Microsoft Azure
Connects the CLM to Microsoft Azure for discovery and management of certificates in Azure Key Vault and Enterprise Applications (SSO/SAML).
Uses of this integration
| Feature | Supported |
|---|---|
| Discovery of certificates in Azure Key Vault | ✅ |
| Discovery of certificates in Enterprise Applications (SSO/SAML) | ✅ |
| Deploy of certificates to Azure Key Vault (via Store) | ✅ |
| Automatic creation of Stores per Key Vault | ✅ |
| Certificate issuance | ❌ |
Prerequisites
An App Registration in Azure Active Directory with the following permissions:
For Key Vault:
Key Vault Certificates Officer— to read and write certificates in Key Vaults
For Enterprise Applications:
Application.Read.All(Microsoft Graph) — to list applications and their certificates
The account needs access to the Subscriptions and Resource Groups that will be included in discovery.
Register
- Go to Integrations in the sidebar menu
- Find the Azure card and click + Configure
- Fill in the fields:
| Field | Description |
|---|---|
| Name | Name to identify the integration, e.g. Azure-Production |
| Tenant ID | Azure AD directory ID |
| Subscription ID | Azure subscription ID |
| Client ID | App Registration ID |
| Client Secret | App Registration secret |
- Click Test connection to validate
- Click Save changes
Edit and Delete
Click the ⋮ menu on the integration card to edit or delete. Remove the linked Stores and discovery jobs before deleting.