Skip to content

Getting started

Connect Azure

Paste four values into a four-step wizard. Nothing is stored until the last step, and the first cost data lands the following night.

Validated against the Azure portal on 27 July 2026 and the setup wizard on 4 August 2026.

You connect Azure yourself, in a four-step wizard at app.infralign.ai. This page owns the wizard.

Everything after the prerequisites happens on screen: the wizard signs in as your app registration, runs read-only checks, lists the subscriptions it found, and stores the credential encrypted only after you confirm.

Access is read-only. The two built-in roles grant no write permission on any resource, and no storage account is needed on the default path.

Book about 45 minutes at management group scope, of which roughly 25 minutes is hands-on.

PartTime
Entra portal work: app registration, secret, rolesAbout 12 minutes
Azure role propagationA wait of up to 10 minutes
The consent answer, when somebody else approves itMinutes to days. Send the request first
The wizard’s own four stepsAbout 6 minutes

Per-subscription role assignment costs about a minute per subscription instead of six minutes once. The propagation wait and the consent wait run at the same time, so neither has to block the other.

Figure 1 draws the whole path. It carries the product’s own two number sequences: three things in Entra first, then the wizard’s own four steps.

Onboarding at a glance. One amber band says who acts: your team, working inside your own Azure tenant, marked read-only and nothing is written to your estate. A chip beside the title reads your time, about 25 minutes. A time axis runs left to right: first in Entra, then in the wizard, then overnight. The band holds three cards, each a short numbered list. The first, chipped three things in Entra, holds register the app, grant two read-only roles, and create a client secret. The second, chipped wizard steps 1 and 2, holds paste the four values and watch the checks run. The third, chipped wizard steps 3 and 4, holds pick subscriptions and confirm. One arrow crosses into the cyan Infralign band below, labelled nightly 02:30 to 06:15 UTC, and lands on the outcome: cost data lands, and Infralign then opens your dashboards. Onboarding at a glance. One amber band says who acts: your team, working inside your own Azure tenant, marked read-only and nothing is written to your estate. A chip beside the title reads your time, about 25 minutes. A time axis runs left to right: first in Entra, then in the wizard, then overnight. The band holds three cards, each a short numbered list. The first, chipped three things in Entra, holds register the app, grant two read-only roles, and create a client secret. The second, chipped wizard steps 1 and 2, holds paste the four values and watch the checks run. The third, chipped wizard steps 3 and 4, holds pick subscriptions and confirm. One arrow crosses into the cyan Infralign band below, labelled nightly 02:30 to 06:15 UTC, and lands on the outcome: cost data lands, and Infralign then opens your dashboards.
Figure 1: You create and hold the credential. The roles grant no workload or resource-configuration writes, and Azure IAM revokes access after propagation.

Do the three Entra tasks first. They are one page, with a portal screenshot at every click: Entra app registration.

Come back here holding four values. The wizard asks for exactly these and nothing else:

ValueWhere it comes from
Directory (tenant) IDThe app registration’s Overview, in the Essentials panel
Application (client) IDThe same panel, two rows up. Not the Object ID
Client secret ValueCertificates & secrets, copied when Entra showed it once. Not the Secret ID
Secret expiry dateShown beside the secret when you created it

Two things also have to be true before the checks can pass. Both roles, Reader and Cost Management Reader, are assigned to infralign-reader at the scope you chose. And Azure has had up to ten minutes to propagate them, which is why an otherwise correct setup returns AuthorizationFailed on its first attempt.

Sign in with the exact address Infralign enrolled for you. A different work account, even your own on another tenant, lands on the “this account is not linked to a customer” screen instead.

The wizard is admin-only. Anyone else on your team reaches a status page until the connection is live and their dashboards open. It shows how far setup has got and nothing else: no credential, no identifiers, no controls.

