# Connect Azure

> Coming soon, not available yet. Create a resource group and an app registration (service principal) with access to that resource group only, so Rowsafe can create database servers (virtual machines) there. The role, the custom role alternative, and how to revoke it.

Source: https://rowsafe.sh/docs/guides/cloud-accounts/azure

> **Coming soon: you can't connect Azure yet:** Rowsafe can't create servers in Azure yet: it has only been tested against a stand-in for Azure's API, not a real account, so the dashboard shows Azure as coming soon. This page describes how connecting it will work. Today, use [DigitalOcean](https://rowsafe.sh/docs/guides/cloud-accounts/digitalocean), [AWS](https://rowsafe.sh/docs/guides/cloud-accounts/aws) or [OVHcloud](https://rowsafe.sh/docs/guides/cloud-accounts/ovh), or [Rowsafe Cloud](https://rowsafe.sh/docs/guides/rowsafe-cloud).

To [create servers for you](https://rowsafe.sh/docs/guides/create-a-server) in Azure, Rowsafe needs an **app registration with access to one resource group**. You create both in the Azure portal and paste five values into the dashboard once. It takes about five minutes.

## Create the resource group and the app

### Create a resource group

In the [Azure portal](https://portal.azure.com), open **Resource groups** and click **Create**. Name it (for example `rowsafe`), pick a region and create it. Rowsafe will only work inside this resource group.

### Register the resource providers

Open **Subscriptions**, choose your subscription, then **Resource providers**. Make sure **Microsoft.Compute** and **Microsoft.Network** say **Registered** (select them and click **Register** if not).

### Register the app

Open **Microsoft Entra ID**, then **App registrations**, and click **New registration**. Name it `Rowsafe`, keep the defaults and click **Register**. Copy the **Application (client) ID** and the **Directory (tenant) ID** from its overview.

### Create a client secret

In the app, open **Certificates & secrets**, click **New client secret**, pick an expiry and click **Add**. Copy the secret's **Value** right away (not its ID): Azure shows it only once.

### Give the app the resource group, and only that

Go back to your resource group, open &#x2A;*Access control (IAM)**, click **Add**, **Add role assignment**. Choose **Contributor** (or the [custom role below](#what-access-this-gives-rowsafe)), click **Next**, select the `Rowsafe` app as the member, then **Review + assign**.

### Paste it into Rowsafe

On the resource group's **Overview** page, copy the **Subscription ID**. In the Rowsafe dashboard, open **Settings → Cloud accounts** (or **Create a server for me**), click **Connect a cloud account**, choose **Microsoft Azure**, paste the tenant ID, client ID, client secret, subscription ID and the resource group's name, give the account a name your team will recognize, and click **Connect**.

Rowsafe checks the credentials before it saves them: that they work, that the resource group exists, and that the app may do everything it needs there, without creating anything. If something is missing, it says what.

## What access this gives Rowsafe

**Contributor on one resource group** lets the app create, change and delete anything in that resource group, and nothing outside it. For less, create a custom role (in the subscription's &#x2A;*Access control (IAM)**, **Add**, **Add custom role**, **Start from JSON**) and assign it on the resource group instead of Contributor. Replace the two placeholders with your subscription ID and resource group:

```json
{
  "Actions": [
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Compute/virtualMachines/read",
    "Microsoft.Compute/virtualMachines/write",
    "Microsoft.Compute/virtualMachines/delete",
    "Microsoft.Compute/virtualMachines/start/action",
    "Microsoft.Compute/virtualMachines/deallocate/action",
    "Microsoft.Compute/virtualMachines/vmSizes/read",
    "Microsoft.Compute/disks/read",
    "Microsoft.Compute/disks/write",
    "Microsoft.Compute/disks/delete",
    "Microsoft.Network/virtualNetworks/read",
    "Microsoft.Network/virtualNetworks/write",
    "Microsoft.Network/virtualNetworks/subnets/read",
    "Microsoft.Network/virtualNetworks/subnets/write",
    "Microsoft.Network/virtualNetworks/subnets/join/action",
    "Microsoft.Network/networkSecurityGroups/read",
    "Microsoft.Network/networkSecurityGroups/write",
    "Microsoft.Network/networkSecurityGroups/delete",
    "Microsoft.Network/networkSecurityGroups/join/action",
    "Microsoft.Network/publicIPAddresses/read",
    "Microsoft.Network/publicIPAddresses/write",
    "Microsoft.Network/publicIPAddresses/delete",
    "Microsoft.Network/publicIPAddresses/join/action",
    "Microsoft.Network/networkInterfaces/read",
    "Microsoft.Network/networkInterfaces/write",
    "Microsoft.Network/networkInterfaces/delete",
    "Microsoft.Network/networkInterfaces/join/action",
    "Microsoft.Authorization/permissions/read"
  ],
  "AssignableScopes": [
    "/subscriptions/<subscription-id>/resourceGroups/<resource-group>"
  ],
  "Description": "Lets Rowsafe create, resize and delete database servers in one resource group.",
  "Name": "Rowsafe servers",
  "NotActions": []
}
```

Rowsafe itself creates, in that resource group and tagged `rowsafe=1`: for each server, a Debian 12 virtual machine with its disk, a network interface, a static public IP address and a network security group that lets in only the addresses you chose; and one virtual network per region, shared by your servers there. Your SSH keys go on the VM (for the user `rowsafe`) only if you give them, and Rowsafe never adds its own. Password logins are off. It creates them only when someone in your organization clicks and confirms. The credentials are stored encrypted, never shown again, and used only for those servers. See [what Rowsafe does with your cloud account](https://rowsafe.sh/docs/guides/create-a-server#what-rowsafe-does-with-your-cloud-account).

## Revoke it

- **In Azure:** in the app registration, **Certificates & secrets**, delete the secret. Or remove the role assignment on the resource group, or delete the app.
- **In Rowsafe:** **Settings → Cloud accounts**, **Remove**. Rowsafe forgets the credentials; nothing in your subscription changes. You can remove an account once its servers are deleted.

After you revoke it, or when the secret expires, your servers keep running and stay protected, but Rowsafe can no longer resize them, change their firewall or delete them. Do that in the Azure portal.

## Good to know

- Prices in the dashboard are "about": estimates from Azure's pay-as-you-go list prices in one region. Other regions differ, and your Azure bill is what counts.
- Deleting a server removes its VM, disk, network interface, public IP address and network security group. The region's virtual network stays, for your other servers; delete it in the portal if you no longer need it.
- Azure limits CPUs and public IP addresses per region. If you reach a limit, Rowsafe says so: ask for more under **Subscriptions**, **Usage + quotas**.
- An Azure Policy in your subscription can block what Rowsafe creates. Rowsafe says so; ask your Azure admin to allow it for the resource group.
