Working directly with the Azure Stack Resource Manager API

I would like to follow up on a blog post I have read here. They talk about how you can interact directly with the Azure Resource Manager API with PowerShell or other programming / scripting languages. The advantage is I don’t need any Azure PowerShell modules in order to retrieve any data from Azure Stack. In the blog post they are talking about the TP1 configuration to use. But we might noticed that some things has been changed in TP2 and in the TP2 refresh bits. So lets see how we can kickstart to setup our environment and use PowerShell to talk to Azure Stack ARM API directly with the TP2 bits and the new Azure Portal experience.

First we need to login as service administrator in the Azure Portal to add a new Application in our Azure AD. Go to the App registrations in the new Azure Portal and choose Add, then specify a name and use for sign-on URL http://localhost


Click on create. In this newly created application go to settings, then select the Keys section and add a new key. Save the key for later use. I found a bug or a strange behavior. If you used 2 years or longer you might receive a “AADSTS50012: Invalid client secret is provided.” I solved it by selecting a key that is 1 year valid:


Now head over to the properties and take the application ID:


The next thing we need to do is to give this new application permissions to interact with the Azure Stack ARM API. Go to required permission in the portal and assign permissions to Azure Resource Manager by typing in the search bar AzureStack. It will list the available API’s. If you have like me more than 1 Azure Stack installs done in your AAD select all of them by repeating this next 2 steps for sake of simplicity. (I do recommend Microsoft to add a column in this list to add the app id so we can target correct API when we have multiple of them):


Next select the permission Access Azure Stack Resource Manager. Then select ‘Select’ and then ‘Done’ :


We need the App ID URI for the Azure Resource Manager API. So now head over to your Azure Resource Manager application and write down your App ID URI:


If you have multiple installs of Azure Stack please check the App ID URI with your installation by running this command:

Then make sure the App ID URI and the result in your PowerShell result are the same:

The last thing we need is the tenant ID. A quick jumpstart, to get the tenant ID is go to the help button in the right top corner in the Azure Portal and click on Diagnostics:


You will find half way the new windows that is opened the tenant ID for your tenant:


If your collection of references we collected during the AAD App setup is correct we can construct the following code. Replace the first 6 line variables with your values:

To get started with more API REST calls please find here the reference to the API documentation. Do note, not all services are available in Azure Stack and you might encounter some errors that some specific API version is not available in Azure Stack. You will then get an error and it will tell you what API version are available in Azure Stack and you have to update these in your script. When I run some queries I get results from Azure Stack ARM API:

Spread the word. Share this post!

Mark Scholman

About the author

Mark is consultant at Inspark and a Cloud and Datacenter MVP. In his day to day job he is building clouds with Azure Stack, Azure Pack and Hyper-V.

Twitter: @markscholman

  • Michael Lamia

    Hi Mark,

    This is an excellent post. I don’t suppose you’ve had a chance to revisit this since the recent release of TP3 Refresh? I got to the point where I need to find the App ID URI for the Azure Stack ARM API, but I do not see my TP3 Refresh instance anywhere. I see all my past TP2 and TP3 instances but not Refresh. Has something changed in the way Refresh registers with AAD?

    I can provide more detail upon request.

    Thanks in advance for any guidance you might be able to provide.


  • Shravani Chepuri

    Hi Mark
    I am working with azure stack TP3.
    I have created new application but I couldn’t find Azure Stack Resource Manager API in the list to give the permission to my application.

    I still continued to execute the above power shell script , It’s failing with the below error. Is the URL changed on TP3 ?

    Invoke-RestMethod : The remote name could not be resolved: ‘api.azurestack.local’