By default the wizard refuses a credential from a different directory. Two cases need cross-tenant connections switched on: your Azure estate spans tenants, or you sign in from another tenant, such as a personal Microsoft account or a managed service provider. Ask Infralign to switch them on before you start.

Open the link Infralign sent you, or go to app.infralign.ai. While setup is incomplete, every URL lands the admin on the wizard.

Admin consent should already be in place from the consent URL, which is the documented path. If it is not, the first sign-in from your tenant raises the same dialog. Everything it asks for is a sign-in permission. It grants no access to your subscriptions or your cost data: that access comes from the two role assignments above, which you control. The full list, and the four checks to make in the dialog, are on dashboard sign-in.

If you administer more than one Infralign account, a picker asks which one you are acting for before the wizard opens.

Paste four values: the Directory (tenant) ID, the Application (client) ID, the client secret Value, and the secret’s expiry date.

No credential is stored at this point. The secret and its expiry stay in the browser tab you are working in. They are never written to local storage, session storage, or a URL.

Infralign receives the secret twice. Step 2 uses it for the validation run and discards it without writing it. Step 4 stores it, and step 4 is the only step that does. Close or reload the tab before then and nothing is stored.

From step 4 the secret is encrypted before it is written, and held only as ciphertext. The encryption key is kept outside the database. Details: security and data handling.

The two identifiers you typed behave differently. Selecting Validate the connection saves the Directory (tenant) ID and the Application (client) ID as a draft connection, with an audit entry recording that you entered them. Neither is a credential, and both appear in your own audit trail on the connection page.

Done when you select Validate the connection and the Validate step opens.

The Connect step of the setup wizard. A collapsible block titled "Three things in Entra first" lists the app registration, the two roles at management group scope, and the client secret. Below it, a form asks for the Directory (tenant) ID, the Application (client) ID, the client secret value, and the secret expiry date. A yellow banner across the top reads "Simulated Azure mode", because the capture comes from a development build.

Captured from the setup service on 4 August 2026, signed in as a test account. The “Simulated Azure mode” banner appears on development builds only. You will not see it.

Nothing has to be deleted or restarted, and no support request is involved.

If you close the tab before selecting Validate the connection, nothing is written. You start from an empty form.

Close it after that, and reopening app.infralign.ai lands you back in the wizard with both ID fields filled in from the draft. The secret and its expiry date are not saved, because step 4 is the only step that stores a credential. Paste those two again and carry on.

The wizard signs in as infralign-reader and runs read-only checks. Two apply to the account: one sign-in, and one subscription list. Three more run per subscription found: Reader, Cost Management Reader, and a one-day cost query.

It takes 30 to 60 seconds. Results stream in as each check settles, so a slow subscription does not hide the rest.

Nothing is written, in your tenant or in Infralign’s. A failed row explains itself and names the subscription. Fix the role assignment in the portal, then re-run the failed checks without re-entering anything.

Done when every check reports green, or the account checks are green and you have decided what to do about the subscriptions that failed.

The Validate step. A progress bar reads eleven of eleven checks passed. Under an Account heading, two green rows confirm the service-principal sign-in and that three subscriptions were discovered. Below, one group per subscription, each with three green rows: Reader assigned, Cost Management Reader assigned, and one day of cost data read.

Captured from the setup service. The subscriptions shown are test fixtures.

A subscription without the Reader role is invisible to discovery. It does not appear as a failed row, it does not appear at all. If you expected more subscriptions than the wizard found, assign the role and re-run discovery.

Every discovered subscription is ticked. Untick any you want left out. A subscription whose checks failed starts unticked and can be added later from the connection page, so one missing role assignment does not block the rest of the estate.

Adding one is deliberate, and takes about a minute:

  1. Open Admin → Connection.
  2. Select Re-check the connection. This runs the same discovery the wizard ran.
  3. Anything new appears in the subscription list, unticked, above a notice naming it.
  4. Tick it and select Save subscriptions. Collection starts on the next nightly run.

