Getting started
Connect Azure
Paste four values into a four-step wizard. Nothing is stored until the last step, and the first cost data lands the following night.
Validated against the Azure portal on 27 July 2026 and the setup wizard on 4 August 2026.
You connect Azure yourself, in a four-step wizard at app.infralign.ai. This page owns the wizard.
Everything after the prerequisites happens on screen: the wizard signs in as your app registration, runs read-only checks, lists the subscriptions it found, and stores the credential encrypted only after you confirm.
Access is read-only. The two built-in roles grant no write permission on any resource, and no storage account is needed on the default path.
How long this really takes
Section titled “How long this really takes”Book about 45 minutes at management group scope, of which roughly 25 minutes is hands-on.
| Part | Time |
|---|---|
| Entra portal work: app registration, secret, roles | About 12 minutes |
| Azure role propagation | A wait of up to 10 minutes |
| The consent answer, when somebody else approves it | Minutes to days. Send the request first |
| The wizard’s own four steps | About 6 minutes |
Per-subscription role assignment costs about a minute per subscription instead of six minutes once. The propagation wait and the consent wait run at the same time, so neither has to block the other.
Onboarding at a glance
Section titled “Onboarding at a glance”Figure 1 draws the whole path. It carries the product’s own two number sequences: three things in Entra first, then the wizard’s own four steps.
Before you open the wizard
Section titled “Before you open the wizard”Do the three Entra tasks first. They are one page, with a portal screenshot at every click: Entra app registration.
Come back here holding four values. The wizard asks for exactly these and nothing else:
| Value | Where it comes from |
|---|---|
| Directory (tenant) ID | The app registration’s Overview, in the Essentials panel |
| Application (client) ID | The same panel, two rows up. Not the Object ID |
| Client secret Value | Certificates & secrets, copied when Entra showed it once. Not the Secret ID |
| Secret expiry date | Shown beside the secret when you created it |
Two things also have to be true before the checks can pass. Both roles, Reader and Cost Management Reader, are assigned to infralign-reader at the scope you chose. And Azure has had up to ten minutes to propagate them, which is why an otherwise correct setup returns AuthorizationFailed on its first attempt.
Sign in with the exact address Infralign enrolled for you. A different work account, even your own on another tenant, lands on the “this account is not linked to a customer” screen instead.
The wizard is admin-only. Anyone else on your team reaches a status page until the connection is live and their dashboards open. It shows how far setup has got and nothing else: no credential, no identifiers, no controls.
By default the wizard refuses a credential from a different directory. Two cases need cross-tenant connections switched on: your Azure estate spans tenants, or you sign in from another tenant, such as a personal Microsoft account or a managed service provider. Ask Infralign to switch them on before you start.
Signing in
Section titled “Signing in”Open the link Infralign sent you, or go to app.infralign.ai. While setup is incomplete, every URL lands the admin on the wizard.
Admin consent should already be in place from the consent URL, which is the documented path. If it is not, the first sign-in from your tenant raises the same dialog. Everything it asks for is a sign-in permission. It grants no access to your subscriptions or your cost data: that access comes from the two role assignments above, which you control. The full list, and the four checks to make in the dialog, are on dashboard sign-in.
If you administer more than one Infralign account, a picker asks which one you are acting for before the wizard opens.
The four wizard steps
Section titled “The four wizard steps”Step 1. Connect
Section titled “Step 1. Connect”Paste four values: the Directory (tenant) ID, the Application (client) ID, the client secret Value, and the secret’s expiry date.
No credential is stored at this point. The secret and its expiry stay in the browser tab you are working in. They are never written to local storage, session storage, or a URL.
Infralign receives the secret twice. Step 2 uses it for the validation run and discards it without writing it. Step 4 stores it, and step 4 is the only step that does. Close or reload the tab before then and nothing is stored.
From step 4 the secret is encrypted before it is written, and held only as ciphertext. The encryption key is kept outside the database. Details: security and data handling.
The two identifiers you typed behave differently. Selecting Validate the connection saves the Directory (tenant) ID and the Application (client) ID as a draft connection, with an audit entry recording that you entered them. Neither is a credential, and both appear in your own audit trail on the connection page.
Done when you select Validate the connection and the Validate step opens.

