Azure Onboarding Process
Connect Azure to Wiv with the in-app keyless wizard. Wiv provisions federated workload identity, billing export to Blob, and per-subscription access — no client secret to store.
Written By Dotan Cohen
Last updated 11 days ago
Connect Azure to Wiv from Integrations → Azure → New Azure Integration. The wizard uses Microsoft sign-in and provisions a federated workload integration — Wiv does not store a long-lived client secret.
Note: Need a client-secret wiv_account instead? Use Azure Onboarding Process (script) or Azure Onboarding Process (Manual).
What Wiv sets up
Discovers your tenant, billing accounts, subscriptions, and management groups.
Creates or reuses a host subscription (existing or dedicated from billing scope).
Registers an Entra app and configures federated workload trust (no stored client secret).
Grants billing-account roles and per-subscription Reader, Monitoring Reader, and Cost Management Reader.
Creates a daily FOCUS Parquet export to Blob with managed identity (
allowSharedKeyAccess=false).Optionally assigns metrics scope at a management group.
Verifies federated access and saves the integration.
Wiv does not create Synapse resources for new installations.
Prerequisites
Billing account visibility
The wizard needs a billing account visible to the Microsoft login you use (EA, MCA, or CSP partner MCA). Customer tenants with no billing account cannot complete in-app onboarding.
Permissions in Wiv
You need permission to create integrations in Wiv.
Permissions in Microsoft Entra / Azure
Sign in as a user who can discover billing accounts, list subscriptions, create Azure resources, and create an Entra app with a federated credential.
EA only: Enterprise Administrators must enable Account owners can view charges under Cost Management + Billing → Policies.
Connect in Wiv
Sign in to Wiv and go to Integrations.
Click Azure, then New Azure Integration.
Follow the four wizard steps: Connect, Configure, Provision, Complete.
Connect
On Grant Wiv.ai access to Azure, click Connect to Azure. Microsoft asks you to authorize Wiv to discover your tenant and billing scope, then provision resources.

Configure
On Choose your Azure scope, select the billing account, complete agreement-specific fields (MCA billing profile, EA enrollment account, or CSP customer scope), confirm the host subscription name, optionally select a metrics management group, and click Apply.

When Apply succeeds, the panel shows Configuration confirmed:

Provision
Setting up your integration runs provisioning phases (host subscription, app registration, billing roles, smoke test, FOCUS export, optional metrics, federated trust, verification). Use Retry on a failed phase or Onboard Manually to fall back.

Complete
When setup succeeds you see Your Azure environment is connected. Click View Cloud Inventory to open the Azure integrations list.

Generate Integration Link
MSP and customer-led onboarding can use Generate Integration Link from the Azure integrations page. The link flow uses the same provisioning engine as this wizard.

After onboarding
Confirm the new Azure integration appears under Integrations → Azure.
Allow 5–30 minutes for the first FOCUS export, or run Run now on
WivFocusDailyExportin the Azure portal.Do not delete the Entra app registration while the integration is active — workflows fail with
AADSTS700016if the app is removed.