# Connect an Azure provider link

Connect an Azure account to Northflank through a provider link. Choose the supported features for your task before granting Azure permissions.

Connecting the account does not create a cluster. For registry access, select the relevant registry features. Cluster permissions and quotas apply when you also deploy clusters.

Review [provider-link features](provider-links) for availability. For cluster deployment, use [Microsoft Azure on Northflank](https://northflank.com/docs/v1/application/bring-your-own-cloud/azure-on-northflank).

## Add your Azure account

Create a Microsoft Entra ID application to connect your Azure subscription to Northflank.

> [!note] Requirements
>
> You will need the following to get started:
>
> - Permission to register applications and create client secrets in Microsoft Entra ID
> - Permission to assign roles on the subscription, such as Owner or User Access Administrator
> - For cluster deployment: sufficient [quotas](https://northflank.com/docs/v1/application/bring-your-own-cloud/azure-on-northflank#check-your-quotas) to deploy your cluster

If your tenant restricts application registration, Application Administrator or Cloud Application Administrator can provide the required application permissions.

### Start the integration in Northflank

1. Open Cloud → Provider links in Northflank.

2. Open the [Azure provider link form](https://app.northflank.com/s/account/cloud/integrations/new/azure).

3. Under Basic information, enter a Name.

4. Select the features you need under Desired features.

For registry access, select Docker Registries and, for project builds, Docker Registry Push. Select BYOC only if this integration also manages clusters.

### Register an application in Entra ID

Copy each requested value into Credentials in Northflank as you complete these steps.

1. Open Microsoft Entra ID in the [Azure portal](https://portal.azure.com/).

2. Open App registrations and [register a new application](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app).

3. Copy the directory (tenant) ID and application (client) ID into Northflank.

4. Open the link for Managed application in local directory.

5. Copy the object ID from that application's properties into Northflank.

6. Return to the application registration and open Certificates & secrets.

7. Create a client secret and copy its value into Northflank.

Use the secret value, rather than its ID.

### Grant the application access to your subscription

The Northflank Azure integration requires the Contributor role on the connected subscription, including for registry use. Registry pull and push roles alone do not replace this integration requirement.

1. Open Subscriptions in Azure and select the subscription to connect.

2. Open Access control (IAM) and add a role assignment.

3. Select the [Contributor role](https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/privileged#contributor).

4. Under Members, select User, group, or service principal.

5. Select your application's service principal and save the assignment.

6. For cluster deployment, open Resource providers and register `Microsoft.ContainerService`.

7. Copy the subscription ID into Subscription ID under Credentials in Northflank.

8. Select Create provider link.

For registry use, connect an existing Azure Container Registry in this subscription. The registry uses the `Microsoft.ContainerRegistry` resource provider. See [Azure resource provider registration](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/resource-providers-and-types) if Azure reports a registration error.

For cluster deployment, continue to [quotas](https://northflank.com/docs/v1/application/bring-your-own-cloud/azure-on-northflank#check-your-quotas) and [cluster creation](https://northflank.com/docs/v1/application/bring-your-own-cloud/azure-on-northflank#create-a-cluster).

You can update the integration's credentials when required.

> [!warning] Keep access to existing resources
>
> Keep access to existing resources when you replace credentials. Without that access, Northflank cannot manage those resources, and deleting clusters directly in Azure can leave unused resources.

