> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Azure

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/azure.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=44f49f086a7cd22f99447aa35c2f45cc" alt="" noZoom width="96" height="96" data-path="images/connectors/azure.svg" />

  <h1>Azure</h1>
</div>

## Connection

### Setup

<Steps>
  <Step title="Create a service principal">
    [Register an app and create a service principal](https://learn.microsoft.com/entra/identity-platform/howto-create-service-principal-portal),
    then [add a client secret](https://learn.microsoft.com/en-us/entra/identity-platform/how-to-add-credentials?tabs=client-secret#add-a-credential-to-your-application) to it.
  </Step>

  <Step title="Assign it a role">
    [Assign](https://learn.microsoft.com/azure/role-based-access-control/role-assignments-portal) one of
    the roles under [Permissions](#permissions) on the management group, subscription or resource group
    Klef grants access at.
  </Step>
</Steps>

### Settings

| Setting                                                   | Required | Description                                                                               |
| --------------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------- |
| Tenant ID                                                 | Yes      | Directory (tenant) ID of your Entra tenant.                                               |
| Client ID                                                 | Yes      | Application (client) ID of the service principal Klef signs in as.                        |
| Client secret                                             | Yes      | Client secret of that service principal. Stored encrypted.                                |
| Scope (management group, subscription, or resource group) | Yes      | Resource ID of the management group, subscription or resource group Klef grants roles on. |
| Assignment mode                                           |          | The kind of assignment the connection test checks permissions for.                        |

### Permissions

Minimum permissions the connection requires.

| Capability                                                      | Required | Granted by (any one)                           |
| --------------------------------------------------------------- | -------- | ---------------------------------------------- |
| Read role assignments and definitions                           | Yes      | `Reader`, `User Access Administrator`, `Owner` |
| Assign and remove roles                                         | Yes      | `User Access Administrator`, `Owner`           |
| Grant access that expires                                       |          | `User Access Administrator`, `Owner`           |
| Make principals eligible through Privileged Identity Management |          | `User Access Administrator`, `Owner`           |
| Resolve principals by address                                   |          | `User.Read.All`, `Directory.Read.All`          |

## azure.iam\_role\_assignment

### Fields

| Field                           | Type               | Required | Description                                                                                                                                                                          |
| ------------------------------- | ------------------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `principalId` (Directory user)  | reference, user    | Yes      | The Entra user the roles are granted to, by object ID, sign-in name or email. Names the account rather than describing it, so a diff leaves it out.                                  |
| `roles`                         | grant              |          | Azure role assignments the user holds. One row grants one role.                                                                                                                      |
| `roles[].role`                  | string             | Yes      | Role definition ID, such as acdd72a7-3385-48ef-bd42-f606fba81ae7 for Reader.                                                                                                         |
| `roles[].scope`                 | string             |          | Resource ID the role applies to. Defaults to the connection's scope.                                                                                                                 |
| `roles[].mode` (How it is held) | enum               |          | How the role is held. An eligible role is activated through Privileged Identity Management. Defaults to active. Values: `active` (Held outright), `eligible` (Eligible to activate). |
| `roles[].condition`             | string, up to 8000 |          | Attribute-based condition that narrows the assignment.                                                                                                                               |
| `roles[].expiresAt`             | date               |          | When the assignment ends. Azure removes it at that time.                                                                                                                             |

## Examples

### Cloud access for engineers

AWS permission sets and Azure roles for engineers, read-only in production with just-in-time Contributor, removed when they leave.

```hcl theme={null}
stage active {
  target azure.iam_role_assignment {
    principalId = worker.business_email
    roles = [
      # Reader on the production subscription.
      {
        role  = "acdd72a7-3385-48ef-bd42-f606fba81ae7"
        scope = "/subscriptions/00000000-0000-0000-0000-000000000000"
        mode  = "active"
      },
      # Contributor on production, activated through Privileged Identity Management when needed.
      {
        role  = "b24988ac-6180-42a0-ab88-20f7382dd24c"
        scope = "/subscriptions/00000000-0000-0000-0000-000000000000"
        mode  = "eligible"
      },
    ]
  }
}
```
