mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 11:27:32 +00:00
docs: azure app connection certificate auth
This commit is contained in:
Binary file not shown.
|
After Width: | Height: | Size: 135 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 173 KiB |
@@ -66,29 +66,72 @@ Infisical currently only supports two methods for connecting to Azure, which are
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Client Secret Authentication">
|
|
||||||
Ensure your Azure application has the required permissions that Infisical needs for the Azure Client Secrets connection to work.
|
|
||||||
|
|
||||||
**Prerequisites:**
|
<AccordionGroup>
|
||||||
- An active Azure setup.
|
|
||||||
|
|
||||||
<Steps>
|
<Accordion title="Client Secret Authentication">
|
||||||
<Step title="Assign API permissions to the application">
|
Ensure your Azure application has the required permissions that Infisical needs for the Azure Client Secrets connection to work.
|
||||||
For the Azure Client Secrets connection to work, assign the following permissions to your Azure application:
|
|
||||||
|
**Prerequisites:**
|
||||||
|
- An active Azure setup.
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Assign API permissions to the application">
|
||||||
|
For the Azure Client Secrets connection to work, assign the following permissions to your Azure application:
|
||||||
|
|
||||||
|
#### Required API Permissions
|
||||||
|
|
||||||
|
**Microsoft Graph**
|
||||||
|
- `Application.ReadWrite.All`
|
||||||
|
- `Application.ReadWrite.OwnedBy`
|
||||||
|
- `Application.ReadWrite.All` (Delegated)
|
||||||
|
- `Directory.ReadWrite.All` (Delegated)
|
||||||
|
- `User.Read` (Delegated)
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Accordion>
|
||||||
|
<Accordion title="Certificate Authentication">
|
||||||
|
Ensure your Azure application has the required permissions that Infisical needs for the Azure Client Secrets connection to work.
|
||||||
|
|
||||||
|
**Prerequisites:**
|
||||||
|
- An active Azure setup.
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Assign API permissions to the application">
|
||||||
|
For the Azure Client Secrets connection to work, assign the following permissions to your Azure application:
|
||||||
|
|
||||||
|
#### Required API Permissions
|
||||||
|
|
||||||
|
**Microsoft Graph**
|
||||||
|
- `Application.ReadWrite.All`
|
||||||
|
- `Application.ReadWrite.OwnedBy`
|
||||||
|
- `Application.ReadWrite.All` (Delegated)
|
||||||
|
- `Directory.ReadWrite.All` (Delegated)
|
||||||
|
- `User.Read` (Delegated)
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
|
||||||
|
<Step title="Upload your certificate to your Azure App Registration">
|
||||||
|
Navigate to the **Certificates & secrets** section of your Azure App Registration, and press the **Upload certificate** button.
|
||||||
|
|
||||||
|
Select the **Upload** button and upload your certificate.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
Keep in mind that you'll need the both the certificate & private key in order to configure the Azure Client Secrets connection within Infisical.
|
||||||
|
</Tip>
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
</AccordionGroup>
|
||||||
|
|
||||||
#### Required API Permissions
|
|
||||||
|
|
||||||
**Microsoft Graph**
|
|
||||||
- `Application.ReadWrite.All`
|
|
||||||
- `Application.ReadWrite.OwnedBy`
|
|
||||||
- `Application.ReadWrite.All` (Delegated)
|
|
||||||
- `Directory.ReadWrite.All` (Delegated)
|
|
||||||
- `User.Read` (Delegated)
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
</Steps>
|
|
||||||
</Accordion>
|
|
||||||
|
|
||||||
## Setup Azure Connection in Infisical
|
## Setup Azure Connection in Infisical
|
||||||
|
|
||||||
@@ -123,6 +166,17 @@ Infisical currently only supports two methods for connecting to Azure, which are
|
|||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
</Tab>
|
</Tab>
|
||||||
|
<Tab title="Certificate">
|
||||||
|
<Step title="Create Connection">
|
||||||
|
Fill in the **Tenant ID**, **Client ID**, **Certificate**, and **Private Key** fields with the Directory (Tenant) ID, Application (Client) ID, Certificate and Private Key you obtained in the [previous step](#certificate-authentication).
|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
The private key is never transmitted to Azure, and it is only used to sign the client assertion used to authenticate with Azure.
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Tab>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Connection Created">
|
<Step title="Connection Created">
|
||||||
|
|||||||
Reference in New Issue
Block a user