# Azure: credentials

You create an app registration in Entra ID, store tenant, client, and secret under Cloud accounts, and let MainPath create clusters in your Azure subscription.

> Source: https://www.mainpath.ai/en/docs/azure-cloud-credentials/

Under [Cloud accounts]({{< relref "cloud-accounts" >}}) you store a service principal for Microsoft Azure. MainPath uses it to create [Kubernetes clusters]({{< relref "kubernetes-integration" >}}) (AKS) and optional databases in your subscription.

## Create an app registration in Entra ID

1. Open the [Azure portal](https://portal.azure.com/) → **Microsoft Entra ID** → **App registrations** → **New registration**.
2. Choose a descriptive name such as `application-platform-azure`.
3. Under **Overview**, note the **Directory (tenant) ID** and the **Application (client) ID**.
4. Under **Certificates & secrets** → **New client secret**, create a secret and copy the **Value** immediately. Azure shows it only once.
5. Under **Subscriptions**, note the **Subscription ID** of the subscription where the clusters should live.
6. Assign the enterprise application (the service principal) a role on that subscription that can create AKS, networks, and databases, for example **Contributor**.

Microsoft describes the path in [Create a Microsoft Entra app and service principal](https://learn.microsoft.com/entra/identity-platform/howto-create-service-principal-portal).

## Add the account in MainPath

1. Open **Cloud accounts** and click **Add cloud account**.
2. Choose **Azure**.
3. Enter a name, slug, and these values:

| Platform field | Source |
|---|---|
| Tenant ID | Directory (tenant) ID of the app registration |
| Client ID | Application (client) ID of the same app registration |
| Client secret | value of the client secret |
| Subscription ID | Subscription ID under **Subscriptions** |
| Region | Azure region, for example `germanywestcentral` |

4. Save. Then select the account when you create a cluster under **Kubernetes clusters**.

## See also

- [Cloud accounts]({{< relref "cloud-accounts" >}})
- [Kubernetes clusters]({{< relref "kubernetes-integration" >}})
- [AWS: credentials]({{< relref "aws-cloud-credentials" >}})
- [Google Cloud: credentials]({{< relref "gcp-cloud-credentials" >}})
- [Open Telekom Cloud: credentials]({{< relref "otc-cloud-credentials" >}})

