Azure Setup
Cloudgeni supports two Azure connection methods:- Quick Connect creates the service principal and required role assignments through an Azure authorization flow.
- Manual lets you connect an existing service principal by entering its credentials.
In The UI
- Choose the target workspace, open
Integrations, and select Cloud. - Choose Connect Azure.
- Enter an integration name.
- Choose Quick or Manual.
Quick Connect
- Select Quick.
- Choose Connect Azure.
- Sign in to Azure with an account that can grant the requested subscription permissions.
- Complete the consent flow and return to Cloudgeni.
- Verify that the integration becomes active.
Manual Service Principal
- Create or select a service principal with access to the subscription you want Cloudgeni to inspect.
- Select Manual.
- Enter the subscription ID and tenant ID.
- Enter the service principal’s client ID and client secret.
- Optionally add friendly subscription and tenant names and select a default Azure location.
- Save the integration and verify that it becomes active.
Guest Users (B2B) In Another Directory
If your subscriptions live in a Microsoft Entra directory where you are a guest user, the default sign-in lands in your home directory and the connection fails with “No Azure subscriptions found”. Use the optional Microsoft Entra directory (tenant) field on the Quick Connect card to enter the tenant ID or a verified domain of the directory that holds your subscriptions. You still need Owner (or User Access Administrator) on the target subscription in that directory so Quick Connect can create the role assignments.After Connect
Once the integration is active:- Run a sync to confirm inventory access
- Use Cloud Monitors for Azure Defender findings
- Use Cloud Compliance for framework-based posture scans
- Use Cost & Billing views after Azure Cost Management data has been collected
Service Principal Roles
Quick Connect creates the required role assignments automatically. For Manual setup, grant the service principalReader, Cost Management Reader,
Security Reader, Log Analytics Reader, and Storage Account Key Operator Service Role.
Cost Management Reader is required for actual Cost & Billing data.
create-for-rbac output before extracting fields: the client secret (password)
is returned exactly once and cannot be retrieved later. The manual credential form needs APP_ID
(client ID), CLIENT_SECRET, and TENANT_ID.
If your organization scopes permissions below the subscription, make sure every resource group,
workspace, and storage account you want Cloudgeni to inspect is included.
Verify The Connection
After either setup method:- Open the Azure integration and run a sync.
- Confirm the expected subscriptions and resources appear.
- Open Cost & Billing to verify cost access when
Cost Management Readeris configured. - Run a cloud compliance scan or review Azure Defender findings.
Cost Management Reader and Azure billing
visibility at the subscription scope.
Next
Connect Cloud
Return to the shared cloud setup page.
Cloud Compliance
Move into framework-based posture review once setup is healthy.