Captured from the setup service on 4 August 2026, signed in as a test account. The “Simulated Azure mode” banner appears on development builds only. You will not see it.
If you close the tab before you finish
Section titled “If you close the tab before you finish”Nothing has to be deleted or restarted, and no support request is involved.
If you close the tab before selecting Validate the connection, nothing is written. You start from an empty form.
Close it after that, and reopening app.infralign.ai lands you back in the wizard with both ID fields filled in from the draft. The secret and its expiry date are not saved, because step 4 is the only step that stores a credential. Paste those two again and carry on.
Step 2. Validate
Section titled “Step 2. Validate”The wizard signs in as infralign-reader and runs read-only checks. Two apply to the account: one sign-in, and one subscription list. Three more run per subscription found: Reader, Cost Management Reader, and a one-day cost query.
It takes 30 to 60 seconds. Results stream in as each check settles, so a slow subscription does not hide the rest.
Nothing is written, in your tenant or in Infralign’s. A failed row explains itself and names the subscription. Fix the role assignment in the portal, then re-run the failed checks without re-entering anything.
Done when every check reports green, or the account checks are green and you have decided what to do about the subscriptions that failed.

Captured from the setup service. The subscriptions shown are test fixtures.
A subscription without the Reader role is invisible to discovery. It does not appear as a failed row, it does not appear at all. If you expected more subscriptions than the wizard found, assign the role and re-run discovery.
Step 3. Scope
Section titled “Step 3. Scope”Every discovered subscription is ticked. Untick any you want left out. A subscription whose checks failed starts unticked and can be added later from the connection page, so one missing role assignment does not block the rest of the estate.
Adding a subscription later
Section titled “Adding a subscription later”Adding one is deliberate, and takes about a minute:
- Open Admin → Connection.
- Select Re-check the connection. This runs the same discovery the wizard ran.
- Anything new appears in the subscription list, unticked, above a notice naming it.
- Tick it and select Save subscriptions. Collection starts on the next nightly run.
If the new subscription does not appear, infralign-reader has no Reader role on it. Assign the two roles and re-check. Or assign them at management group scope once, and every subscription created beneath it is discoverable from then on.
You cannot proceed with nothing ticked. If you untick everything and select the button, the step refuses inline with “Keep at least one subscription to continue.” Nothing is lost and nothing is stored; you are still on the same screen.
Zero subscriptions never reaches this step in the first place. Discovery is one of the account checks in step 2, and it fails there with “No subscriptions are visible to this app registration”, which means infralign-reader holds Reader on nothing. Assign it, at management group scope for preference, and re-run.
Done when the count above the list matches the subscriptions you want processed.

Captured from the setup service. The subscriptions shown are test fixtures.
Step 4. Confirm
Section titled “Step 4. Confirm”The last step lists everything about to be stored: both IDs, the credential type and its expiry, the subscriptions in scope, and any exclusion with the reason it was excluded. Read it, then select Finish setup.
This is the only irreversible step on the page. Everything before it can be abandoned by closing the tab. Finish setup writes the credential.
The same screen offers two optional extras you can skip: adding your team, and asking Infralign to connect a Teams webhook. Neither is needed for the first run. See manage who has access.
Done when the wizard replaces itself with a progress screen naming the ingestion window.

Captured from the setup service on 4 August 2026. The identifiers, subscription names and dates are seeded test fixtures. The “Simulated Azure mode” banner appears on development builds only.
After you finish
Section titled “After you finish”Two clocks run, and they are not the same clock.
The data lands on a timer. The first nightly run starts between 02:30 and 06:15 UTC, and the progress screen names the day your cost data is expected.
The dashboards are opened by a person. Infralign checks that first run, and once the run has landed your dashboards open within one business day. A person at support@infralign.ai emails you when they are live. Nothing automated sends that message, and the progress screen updates when they open.

