecretNew {
$var = Get-AzKeyVaultSecret -VaultName $vaultName -Name $Key -AsPlainText
return $var
Set-Alias -Name Get-AzKeyVaultSecret -Value Get-AzKeyVaultSecretNew
Any ideas on how to accomplish this?
This should theoretically help your situation. You can run this code at the beginning of the PowerShell session that will be calling your scripts. You will need to make sure any necessary modules are loaded so that the secret object types are loaded.
$Script = { Get-AzKeyVaultSecret -VaultName $this.VaultName -Name $this.Name -AsPlainText }
Update-TypeData -TypeName 'Microsoft.Azure.Commands.KeyVault.Models.PSKeyVaultSecretIdentityItem' -MemberName 'SecretValueText' -MemberType ScriptProperty -Value $Script
The idea is to add the SecretValueText property back to the Microsoft.Azure.Commands.KeyVault.Models.PSKeyVaultSecretIdentityItem objects.
You can try using below workaround to replace below piece of code:
(Get-AzureKeyVaultSecret -VaultName $vaultName-Name $Key).SecretValueText
with Get-AzKeyVaultSecret -VaultName $vaultName -Name $Key -AsPlainText via using RegEx Find & Replace task. Check below steps:
1, Add task RegEx Find & Replace to replace the orginal code with the converted code. See below:
FindRegex: '\(Get-AzureKeyVaultSecret -VaultName \$vaultName -Name \$Key\)\.SecretValueText'
ReplaceRegex: 'Get-AzKeyVaultSecret -VaultName $vaultName -Name $Key -AsPlainText'
2, -AsPlainText parameter is only available in the latest az 5.3.0 version. Since the version installed in cloud agent is 4.7.0. You need to install the az 5.3.0 version before executing your script. See below. Use a powershell task to install az 5.3.0 version.
New-Item -Path "C:\Modules" -Name "az_5.3.0" -ItemType "directory"
Save-Module -Name AZ -RequiredVersion 5.3.0 -Path "C:\Modules\az_5.3.0"
3, Then you can invoke your script in the azure powershell task directly.

Azure: New-AzRoleAssignment Input string was not in a correct format - error with double parsing... without any number

I have a strange problem with my PowerShell script to create Azure user accounts.
Executing command
New-AzRoleAssignment -RoleDefinitionName 'Contributor' -ObjectId "$Usr.Id" -ResourceGroupName "$rgname"
Results in exception:
New-AzRoleAssignment : Input string was not in a correct format.
At myscript.ps1:151 char:5
+ New-AzRoleAssignment -RoleDefinitionName 'Contributor' -ObjectId ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : CloseError: (:) [New-AzRoleAssignment], FormatException
+ FullyQualifiedErrorId : Microsoft.Azure.Commands.Resources.NewAzureRoleAssignmentCommand
I've extracted stacktrace for this exception, and it looks like this:
at System.Number.ParseDouble(String value, NumberStyles options, NumberFormatInfo numfmt)
at Microsoft.Azure.Commands.Resources.NewAzureRoleAssignmentCommand.ExecuteCmdlet()
at Microsoft.WindowsAzure.Commands.Utilities.Common.AzurePSCmdlet.ProcessRecord()
Which is super strange - I'm not using any double number here. I've dig into source code for NewAzureRoleAssignmentCommand - but there is no System.Number.ParseDouble call there.
Only thing related to double is -ConditionVersion, but I don't want to use any Coditions.
What I should check next? I'm not an advanced Azure/Powershell user, so any suggestions are welcomed!
I've tried running command manually using same parameter values, with and without quotation marks - every time I get same error
New-AzRoleAssignment -RoleDefinitionName 'Contributor' -ObjectId f01b4003-8a47-4a9d-8935-cd000c8cd9c5 -ResourceGroupName myValidResourceGrupName
Try using Azure Cloud Shell to check whether the problem might be local to your machine.
Remove the double quotes that are around $
If you'd only have a string like:
$usr = <GUID goes here>
then you could pass "$usr". But in this case, you're trying to access the Id property of the $usr object.
I would try getting your with Get-AzRoleDefinition. I tend to get the objects for everything and use the IDs. This works for me.
$Role = Get-AzRoleDefinition -Name Contributor
$ResourceGroup = Get-AzResourceGroup -Name "ResourceGroupName"
$User = Get-AzADUser -UserPrincipalName "User-UPN-Here"
New-AzRoleAssignment -ObjectId $User.Id -RoleDefinitionId $Role.Id -Scope $ResourceGroup.ResourceId
I had the same problem. This script used to work:
$qa = get-azadgroup -displayname qa;
New-AzRoleAssignment -ObjectId $qa.Id -RoleDefinitionName Owner -ResourceGroupName RG-QA
Started getting this error on one computer but not the other. When I checked the modules version for az.resources, I had 2.1.0, 2.4.0 and 2.5.0. After removing versions 2.4.0 and 2.5.0, the script worked. I have the language of Powershell set to French. it's this issue if anyone else runs into this issue. Workaround as above is to use 2.1.0 of Az.resources but should be fixed soon.

