Share via

Capture Role


The Capture Role operation creates a copy of the operating system virtual hard disk (VHD) that is associated with the Virtual Machine, saves the VHD copy in the same storage location as the operating system VHD, and registers the copy as an image the image repository. You must prepare the Virtual Machine by running the Sysprep command and you must shut down the Virtual Machine before you can capture an image from it.


The Capture Role request may be specified as follows. Replace <subscription-id> with the subscription ID, <cloudservice-name> with the name of the cloud service, <deployment-name> with the name of the deployment, and <role-name> with the name of the Virtual Machine.


Request URI


URI Parameters


Request Headers

The following table describes the request headers.

Request Header



Required. Specifies the version of the operation to use for this request. This header should be set to 2012-03-01 or higher.

Request Body

The following example shows the format of the request body:

<CaptureRoleOperation xmlns="" xmlns:i="">

The following example shows the format of the request body to capture a Linux Virtual Machine:

<CaptureRoleOperation xmlns="" xmlns:i="">

The following table describes the elements of the request body.

Element name



Required. Must be set to CaptureRoleOperation.


Required. Specifies the action that is performed after the capture operation finishes.

Possible values are:

  • Delete – this value causes the virtual machine to be deleted after the image has been captured.

  • Reprovision – this value causes the virtual machine to be redeployed after the image is captured by using the specified information in ProvisioningConfiguration.


Optional. Contains information that is used to redeploy a Virtual Machine after an image has been captured. This element is only used when the PostCaptureAction is set to Reprovision.


Required. Specifies the description of the captured image. The value of this element is only obtained programmatically and does not appear in the Management Portal.


Required. Specifies the name of the captured image.


Contains information that is used to redeploy a Virtual Machine after an image has been captured.

Element name



Required. To provision a new Virtual Machine, you must specify one of the following configuration sets:

  • WindowsProvisioningConfiguration

  • LinuxProvisioningConfiguration


Optional in WindowsProvisioningConfiguration. Specifies the computer name for the Virtual Machine. If you do not specify a computer name, one is assigned that is a combination of the deployment name, role name, and identifying number. Computer names must be 1 to 15 characters long.


Required in WindowsProvisioningConfiguration. Specifies the base-64-encoded string that contains the administrator password to use for the Virtual Machine.


Optional in WindowsProvisioningConfiguration. Specifies whether automatic updates are enabled for the Virtual Machine.

Possible values are:

  • true

  • false

The default value is true.


Optional in WindowsProvisioningConfiguration. Specifies the time zone for the Virtual Machine.

For a complete list of supported time zone entries, you can:

  • Refer to the values listed in the registry entry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones.

  • You can use the tzutil command-line tool to list the valid time.


Optional in WindowsProvisioningConfiguration. Contains properties that define a domain to which the Virtual Machine will be joined.


Optional in WindowsProvisioningConfiguration. Contains a list of service certificates with which to provision to the new Virtual Machine.


Optional in WindowsProvisioningConfiguration. Contains configuration settings for the Windows Remote Management service on the Virtual Machine. This enables remote Windows PowerShell.


Required in WindowsProvisioningConfiguration. Specifies the name of the default administrator account. This is a required parameter after version 2013-03-01.


Optional in WindowsProvisioningConfiguration. Specifies a base-64 encoded string of custom data. The base-64 encoded string is decoded to a binary array that is saved as a file on the Virtual Machine. The maximum length of the binary array is 65535 bytes. The file is saved to %SYSTEMDRIVE%\AzureData\CustomData.bin. If the file exists, it is overwritten. The security on directory is set to System:Full Control and Administrators:Full Control.

The CustomData element is only available using version 2013-10-01 or higher.


Optional. Specifies additional base-64 encoded XML formatted information that can be included in the Unattend.xml file, which is used by Windows Setup.

The AdditionalUnattendContent element is only available using version 2014-04-01 or higher.


Required in LinuxProvisioningConfiguration. Specifies the host name for the Virtual Machine. Host names must be 1 to 64 characters long.


Required in LinuxProvisioningConfiguration. Specifies the name of a user account to be created in the sudoer group of the Virtual Machine. User account names must be 1 to 32 characters long.


Required in LinuxProvisioningConfiguration. Specifies the password for the user account. Passwords must be 6 to 72 characters long.


Optional in LinuxProvisioningConfiguration. Specifies whether SSH password authentication is disabled. By default this value is set to true.

Possible values are:

  • true

  • false

The default value is true.