Captured from the setup service. The customer, identifiers and dates are seeded test fixtures.
A wizard finished on a Thursday evening therefore puts your cost data in place overnight, and your dashboards in front of your team by Friday close at the latest. Finish on a Friday and the business day is Monday.
Read your first day for what to check once the dashboards open.
Administering the connection afterwards
Section titled “Administering the connection afterwards”The same URL becomes the administration surface once the connection is live. Admins reach it from an Admin section in the dashboard sidebar, whose tabs read Overview, Connection and People. The section is visible to admins only.
| Surface | Path | What you can do there |
|---|---|---|
| Overview and connection | /setup/admin and /setup/admin/connection | Read the stored connection, rotate the client secret, edit the subscription list, re-check the credential, read the audit trail, end the connection |
| People | /setup/admin/users | Add and remove people, and set each to Admin or Viewer |
Rotation validates the new secret before it replaces the old one. A failed check changes nothing. Create the new secret in Entra first, then paste it in, which gives you an overlap with no gap in the nightly run.
Before the secret expires
Section titled “Before the secret expires”Azure client secrets expire. The portal default is six months and the maximum is twenty-four. This is the most common way a working connection stops working months later. Who is watching the date decides whether it surprises you.
Nothing reaches you. Put the reminder in your own calendar. The connection page shows the expiry date, and inside the last 30 days it adds a day count and an amber badge. Both appear only when an admin opens that page. No email, Teams message or alert is sent as the date approaches, and no scheduled job checks it.
That is why the wizard asks for the expiry date: it is what the page counts down from. If you skipped it, the page says it does not know when the secret expires and offers a field to fill it in.
If the secret does lapse, the nightly run stops collecting and the failure looks like any other authentication failure rather than announcing itself as an expiry. Dashboards keep showing the data already collected, so the symptom is cost figures that quietly stop moving. Rotating a new secret in restores collection from the next run.

Captured from the setup service. Identifiers, dates and the account name are test values.
Revoking access
Section titled “Revoking access”Three independent switches, all held by your team.
| Switch | Where | What stops, and how fast |
|---|---|---|
| Delete the role assignments | Azure portal, at the scope you granted them | The nightly run stops reading, after Azure RBAC propagation |
Delete the infralign-reader app registration | Entra admin center | The stored secret authenticates nothing from that moment |
| Remove a person | the People page | Their access ends in about a second, including any session they have open |
Nothing has to be revoked on Infralign’s side for the first two. The connection holds no write permission in your estate.
Troubleshooting
Section titled “Troubleshooting”| Symptom | Cause | Fix |
|---|---|---|
| Sign-in lands on the “this account is not linked to a customer” screen | The address signed in with differs from the one Infralign enrolled | Compare the two first. If they match, or the enrolled address is wrong, ask for it to be changed |
| The consent dialog says approval is needed on behalf of your organisation | Tenant policy blocks non-admin consent | Ask a Global Administrator to open the same link |
| The sign-in check fails | One of the three values is wrong, or the pasted secret is the Secret ID rather than the Value | Check all three against the portal. Re-running sends the same values and fails the same way |
| The sign-in check fails and every value matches the portal | The secret has expired. An expired secret authenticates nothing, and Entra returns the same refusal as a wrong one | Open Certificates & secrets and read the Expires column. Create a new secret, then rotate it in on the connection page |
| Add role assignment is greyed out in the portal, so you cannot grant the roles at all | You hold app-registration rights but not Owner or User Access Administrator at that scope | Nothing on your side unblocks this. Find whoever holds it, and send them the scope, the two roles, and the app name. What to send, and the Global Administrator fallback |
| A subscription’s Reader or Cost Management Reader check fails | The role is missing on that subscription, or is still propagating | Assign it, wait up to ten minutes, then re-run the failed checks |
| Discovery fails with “No subscriptions are visible to this app registration” | infralign-reader holds Reader on no subscription, or the assignment has not propagated | Assign Reader at management group scope, wait up to ten minutes, and re-run |
| The wizard found fewer subscriptions than you expected | A subscription without Reader is invisible to discovery | Assign Reader, then re-run discovery from the Scope step |
Validation returns AADSTS53003 or another AADSTS error | A workload-identity Conditional Access policy blocks the app | Scope the policy by named location using Infralign’s egress IPs, rather than excluding the identity. Email support@infralign.ai for the current IP list |
| Dashboards empty after the first run | A subscription is missing one of its two role assignments | Re-check Access control (IAM) → Role assignments, then re-check the connection |
If you cannot use the wizard
Section titled “If you cannot use the wizard”Some tenants need the exact portal click path recorded for change control, or a CLI transcript as evidence that the access works. Both are in manual connection, which also covers what to do when an admin cannot reach the wizard at all. It is the fallback, not the normal path.
Next: Manage who has access. Add and remove your own people, and set what each role can change.