See below for adding a Cloud Service Provider account for Azure.

When the service account keys are rotated, the Cryptographic Security Platform Vault for Cloud Keys creates a new key and replaces the key that was used when you registered the Cloud Service Provider account. Please do not delete the service account key.

To add an account for Azure

  1. Log in to the Cryptographic Security Platform Vault for Cloud Keys webGUI using an account with Cloud Admin privileges.
  2. In the top menu bar, click CloudKeys.
  3. Click the CSP Accounts tab and select Actions > Add Cloud Service Provider Account.
  4. On the Details tab of the Add CSP dialog box, enter the account details. 

  5. Click Continue.

  6. On the Schedule tab, determine the rotation schedule for the access keys. 

    • Never
    • Every x days
    • Every x weeks
    • Every x months
    • Every x years
  7. Click Add.

Name

The name you want to use for the Cloud Service Provider Account.

Description

An optional description of the Cloud Service Provider Account.

Admin Group

Select the admin group you want to use for the account.

Type

Select AZURE.

Microsoft Entra Tenant ID

Enter the Microsoft Entra tenant ID.

You can find this value in Azure under Azure > Azure Active Directory.

Subscription ID

The Azure subscription ID.

You can find this in Azure under Azure > Subscriptions.

Application (Client) ID

The Service Principal client ID. Click the link to update the Client ID and Client Secret.

You can find this in Azure under Azure > Azure Active Directory > App Registrations

Application Object ID

The Object ID of your BYOK application. This is required if you don't have Microsoft Graph permissions.

You can find this in Azure under Azure > Azure Active Directory > App Registrations

Authentication Method

The authentication method. Select: 

  • Client Secret to use the Azure Service Principal secret that you created for authentication.
  • Internally generated CSR / Certificate to use certificate-based authentication and optionally generate a self-signed certificate. You can accept the generated certificate expiration, or choose your own expiration date. You will need to upload the certificate to the Azure App Service. 

    If you do not allow the self-signed certificate to be generated, a certificate signing request will be generated, which you must sign and upload to both Azure and Vault.

  • Externally Signed Certificate to upload a certificate file and private key in PEM format. 

    Upload the certificate file to the Azure App Service before you create the Cloud Service Provider Account.

Common Name

If you selected Internally generated CSR / Certificate, enter the common name to be used for the certificate.

If you are using client secret-based or externally signed certificate-based authentication, then this field is hidden.

Passphrase

If you selected Externally Signed Certificate, you can enter a passphrase to encrypt the private key.

If you are using client secret-based or internally generated certificate-based authentication, then this field is hidden.

Client Secret

The Azure Service Principal secret that you created.

If you are using certificate-based authentication, then this field is hidden.