If the new subscription does not appear, infralign-reader has no Reader role on it. Assign the two roles and re-check. Or assign them at management group scope once, and every subscription created beneath it is discoverable from then on.

You cannot proceed with nothing ticked. If you untick everything and select the button, the step refuses inline with “Keep at least one subscription to continue.” Nothing is lost and nothing is stored; you are still on the same screen.

Zero subscriptions never reaches this step in the first place. Discovery is one of the account checks in step 2, and it fails there with “No subscriptions are visible to this app registration”, which means infralign-reader holds Reader on nothing. Assign it, at management group scope for preference, and re-run.

Done when the count above the list matches the subscriptions you want processed.

The Scope step. A list of three discovered subscriptions, each ticked, each showing its name and subscription ID. Above the list, a count reads three of three selected. Below it, a note in bold: a subscription created later is never added on its own.

Captured from the setup service. The subscriptions shown are test fixtures.

The last step lists everything about to be stored: both IDs, the credential type and its expiry, the subscriptions in scope, and any exclusion with the reason it was excluded. Read it, then select Finish setup.

This is the only irreversible step on the page. Everything before it can be abandoned by closing the tab. Finish setup writes the credential.

The same screen offers two optional extras you can skip: adding your team, and asking Infralign to connect a Teams webhook. Neither is needed for the first run. See manage who has access.

Done when the wizard replaces itself with a progress screen naming the ingestion window.

The Confirm step, headed "Here is what happens next". A "What we will save" card lists the tenant and client IDs, the credential type with its expiry, the subscriptions in scope, the one subscription excluded and who unticked it, and a line saying new subscriptions are added by you in settings and never automatically. A "Finish setup" card lists four numbered outcomes: the credential is stored encrypted and the first ingestion starts between 02:30 and 06:15, the first cost data is expected on a named date, Infralign checks that run and opens the dashboards once it has landed, and a person confirms by email from support@infralign.ai with no automated notification. Back and Finish setup buttons sit below. A third card offers two optional extras: adding team members, and a Teams webhook.

Captured from the setup service on 4 August 2026. The identifiers, subscription names and dates are seeded test fixtures. The “Simulated Azure mode” banner appears on development builds only.

Two clocks run, and they are not the same clock.

The data lands on a timer. The first nightly run starts between 02:30 and 06:15 UTC, and the progress screen names the day your cost data is expected.

The dashboards are opened by a person. Infralign checks that first run, and once the run has landed your dashboards open within one business day. A person at support@infralign.ai emails you when they are live. Nothing automated sends that message, and the progress screen updates when they open.

The progress screen that replaces the wizard, headed "Your first cost data lands Wednesday morning". A paragraph explains that nothing else is needed, that the first nightly run starts between 02:30 and 06:15, and that once the run has landed the dashboards open within one business day, confirmed by email from support@infralign.ai. A "What we have" card lists the customer, the tenant and app registration IDs, the subscriptions in scope, one excluded subscription, a note that a new subscription is added by an admin in settings and never on its own, and the day data is expected. Cards below offer optional extras and a support contact.

Captured from the setup service. The customer, identifiers and dates are seeded test fixtures.

A wizard finished on a Thursday evening therefore puts your cost data in place overnight, and your dashboards in front of your team by Friday close at the latest. Finish on a Friday and the business day is Monday.

Read your first day for what to check once the dashboards open.

The same URL becomes the administration surface once the connection is live. Admins reach it from an Admin section in the dashboard sidebar, whose tabs read Overview, Connection and People. The section is visible to admins only.

SurfacePathWhat you can do there
Overview and connection/setup/admin and /setup/admin/connectionRead the stored connection, rotate the client secret, edit the subscription list, re-check the credential, read the audit trail, end the connection
People/setup/admin/usersAdd and remove people, and set each to Admin or Viewer

Rotation validates the new secret before it replaces the old one. A failed check changes nothing. Create the new secret in Entra first, then paste it in, which gives you an overlap with no gap in the nightly run.