Optional in LinuxProvisioningConfiguration. Specifies the SSH public keys and key pairs to use with the Virtual Machine.


Optional in LinuxProvisioningConfiguration. Specifies a base-64 encoded string of custom data. The base-64 encoded string is located in the ovf-env.xml file on the ISO of the Virtual Machine. The file is copied to /var/lib/waagent/ovf-env.xml by the Azure Linux Agent. The Azure Linux Agent will also place the base-64 encoded data in /var/lib/waagent/CustomData during provisioning. The maximum length of the binary array is 65535 bytes.

The CustomData element is only available using version 2013-10-01 or higher.


Contains properties that define a domain to which the Virtual Machine will be joined.

Element name



Optional. Specifies the credentials to use to join the Virtual Machine to the domain.


Optional. Specifies the domain to join.


Optional. Specifies the Lightweight Directory Access Protocol (LDAP) X 500-distinguished name of the organizational unit (OU) in which the computer account is created. This account is in Active Directory on a domain controller in the domain to which the computer is being joined.




Specifies the credentials to use to join the Virtual Machine to the domain.


Optional. Specifies the name of the domain used to authenticate an account. The value is a fully qualified DNS domain. If the domains name is not specified, Username must specify the user principal name (UPN) format (user@fully-qualified-DNS-domain) or the fully-qualified-DNS-domain\username format.



Required. Specifies a user name in the domain that can be used to join the domain.


Required. Specifies the password to use to join the domain.


Contains a list of service certificates with which to provision to the new Virtual Machine. Stored certificate settings reference certificates that already exist in the cloud service. Before you configure the stored certificates for the Virtual Machine, you must call the Add Service Certificate operation or add the certificate by using the Management portal.

Element name



Required. Specifies the parameters for the certificate.


Required. Specifies the certificate store location on the Virtual Machine.

The only supported value is LocalMachine.


Required. Specifies the name of the certificate store from which the certificate is retrieved.

For example, “My”.


Required. Specifies the thumbprint of the certificate. The thumbprint must specify an existing service certificate.


Contains configuration settings for the Windows Remote Management service on the Virtual Machine.

Element name



Required. Contains a collection of information for enabling remote Windows PowerShell.


Required. Specifies the protocol and certificate information for the listener.


Specifies the protocol of listener.

  • Http

  • Https

The value is case sensitive.


Optional. Specifies the certificate thumbprint for the secure connection. If this value is not specified, a self-signed certificate is generated and used for the Virtual Machine.


Specifies additional base-64 encoded XML formatted information that can be included in the Unattend.xml file, which is used by Windows Setup.

Element name



Required. Specifies the name of the pass that the content applies to. The only allowable value is oobeSystem.


Required. Specifies the name of the component to configure with the added content. The only allowable value is Microsoft-Windows-Shell-Setup.


Required. Specifies the name of the setting to which the content applies.

Possible values are:

  • FirstLogonCommands

  • AutoLogon


Required. Specifies the base-64 encoded XML formatted content that is added to the unattend.xml file for the specified path and component. The XML must be less that 4 KB and must include the root element for the setting or feature that is being inserted.


Specifies the SSH public keys and key pairs to use with the Virtual Machine.

Element name



Optional. Specifies the collection of SSH public keys.


Required. Specifies the public key.


Required. Specifies the SHA1 fingerprint of an X509 certificate associated with the hosted service that includes the SSH public key.


Required. Specifies the full path of a file, on the Virtual Machine, where the SSH public key is stored. If the file already exists, the specified key is appended to the file.




Required. Contains a collection of SSH key pairs.


Required. Contains an SSH key pair to be installed on the virtual machine.


Required. Specifies the SHA1 fingerprint of an X509 certificate that is associated with the cloud service and includes the SSH keypair.


Required. Specifies the full path of a file, on the virtual machine, which stores the SSH private key. The file is overwritten when multiple keys are written to it. The SSH public key is stored in the same directory and has the same name as the private key file with .pub suffix.




The response includes an HTTP status code, a set of response headers, and a response body.

Status Code

A successful operation returns status code 202 (Accepted).

Response Headers

The response for this operation includes the following headers. The response may also include additional standard HTTP headers.

Response Header



A value that uniquely identifies a request made against the management service.

Response Body



The image that is captured from the Virtual Machine is located in the same storage account its operating system disk. You can find the name of the storage account by looking at the Disks section of the dashboard for the Virtual Machine in the portal.