---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Add an Azure service account

# Add an Azure service account {#azure-service-account-cloud-mgt__title-azure-service-account}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

During Cloud Provisioning Day 1 setup, you added one service account
to the cloud account. To compartmentalize your infrastructure or to include different
datacenters, you can add another service account. A particular datacenter, however, cannot
be selected in more than one service account in a cloud account.

## Before you begin

Role required: sn_cmp.cloud_admin

## Procedure

1. Open the Azure-Credentials.txt text file that you created during the [Create a Microsoft Azure service principal](https://servicenow-prod.fluidtopics.net/3zMlRPTf3~gp0FlJ4z5P3Q "To securely access resource and billing data on your Microsoft Azure account, the Discovery process must present appropriate Microsoft Azure account credentials. You create a special programmatic account — a Microsoft Azure service principal — to generate the required credentials.") procedure.
2. Navigate to Cloud Admin PortalManageService Accounts.
3. Click New, enter a unique and meaningful Name, and then fill in the form.  
   {#azure-service-account-cloud-mgt__table_gs3_bdy_my__entry__2}

   | Field | Description |
   |-|-|
   | Account ID | The Azure Subscription ID value that you copied from the Azure Portal into the text file. See [Discovery for Microsoft Azure Cloud](https://servicenow-prod.fluidtopics.net/iMXKXsU7K2dnNRjDU4ObTg "If your cloud resources are in an Azure cloud, you must create a user identity called a service principal that grants permissions to the MID Server to access selected resources.") to learn Management Groups subscription IDs. |
   | Discovery credentials | Name of the credentials that you created in the [Store the Azure service principal credentials in the instance](https://servicenow-prod.fluidtopics.net/DvzfkOrfQSrS9kcVzwkzGA "To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery, you first create Azure service principal credentials in the Azure Portal. You then securely store the credentials in a service account in your instance.") procedure. In the example, you used the name <kbd class="ph userinput">Azure service principal credentials</kbd>. |
   | Datacenter URL | URL of the datacenter. This field is required only for the government and regional accounts. Discovery and Service Mapping Patterns supports the US, Germany, and China Microsoft Azure government clouds. |
   | Datacenter type | Select Azure Datacenter. |
   | Datacenter discovery status | Auto-generated value: Status and timestamp of the last execution of Discovery on the datacenter. |
   | Should pull events | Option to enable the ServiceNow AI Platform® to collect resource change information from the Microsoft Azure cloud. The ServiceNow AI Platform® uses the resource change information to update the Configuration Management Database (CMDB). For more information on the supported Azure resource types, see [Azure change processing](https://servicenow-prod.fluidtopics.net/48qJRqeZTZOuHhnAAtJDrA "The Azure change processing feature collects information about Microsoft Azure resources that have undergone a life-cycle state change or configuration change near real time. Then, it uses the collected information to update the Configuration Management Database (CMDB)."). If you select the Should pull events check box for a management group, the ServiceNow AI Platform enables Azure change processing for all the subscriptions in the management group. |
   [ ]

   {#azure-service-account-cloud-mgt__table_gs3_bdy_my}
4. Click Update or Submit.  
   The system creates the service account and displays the list of all discovered datacenters.

## What to do next

After you complete all procedures in this initial "Day 1" setup, you can create additional cloud accounts and service accounts to organize and compartmentalize your cloud infrastructure.  
Note:  
If you are on a domain separated instance, only those events that are updated to
the CMDB and belong to your domain are visible. Events create configuration
items (CI) in the same domain as the cloud service account they are mapped
to.
**Related concepts**   

* [Discovery for Microsoft Azure Cloud](https://servicenow-prod.fluidtopics.net/iMXKXsU7K2dnNRjDU4ObTg "If your cloud resources are in an Azure cloud, you must create a user identity called a service principal that grants permissions to the MID Server to access selected resources.")

*[\>]: and then


