Skip to main content
The Microsoft Azure connector uses the Cloud Infrastructure Access data model, which stores access as role-scope bindings and computes effective access on demand. This enables access requests with resource hierarchy navigation, access reviews scoped by inheritance, entitlement configuration rules based on role and scope, and lifecycle automation across the Azure resource tree.

Capabilities

This connector pulls account, group, managed identity, and enterprise application information from the Entra ID connector. You’ll configure this relationship when setting up the connector.

Gather Azure credentials

Configuring the connector requires you to pass in credentials generated in Azure. Gather these credentials before you move on.
A user with the Global Administrator permission in Azure must perform this task.

Create a new Entra application

1
In the Entra admin center, navigate to App registrations.
2
Click + New registration.
3
Give the application a name, such as “C1”, and select the supported account type relevant to your Entra installation. You do not need to set a redirect URL.
4
Click Register.
5
The new app is created. Carefully copy and save the Application (client) ID and the Directory (tenant) ID shown on the application summary page.
6
Next, we’ll generate a client secret for this app. Click Certificates & secrets.
7
Click + New client secret.
8
Give the client secret a description and set its expiration.
9
Click Add.
10
The client secret is generated. Carefully copy and save the Secret Value.

Assign Azure RBAC permissions to the application

Repeat this process for each subscription you want to sync to C1. Alternately, you can grant a Management Group scope encompassing all the desired subscriptions.
Management groups are listed on every sync run, regardless of whether any role assignment references one. If the connector’s credentials only have Reader at the subscription level, that listing is denied and the whole sync fails — it does not degrade gracefully. Grant Reader at the Management Group scope too (instead of, or in addition to, at each subscription below it).
1
In the Azure portal’s search bar, type “Subscriptions” and select the relevant Azure subscription.
2
In the left-hand menu of your subscription, select Access control (IAM).
3
Click + Add > Add role assignment.
4
On the Role tab, search for and select the Reader role. If you want to use the C1 connector to provision Azure roles, also grant the User Access Administrator role. Then, on the Conditions tab, select Allow user to assign all roles.
5
Click Next.
6
On the Members tab, ensure User, group, or service principal is selected for Assign access to.
7
Click + Select members.
8
In the Select members pane, search for and select the name of your App Registration.
9
Click Select at the bottom of the pane.
10
Click Review + assign at the bottom. Allow time for the new role to propagate. Azure role assignments can take several minutes (typically five to 15, sometimes up to 30) to fully propagate.

Grant access to provision tenant root scoped role assignments (optional)

If you need C1 to provision role assignments at the Azure tenant root scope (/) — that is, role assignments that appear as “Root (inherited)” throughout your Azure hierarchy — the app requires an additional User Access Administrator assignment at that scope.
The Tenant Root Group visible in the Azure Portal is a management group, not the actual tenant root scope. Role assignments made there will not grant the necessary permission. This setup must be done using the Azure CLI.
A user with the Global Administrator permission in Azure must perform this task.
1
Elevate the Global Administrator’s own access to the tenant root scope. Run the following command using the Azure CLI:
2
Assign the User Access Administrator role to your app at the tenant root scope. Replace <app-object-id> with the Object ID of your Entra app registration (found in Entra ID → App registrations → your app → Overview):
3
Revoke the Global Administrator’s temporary elevated access using one of the following methods:Option A — Azure Portal: Navigate to Microsoft Entra ID → Properties, set Access management for Azure resources back to No, and click Save.Option B — Azure CLI:
To remove this permission from the app in the future:
Done. Next, move on to the connector configuration instructions.

Optional configuration

Three additional settings are available in the connector’s configuration form:
  • Azure cloud — the Azure cloud environment to connect to: public (default), usgovernment, or china. This is the only way to point the connector at the US Government or China clouds instead of the public Azure cloud.
  • Skip roles with no assignments — when enabled, only Azure roles with at least one active assignment are synced, instead of every role definition in scope.
  • Sync sub-resources — which kinds of nested sub-resource to sync. Leave empty to sync none. Sub-resources are not a separate resource type: each one is synced as an Azure resource, nested under the Azure resource that owns it.
Sync sub-resources only has an effect if the Azure resources resource type is enabled.Sub-resources are synced as children of the Azure resources that own them — a blob container is synced under its storage account. If Azure resources are not being synced, there are no parents to sync them under, and enabling this setting does nothing.

Supported sub-resource types

Each value below is a scope Azure documents as directly role-assignable. Everything listed here syncs as an Azure resource — the values select which kinds are included, not which resource types exist. Select only the ones you need: each selected value costs one extra API call per parent resource, on every sync. Not currently supported: Key Vault secrets, keys and certificates (listing them requires a Key Vault data-plane connection, which is separate from the Azure Resource Manager access this connector uses), Azure Files shares, Service Bus topic subscriptions, and Event Hubs consumer groups.

Why sync sub-resources

Azure allows a role to be assigned directly at a sub-resource scope. A common example is granting Storage Blob Data Contributor on a single blob container rather than on the whole storage account:
Assignments made at those scopes are only visible in C1 if the sub-resource itself is synced. With this setting disabled, access granted on an individual container does not appear anywhere, even though the storage account above it syncs normally. The trade-off is API calls: each selected type costs one additional request per parent resource per sync — selecting all three storage types means three extra calls for every storage account in the tenant. That is why nothing is selected by default, and why the types are chosen individually rather than with a single on/off switch.
If a resource cannot be listed because it does not offer that sub-resource at all — a disabled storage account, or a Premium account that has no queue or table service — the connector skips it and continues syncing everything else. A permissions error is different: if the connector is not allowed to list a resource’s children, the sync fails, because silently syncing less access than exists would be misleading.

Configure the Azure connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of Azure credentials generated by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Azure and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Paste the application (client) ID into the Azure client ID field.
9
Paste the client secret into the Azure client secret field.
10
Paste the directory (tenant) ID into the Azure tenant ID field.
11
Click Save.
12
Finally, tell the connector where to find the identities that will be used for this app in C1.
  1. In the Shared identity source area of the page, click Edit.
  2. Select your Entra connector.
  3. Under Only import identities of type, select Users, Groups, and Apps. Azure reports both managed identities and enterprise applications as service principals, so role assignments held by an enterprise application only resolve when Apps is selected.
  4. Optional. Limit the identities pulled from the connector you selected to only those with a certain entitlement by setting the entitlement.
  5. Click Save.
13
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your Azure connector is now pulling access data into C1.