See below for creating a service principal.
If you wish to use DKE, you will need to create a separate registered application to provide access to the Azure Key Vaults. If you only wish to manage DKE keys, then the service principal does not need access to any Azure Key Vaults.
Creating and registering an Azure application
Create a service application in Azure and register it in Azure Active Directory using App Registrations.
Use New Registration to create the BYOK service application with the following parameters:
Parameter | Value |
|---|---|
name | Select a name, for example, |
account type | Select Accounts in this organizational directory only ( only - Single tenant). This option restricts access to users and services in the current Azure AD tenant. |
application type | Web |
Setting rotation permissions
Optionally, add the following permissions to allow auto rotation of client secrets.
This configuration is recommended for enhanced security and requires admin consent.
If your Azure license allows role assignments:
Navigate to Azure Active Directory > App Registrations > <mybyokapp> > Roles and Administrators.
Click the Cloud Application Administrator role.
Click Add Assignments.
Start typing the name of the BYOK service application in the search box, and check the checkbox for the corresponding Enterprise application.
Click Add.
If your Azure license does not allow role assignments:
Navigate to Azure Active Directory > App Registrations > <mybyokapp> > API Permissions.
Click Add a permission
Add the following permission:
Application.ReadWrite.All Type:ApplicationUse Grant Admin Consent for <directory name> to grant permissions.
You will need global administrator rights to grant these permissions.
Selecting the Azure application
To select the Azure application:
- Navigate to Azure > Subscriptions > <your subscription> > Access Control (IAM).
- In Role Assignments, select Role > Reader > Members.
- Select your application. for example, mybyokapp.
Reviewing services
Navigate to Azure > <directory name> > Enterprise Applications > mybyokapp > Permissions and check that the service principal, which has the same name as the BYOK application, has all required permissions.