Azure Powershell - iterate through a list (txt) with db names and set them as variables in script

I have the following challenge at the Moment:
With T-SQL I created a list of databases attached to our SQL instance and put this list in a txt file, so far no Problem.
Now with PowerShell I want to set up LongTermRetention backups in Azure with following cmdlet:
Set-AzSqlDatabaseBackupLongTermRetentionPolicy -ServerName $serverName -DatabaseName [name of database] -ResourceGroupName $resourceGroup -WeeklyRetention P53W -MonthlyRetention P48M -YearlyRetention P10Y -WeekOfYear 52
(I checked the Syntax of the cmdlet by inserting a database name manually and it works)
the variables given are set prior (ServerName, resourceGroup)
Where I am struggling now is, how I can get the names of the txt file one after another as parameter "DatabaseName" into my cmdlet, as I have never done something like this.
I would be very grateful for either a link on how to do this or maybe a solution posted here.
Thank you in advance and Kind regards
EDIT: I found a solution, Maybe not the most elegant, but working:
$files = Get-Content "C:\DEV\testfile.txt"
foreach ($file in $files){
Set-AzSqlDatabaseBackupLongTermRetentionPolicy -ServerName $serverName -DatabaseName $file -ResourceGroupName $resourceGroup -WeeklyRetention P53W -MonthlyRetention P48M -YearlyRetention P10Y -WeekOfYear 52
I haven't thought it might have been that easy.
If you have a flat text file where your database names are present like this:
You can use the Get-Content cmdlet to read the file and iterate over each line using the ForEach-Object cmdlet. You can access the current item using $_ ($_ represents the current value in the pipeline):
Get-Content -Path 'pathToYourFile.txt' | ForEach-Object {
Set-AzSqlDatabaseBackupLongTermRetentionPolicy `
-ServerName $_ `
-DatabaseName [name of database] `
-ResourceGroupName $resourceGroup `
-WeeklyRetention P53W `
-MonthlyRetention P48M `
-YearlyRetention P10Y `
-WeekOfYear 52

Why Get-AZRoleAssignment with ResourceName switch doesn't work?

I am trying to list who have Contributor permissions for specific resource name but when I want to use
Get-AZRoleAssignment -ResourceName "ResName"
I am receiving an error:
"Get-AzRoleAssignment : Parameter set cannot be resolved using the
specified named parameters."
However, I am sure that the mentioned resource exists as I can see it when I run the command
get-azresource -ResourceGroupName "ResGroupName"
I was trying:
Get-AZRoleAssignment -ResourceName "ResName" -ResourceGroupName "ResGroupName"
but no luck.
thanks for help
For your issue, you must miss reading the description of the parameter -ResourceName.
The resource name. For e.g. storageaccountprod. Must be used in
conjunction with ResourceGroupName, ResourceType, and
(optionally)ParentResource parameters.
So your PowerShell command should like this:
Get-AZRoleAssignment -ResourceName "ResName" -ResourceGroupName "ResGroupName" -ResourceType Microsoft.Compute/virtualMachines
You can change the type as you want. And if you just get the role Contributor, you can add the parameter -RoleDefinitionName with value Contributor.
