See below for adding a Cloud Service Provider account for Azure.
When the service account keys are rotated, the Cryptographic Security Platform Vault for Cloud Keys creates a new key and replaces the key that was used when you registered the Cloud Service Provider account. Please do not delete the service account key.
To add an account for Azure
- Log in to the Cryptographic Security Platform Vault for Cloud Keys webGUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
- Click the CSP Accounts tab and select Actions > Add Cloud Service Provider Account.
On the Details tab of the Add CSP dialog box, enter the account details.
Click Continue.
On the Schedule tab, determine the rotation schedule for the access keys.
- Never
- Every x days
- Every x weeks
- Every x months
- Every x years
Click Add.
Name
The name you want to use for the Cloud Service Provider Account.
Description
An optional description of the Cloud Service Provider Account.
Admin Group
Select the admin group you want to use for the account.
Type
Select AZURE.
Microsoft Entra Tenant ID
Enter the Microsoft Entra tenant ID.
You can find this value in Azure under Azure > Azure Active Directory.
Subscription ID
The Azure subscription ID.
You can find this in Azure under Azure > Subscriptions.
Application (Client) ID
The Service Principal client ID. Click the link to update the Client ID and Client Secret.
You can find this in Azure under Azure > Azure Active Directory > App Registrations
Application Object ID
The Object ID of your BYOK application. This is required if you don't have Microsoft Graph permissions.
You can find this in Azure under Azure > Azure Active Directory > App Registrations
Authentication Method
The authentication method. Select:
- Client Secret to use the Azure Service Principal secret that you created for authentication.
- Internally generated CSR / Certificate to use certificate-based authentication and optionally generate a self-signed certificate. You can accept the generated certificate expiration, or choose your own expiration date. You will need to upload the certificate to the Azure App Service.
If you do not allow the self-signed certificate to be generated, a certificate signing request will be generated, which you must sign and upload to both Azure and Vault.
- Externally Signed Certificate to upload a certificate file and private key in PEM format.
Upload the certificate file to the Azure App Service before you create the Cloud Service Provider Account.
Common Name
If you selected Internally generated CSR / Certificate, enter the common name to be used for the certificate.
If you are using client secret-based or externally signed certificate-based authentication, then this field is hidden.
Passphrase
If you selected Externally Signed Certificate, you can enter a passphrase to encrypt the private key.
If you are using client secret-based or internally generated certificate-based authentication, then this field is hidden.
Client Secret
The Azure Service Principal secret that you created.
If you are using certificate-based authentication, then this field is hidden.