Complete Azure CLI commands reference — 100 commands across 7 categories. Quick reference cheat sheet for Windows, Mac & Linux.
The Azure CLI is organised as az followed by a service group and a verb — az vm create, az storage account list — and the table lists the service groups with Microsoft's one-line descriptions. Knowing the group names is most of the battle, because every group answers --help with its subcommands. The notes cover the session setup, the groups everyone uses, and the flags that make output scriptable.
| Shortcut | Action |
|---|---|
| az account | Manage Azure subscription information |
| az advisor | Manage Azure Advisor |
| az billing | Manage Azure Billing |
| az config | Manage Azure CLI configuration |
| az consumption | Manage consumption of Azure resources |
| az deployment | Manage Azure Resource Manager template deployment |
| az feature | Manage resource provider features |
| az group | Manage resource groups and template deployments |
| az monitor | Manage the Azure Monitor Service |
| az provider | Manage resource providers |
| az resource | Manage Azure resources |
| az tag | Tag Management on a resource |
| Shortcut | Action |
|---|---|
| az acr | Manage private registries with Azure Container |
| az aks | Azure Kubernetes Service |
| az batch | Manage Azure Batch |
| az capacity | Manage capacity |
| az container | Manage Azure Container Instances |
| az containerapp | Manage Azure Container Apps |
| az disk | Manage Azure Managed Disks |
| az image | Manage custom virtual machine images |
| az ppg | Manage Proximity Placement Groups |
| az restore-point | Manage restore point with res |
| az snapshot | Manage point-in-time copies of managed disks |
| az sshkey | Manage ssh public key with vm |
| az vm | Manage Linux or Windows virtual machines |
| az vmss | Manage groupings of virtual machines in an Azure |
| Shortcut | Action |
|---|---|
| az ad | Manage Microsoft Entra ID (formerly known as Azure |
| az identity | Manage Managed Identity |
| az keyvault | Manage KeyVault keys, secrets, and certificates |
| az lock | Manage Azure locks |
| az managedapp | Manage template solutions provided and maintained |
| az policy | Manage resources defined and used by the Azure |
| az role | Manage Azure role-based access control (Azure RBAC) |
| az security | Manage your security posture with Microsoft |
| Shortcut | Action |
|---|---|
| az ams | Manage Azure Media Services resources |
| az aro | Manage Azure Red Hat OpenShift clusters |
| az bicep | Bicep CLI command group |
| az bot | Manage Microsoft Azure Bot Service |
| az cache | Manage CLI objects cached using the --defer argument |
| az cloud | Manage registered Azure clouds |
| az cognitiveservices | Manage Azure Cognitive Services accounts |
| az compute-fleet | Manage for Azure Compute Fleet |
| az compute-recommender | Manage sku/zone/region recommender info for compute |
| az configure | Manage Azure CLI configuration. This command |
| az connection | Commands to manage Service Connector local connections which allow local environment to connect |
| az data-boundary | Data boundary operations |
| az databoxedge | Manage device with databoxedge |
| az deployment-scripts | Manage deployment scripts at subscription |
| az disk-access | Manage disk access resources |
| az disk-encryption-set | Disk Encryption Set resource |
| az dms | Manage Azure Data Migration Service (classic) |
| az extension | Manage and update CLI extensions |
| az feedback | Send feedback to the Azure CLI Team |
| az find | I'm an AI robot, my advice is based on our Azure |
| az interactive | Start interactive mode. Installs the Interactive |
| az lab | Manage azure devtest labs |
| az login | Log in to Azure |
| az logout | Log out to remove access to Azure subscriptions |
| az managed-cassandra | Azure Managed Cassandra |
| az managedservices | Manage the registration assignments and definitions |
| az maps | Manage Azure Maps |
| az netappfiles | Manage Azure NetApp Files (ANF) Resources |
| az private-link | Private-link association CLI command group |
| az resourcemanagement | Resourcemanagement CLI command group |
| az rest | Invoke a custom request |
| az sf | Manage and administer Azure Service Fabric clusters |
| az sig | Manage shared image gallery |
| az stack | A deployment stack is a native Azure resource type |
| az survey | Take Azure CLI survey |
| az term | Manage marketplace agreement |
| az ts | Manage template specs at subscription or resource |
| az upgrade | Upgrade Azure CLI and extensions |
| az version | Show the versions of Azure CLI modules |
| Shortcut | Action |
|---|---|
| az apim | Manage Azure API Management services |
| az appconfig | Manage App Configurations |
| az appservice | Manage Appservice |
| az functionapp | Manage function apps. To install the Azure |
| az logicapp | Manage logic apps |
| az spring | Manage Azure Spring Apps |
| az staticwebapp | Manage static apps |
| az webapp | Manage web apps |
| Shortcut | Action |
|---|---|
| az backup | Manage Azure Backups |
| az cosmosdb | Manage Azure Cosmos DB database accounts |
| az dls | Manage Data Lake Store accounts and filesystems |
| az hdinsight | Manage HDInsight resources |
| az mariadb | Manage Azure Database for MariaDB servers |
| az mysql | Manage Azure Database for MySQL servers |
| az postgres | Manage Azure Database for PostgreSQL |
| az redis | Manage dedicated Redis caches for your Azure |
| az search | Manage Azure AI Search |
| az sql | Manage Azure SQL Databases and Data Warehouses |
| az storage | Manage Azure Cloud Storage resources |
| az synapse | Manage and operate Synapse Workspace, Spark Pool |
| Shortcut | Action |
|---|---|
| az eventgrid | Manage Azure Event Grid topics, domains, domain |
| az eventhubs | Eventhubs |
| az iot | Manage Internet of Things (IoT) assets |
| az network | Manage Azure Network resources |
| az relay | Manage Azure Relay Service namespaces, WCF relays |
| az servicebus | Servicebus |
| az signalr | Manage Azure SignalR Service |
az login opens a browser to authenticate (or --use-device-code on a headless machine), and az account then lists subscriptions and sets the active one with az account set --subscription, which is the step people forget when a resource "does not exist". az config stores defaults such as a resource group and location so they need not be repeated, and az extension installs command groups that ship separately. az interactive starts a shell with completion and inline help for exploring.
az group creates and lists resource groups, the container for everything else. az vm, az aks, az webapp, az functionapp and az containerapp are the compute surfaces; az storage, az sql, az cosmosdb and az postgres the data ones; az network holds virtual networks, NSGs and load balancers; az keyvault secrets and certificates. az deployment runs ARM and Bicep templates, with az bicep managing the Bicep compiler. az resource works on any resource by ID when a service has no dedicated group.
Every command accepts --output (json, table, tsv) and --query, a JMESPath expression that picks fields out of the JSON, so az vm list --query "[].name" -o tsv is a plain list of names. az monitor reads metrics and activity logs, az role and az ad handle RBAC and Entra ID objects, az lock protects resources from deletion, and az policy shows what compliance rules apply. az find suggests commands from a description when you cannot remember the group, and az feedback reports a bug with the last command's trace attached.
az account list shows them; az account set --subscription "name or id" makes one active for subsequent commands.
Add --query with a JMESPath expression and -o tsv, for example az vm show -g rg -n vm --query "hardwareProfile.vmSize" -o tsv.
az find "description", or az <group> --help to list a group's subcommands.
Some groups are extensions. az extension add --name <name> installs them; az extension list shows what is installed.
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"