Azure Onboarding Process

Connect Azure to Wiv with the in-app keyless wizard. Wiv provisions federated workload identity, billing export to Blob, and per-subscription access — no client secret to store.

Written By Dotan Cohen

Last updated 11 days ago

Connect Azure to Wiv from IntegrationsAzureNew Azure Integration. The wizard uses Microsoft sign-in and provisions a federated workload integration — Wiv does not store a long-lived client secret.

Note: Need a client-secret wiv_account instead? Use Azure Onboarding Process (script) or Azure Onboarding Process (Manual).

What Wiv sets up

  1. Discovers your tenant, billing accounts, subscriptions, and management groups.

  2. Creates or reuses a host subscription (existing or dedicated from billing scope).

  3. Registers an Entra app and configures federated workload trust (no stored client secret).

  4. Grants billing-account roles and per-subscription Reader, Monitoring Reader, and Cost Management Reader.

  5. Creates a daily FOCUS Parquet export to Blob with managed identity (allowSharedKeyAccess=false).

  6. Optionally assigns metrics scope at a management group.

  7. Verifies federated access and saves the integration.

Wiv does not create Synapse resources for new installations.

Prerequisites

Billing account visibility

The wizard needs a billing account visible to the Microsoft login you use (EA, MCA, or CSP partner MCA). Customer tenants with no billing account cannot complete in-app onboarding.

Permissions in Wiv

You need permission to create integrations in Wiv.

Permissions in Microsoft Entra / Azure

Sign in as a user who can discover billing accounts, list subscriptions, create Azure resources, and create an Entra app with a federated credential.

EA only: Enterprise Administrators must enable Account owners can view charges under Cost Management + BillingPolicies.

Connect in Wiv

  1. Sign in to Wiv and go to Integrations.

  2. Click Azure, then New Azure Integration.

  3. Follow the four wizard steps: Connect, Configure, Provision, Complete.

Connect

On Grant Wiv.ai access to Azure, click Connect to Azure. Microsoft asks you to authorize Wiv to discover your tenant and billing scope, then provision resources.

Configure

On Choose your Azure scope, select the billing account, complete agreement-specific fields (MCA billing profile, EA enrollment account, or CSP customer scope), confirm the host subscription name, optionally select a metrics management group, and click Apply.

When Apply succeeds, the panel shows Configuration confirmed:

Provision

Setting up your integration runs provisioning phases (host subscription, app registration, billing roles, smoke test, FOCUS export, optional metrics, federated trust, verification). Use Retry on a failed phase or Onboard Manually to fall back.

Complete

When setup succeeds you see Your Azure environment is connected. Click View Cloud Inventory to open the Azure integrations list.

Generate Integration Link

MSP and customer-led onboarding can use Generate Integration Link from the Azure integrations page. The link flow uses the same provisioning engine as this wizard.

After onboarding

  • Confirm the new Azure integration appears under IntegrationsAzure.

  • Allow 5–30 minutes for the first FOCUS export, or run Run now on WivFocusDailyExport in the Azure portal.

  • Do not delete the Entra app registration while the integration is active — workflows fail with AADSTS700016 if the app is removed.

Troubleshooting

Symptom

Likely cause

Action

Connect failed

Insufficient Microsoft permissions

Retry Connect or use script/manual path

No billing accounts in Configure

Wrong tenant or missing billing read access

Sign in to partner/EA/MCA tenant with billing admin rights

Grant billing access failed

Billing IAM not sufficient

Confirm billing account owner/contributor; wait for propagation

No cost data

First export pending

Run Run now on WivFocusDailyExport

AADSTS700016 in workflows

App deleted or wrong tenant

Re-onboard the integration