Certificate Manager integrates with Microsoft Azure to manage SAML certificates within Azure enterprise applications. Certificate Manager authenticates and interacts with Azure resources using a configured service account.
Create an Azure application
- Access the Azure platform and log in to your account.
- Locate the service Microsoft Entra ID.
- From the side menu, go to Manage > App registrations.
- Click New registration.
- In the Name * field, enter a name for the application.
- Select which account types can use the app or access the API.
- Optional: Select the redirect URI to receive the authentication response.
- Click Register.
- In the Essentials section, copy the values of the following fields:
- Application (client) ID.
- Directory (tenant) ID.
Create a client secret
- Access the Azure platform and log in to your account.
- Locate the service Microsoft Entra ID.
- From the side menu, go to Manage > App registrations.
- Go to the All applications tab and select the application you created.
- From the application's side menu, go to Manage > Certificates & secrets.
- Click New client secret.
- In the Description field, enter a description for the client secret.
- In the Expires field, select when the client secret will expire.
- Click Add.
After creating the client secret, make sure to copy the Value field of the client secret. Otherwise, you will have to create another client secret.
Select API permissions
- Access the Azure platform and log in to your Azure account.
- Locate the service Microsoft Entra ID.
- From the side menu, go to Manage > App registrations.
- Go to the All applications tab and select the application you created.
- From the application's side menu, go to Manage > API permissions.
- In the Configured permissions section, click Add a permission and select Microsoft Graph.
- Select the Application permissions tab, then select the following permission:
Application.ReadWrite.All. - Click Add permissions.
- After adding the permissions, click Grant admin consent for [Azure Active Directory name] and select Yes.
This process is performed in a third-party platform and may change without notice.
Integrate Azure with Certificate Manager
- On Segura® Platform, in the navigation bar, hover over the Products menu and select Certificate Manager.
- From the side menu, go to Management > Authorities and click Cloud providers.
- Go to Add > Azure account.
- In the Name * and Tenant ID * fields, enter a name for the account and the tenant ID obtained in Create an Azure application.
- In the Status field, enable or disable the account.
- Check Set the access data to enter the account's access credentials.
- In the Client ID * and Client secret * fields, enter the values obtained in Create an Azure application and Create a client secret.
- Click Save.
When you create a new account, the form also displays guidance on what the account can be used for, along with a link to this documentation. This guidance appears only when you create an account, not when you edit an existing one.
After you save the account, a confirmation dialog opens automatically. You cannot close it by clicking outside it. Click the button to go directly to the Discovery using Microsoft Azure setup screen. If you do not have permission to create a discovery, the button appears disabled with an explanation of how to request access. To finish account creation without moving on to Discovery, close the dialog: the account is already saved, and you can navigate to Discovery manually later.
The newly added account will appear in the Cloud providers report.