Connect to Azure for Recommendations
Here are the steps to manually set up your Azure integration with Amberflo.
Prerequisites
- Azure Portal Access: Ensure you have sufficient permissions in the Azure portal to create exports and access billing scopes.
- Global Admin Access: If you do not see specific billing scopes or subscriptions, you may need Global Administrator privileges.
During the setup process, you will define the following values. Be sure to record them, as you will need to share these with Amberflo to complete the integration:
Credentials:
- Application (client) ID
- Directory (tenant) ID
- Client secret
Amberflo can integrate with Microsoft Azure to surface actionable cost optimization recommendations based on your usage. This guide walks you through the steps required to securely create the integration with Azure.
Step 1: Create Credentials for Amberflo
- Search for and open Microsoft Entra ID.
- In the left-hand menu, select Manage > App registrations, then click + New registration.
- Name the application (for example, Amberflo) and leave the remaining fields at their default values.
- Click Register.
- On the Overview page of your new application:
- Copy and save the following values for later use:
- Application (client) ID
- Directory (tenant) ID
Next, create a client secret:
- In the left-hand menu, select Certificates & secrets.
- Click + New client secret to generate a secret.
- Copy the Value field of the new client secret and store it securely. This is only shown once.
Note: If your client secret is set to expire, you must renew it before expiration and provide Amberflo with the updated value.
Step 2: Create a Custom Role for Azure Advisor Access
- In the Azure Portal, search for and navigate to Subscriptions.
- Select one of your active subscriptions.
- In the left-hand panel, select Access Control (IAM).
- Click + Add, then choose Add custom role.
- Choose Start from JSON and paste in the following role definition:
- Under Assignable scopes, click Add assignable scopes.
- Select Subscriptions, then choose all subscriptions you want to include.
- Click Select, then Review + create, and finally click Create.
Step 3: Assign the Custom Role to Amberflo
You now need to assign the custom role to the app you created:
In Subscriptions, select each subscription you included in the previous step. For each one the subscriptions we will do the following:
- Go to Access Control (IAM) and click + Add > Add role assignment.
- Under the Roles tab, search for and select the custom role you created (e.g., Amberflo Recommendations Reader).
- Click Next, then Select members.
- In the search box, enter the name of the Service Principal you registered earlier (e.g., Amberflo) and select it.
- Note: The list may initially display only user accounts. To locate your registered application, begin typing the name of the Service Principal (e.g., “Amberflo”) in the search box. The application should appear once you begin entering its name.
- Click Select, then Review + assign.
Repeat these steps for each subscription where you want to enable recommendations.
Step 4: Provide Credentials to Amberflo
Once everything is configured, collect the following values from Step 1:
- Application (client) ID
- Directory (tenant) ID
- Client secret