Azure client secrets expire. The portal default is six months and the maximum is twenty-four. This is the most common way a working connection stops working months later. Who is watching the date decides whether it surprises you.

Nothing reaches you. Put the reminder in your own calendar. The connection page shows the expiry date, and inside the last 30 days it adds a day count and an amber badge. Both appear only when an admin opens that page. No email, Teams message or alert is sent as the date approaches, and no scheduled job checks it.

That is why the wizard asks for the expiry date: it is what the page counts down from. If you skipped it, the page says it does not know when the secret expires and offers a field to fill it in.

If the secret does lapse, the nightly run stops collecting and the failure looks like any other authentication failure rather than announcing itself as an expiry. Dashboards keep showing the data already collected, so the symptom is cost figures that quietly stop moving. Rotating a new secret in restores collection from the next run.

The connection overview. Three tabs read Overview, Connection and People. A Connection card shows the tenant and client IDs, a credential line reading client secret, stored encrypted, then the expiry date, the last validation time and a Healthy badge. Below it, cards for rotating the client secret, editing the subscription list, seeing who has access, the audit trail, and ending the connection.

Captured from the setup service. Identifiers, dates and the account name are test values.

Three independent switches, all held by your team.

SwitchWhereWhat stops, and how fast
Delete the role assignmentsAzure portal, at the scope you granted themThe nightly run stops reading, after Azure RBAC propagation
Delete the infralign-reader app registrationEntra admin centerThe stored secret authenticates nothing from that moment
Remove a personthe People pageTheir access ends in about a second, including any session they have open

Nothing has to be revoked on Infralign’s side for the first two. The connection holds no write permission in your estate.

SymptomCauseFix
Sign-in lands on the “this account is not linked to a customer” screenThe address signed in with differs from the one Infralign enrolledCompare the two first. If they match, or the enrolled address is wrong, ask for it to be changed
The consent dialog says approval is needed on behalf of your organisationTenant policy blocks non-admin consentAsk a Global Administrator to open the same link
The sign-in check failsOne of the three values is wrong, or the pasted secret is the Secret ID rather than the ValueCheck all three against the portal. Re-running sends the same values and fails the same way
The sign-in check fails and every value matches the portalThe secret has expired. An expired secret authenticates nothing, and Entra returns the same refusal as a wrong oneOpen Certificates & secrets and read the Expires column. Create a new secret, then rotate it in on the connection page
Add role assignment is greyed out in the portal, so you cannot grant the roles at allYou hold app-registration rights but not Owner or User Access Administrator at that scopeNothing on your side unblocks this. Find whoever holds it, and send them the scope, the two roles, and the app name. What to send, and the Global Administrator fallback
A subscription’s Reader or Cost Management Reader check failsThe role is missing on that subscription, or is still propagatingAssign it, wait up to ten minutes, then re-run the failed checks
Discovery fails with “No subscriptions are visible to this app registration”infralign-reader holds Reader on no subscription, or the assignment has not propagatedAssign Reader at management group scope, wait up to ten minutes, and re-run
The wizard found fewer subscriptions than you expectedA subscription without Reader is invisible to discoveryAssign Reader, then re-run discovery from the Scope step
Validation returns AADSTS53003 or another AADSTS errorA workload-identity Conditional Access policy blocks the appScope the policy by named location using Infralign’s egress IPs, rather than excluding the identity. Email support@infralign.ai for the current IP list
Dashboards empty after the first runA subscription is missing one of its two role assignmentsRe-check Access control (IAM) → Role assignments, then re-check the connection

Some tenants need the exact portal click path recorded for change control, or a CLI transcript as evidence that the access works. Both are in manual connection, which also covers what to do when an admin cannot reach the wizard at all. It is the fallback, not the normal path.


Next: Manage who has access. Add and remove your own people, and set what each role can change.