Azure
Connection
Setup
1
Create a service principal
2
Assign it a role
Assign one of
the roles under Permissions on the management group, subscription or resource group
Klef grants access at.
Documentation Index
Fetch the complete documentation index at: /docs/llms.txt
Use this file to discover all available pages before exploring further.
Create a service principal
Assign it a role
| Setting | Required | Description |
|---|---|---|
| Tenant ID | Yes | Directory (tenant) ID of your Entra tenant. |
| Client ID | Yes | Application (client) ID of the service principal Klef signs in as. |
| Client secret | Yes | Client secret of that service principal. Stored encrypted. |
| Scope (management group, subscription, or resource group) | Yes | Resource ID of the management group, subscription or resource group Klef grants roles on. |
| Assignment mode | The kind of assignment the connection test checks permissions for. |
| Capability | Required | Granted by (any one) |
|---|---|---|
| Read role assignments and definitions | Yes | Reader, User Access Administrator, Owner |
| Assign and remove roles | Yes | User Access Administrator, Owner |
| Grant access that expires | User Access Administrator, Owner | |
| Make principals eligible through Privileged Identity Management | User Access Administrator, Owner | |
| Resolve principals by address | User.Read.All, Directory.Read.All |
| Field | Type | Required | Description |
|---|---|---|---|
principalId (Directory user) | reference, user | Yes | The Entra user the roles are granted to, by object ID, sign-in name or email. Names the account rather than describing it, so a diff leaves it out. |
roles | grant | Azure role assignments the user holds. One row grants one role. | |
roles[].role | string | Yes | Role definition ID, such as acdd72a7-3385-48ef-bd42-f606fba81ae7 for Reader. |
roles[].scope | string | Resource ID the role applies to. Defaults to the connection’s scope. | |
roles[].mode (How it is held) | enum | How the role is held. An eligible role is activated through Privileged Identity Management. Defaults to active. Values: active (Held outright), eligible (Eligible to activate). | |
roles[].condition | string, up to 8000 | Attribute-based condition that narrows the assignment. | |
roles[].expiresAt | date | When the assignment ends. Azure removes it at that time. |
stage active {
target azure.iam_role_assignment {
principalId = worker.business_email
roles = [
# Reader on the production subscription.
{
role = "acdd72a7-3385-48ef-bd42-f606fba81ae7"
scope = "/subscriptions/00000000-0000-0000-0000-000000000000"
mode = "active"
},
# Contributor on production, activated through Privileged Identity Management when needed.
{
role = "b24988ac-6180-42a0-ab88-20f7382dd24c"
scope = "/subscriptions/00000000-0000-0000-0000-000000000000"
mode = "eligible"
},
]
}
}
Was this page helpful?