---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Store the Azure service principal credentials in the instance

# Store the Azure service principal credentials in the instance {#azure-create-creds-cloud-mgt__title-azure-create-creds}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery, you first create Azure service principal credentials in the Azure Portal. You then securely store the credentials in a service account in your instance.

## Before you begin

Role required:

* Azure Portal Active Directory (AD) administrator
* Cloud Provisioning and Governance: admin or sn_cmp.cloud_admin, discovery_admin
{#azure-create-creds-cloud-mgt__ul_xnz_4wv_ndb}

## Procedure

1. [Create a Microsoft Azure service principal](https://servicenow-prod.fluidtopics.net/3zMlRPTf3~gp0FlJ4z5P3Q "To securely access resource and billing data on your Microsoft Azure account, the Discovery process must present appropriate Microsoft Azure account credentials. You create a special programmatic account — a Microsoft Azure service principal — to generate the required credentials.") and open the text file that you created during the procedure.
2. In the Cloud Admin Portal, navigate to ManageCredentials.
3. Click New and then select Azure Service Principal.
4. Specify the following values on the Azure Service Principal form:  
   {#azure-create-creds-cloud-mgt__table_m3f_bqm_wcb__entry__2}

   | Field | Value |
   |-|-|
   | Name | Name of the service principal to register with the instance. For example, <kbd class="ph userinput">Azure service principal credentials</kbd>. |
   | Authentication Method | Select Client Secret. The Secret key field appears when you select Client Secret. Note: Client Assertion is not supported. |
   [ ]

   {#azure-create-creds-cloud-mgt__table_m3f_bqm_wcb}
5. Copy/paste values from the Azure-Credentials.txt text file into the remaining fields.  
   {#azure-create-creds-cloud-mgt__service-principals-fields}
{#azure-create-creds-cloud-mgt__service-principals-fields}
6. Select the appropriate EA credential from the list, select the Active check box, and then click Save to create the record.
7. Click the Discover Subscriptions related link to find all subscriptions that are associated with the Azure service principal.  
   The instance creates a service account for each discovered subscription.The Azure Subscriptions related list displays all subscriptions that are associated with the Azure service principal.
8. Click a subscription to view the service account that was created for the subscription.
9. Click a discovery status entry in the Credential Discovery Status list to view the associated discovery log.  
   Each time that you click Discover Subscriptions, the instance generates a new discovery status and lists the status in the Credential Discovery Status list.

*[\>]: and then


