Subscription administrators and MSP cloud operators
Connect an Azure subscription for lifecycle review
Set up an authorised read-only Azure application, map a subscription to a customer and understand sync evidence.
Published by Arctic Parade LTD · Updated 2026-09-17 · Sources and editorial process
Create an authorised application
For this first connector, use an application registration in the customer tenant. Record the tenant ID, application ID and a time-limited client secret. The customer administrator must authorise the application; entering a subscription ID alone grants no access. This manual service-principal setup is separate from sign-in SSO and is not an automatic tenant-consent wizard.
Give access only to the intended subscription
Assign the application a read-only Azure role at the subscription scope you are connecting. Reader is a practical initial role for generic resource listing and Advisor recommendation reads; it can read more Azure metadata than this connector needs. For stricter environments, have an administrator create and validate a custom role covering the specific resource read operations and Microsoft.Advisor/recommendations/read. Do not assign Contributor or Owner. The connector does not read workload secrets or change Azure resources.
Map the subscription to the right customer
Create the customer using an initial CSV import, then open Connections. Choose that customer and enter the tenant, subscription, application and secret value. The secret is encrypted at rest and not displayed again. The worker queues inventory and Advisor reads, and the connection page shows success, failure, record counts and the last successful check.
Understand what the evidence means
The connector lists Azure Resource Manager inventory and cached Advisor retirement recommendations. Provider coverage has limits. Exact catalogue feature/date matches can be upgraded to confirmed affected; unlinked observations remain in Advisor evidence. A successful empty recommendation list is not a complete all-clear. Subscription syncs are scheduled daily; failure retains the last successful inventory.
Disconnect and revoke
Disconnect stops future syncs and erases the locally stored secret. Historical inventory and evidence remain for review. The Azure administrator must also revoke the application role or credential in Azure. Credential expiry causes sync failure, which is visible on Connections; reconnect with a new time-limited credential after disconnecting the old connection.
Review remediation after a new sync
An observed recommendation reopens an action previously marked resolved or not applicable. A disappeared recommendation creates a review-required verification state, not automatic completion. Changes still need a recorded completion check, particularly when applications or client libraries cannot be assessed from generic resource inventory.
Sources and further reading
Related field guides
Put the process to work.
Explore the current Azure retirement catalogue, then try a small estate scan. Read the coverage limits before acting on a match.