---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Run Azure Cloud Discovery using Service Principal with SSH Certificates

# Run Azure Cloud Discovery using Service Principal with SSH Certificates {#ariaid-title1}

* Release version: Yokohama
* 
* Updated December 16, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Discover Linux virtual machines on Azure using Service Principal (SP) with short-lived SSH certificates. Using these certificates circumvents the need for passwords or public and private key-pairs.

## Before you begin

Before creating a Cloud Discovery credentials, Service Principles must be set up on the Azure Portal. See the [Microsoft Azure](https://learn.microsoft.com/en-us/azure/?product=popular) documentation site for more information. After creating a Linux VM with Azure AD login enabled, be sure to verify the requirements for login with Azure AD using OpenSSH
certificate-based authentication for Linux VMs. Configure suitable role assignments for the Service Principle and Resource Group.

Before creating credentials, the External Credential Storage plugin is required to connect Azure VM using OpenSSH certificates.

Role required: admin

## Procedure

1. On the instance, navigate to DiscoveryCredentials and select New.
2. For the type of credential, select Azure Service Principal.
3. Fill in the form with the required info and submit.  
4. Navigate to DiscoveryCredentials and select New.
5. For this type of credential, select Azure SSH Certificate Credential.
6. Fill in the form with the necessary information, including linking the Service Principle credential you created.  
   The Azure Service Provider and SSH Certificate credentials have been created and linked. Continue the procedure to create the Cloud Discovery schedule.
7. Navigate to the Cloud Discovery Workspace home page and select Cloud discovery.  
8. Select New discovery schedule.
9. Provide a name for the schedule and select Azure as the cloud provider.
10. Create a new cloud account using your Azure Service Principal credential.  
    For more information, see [Set up Azure service accounts](https://servicenow-prod.fluidtopics.net/wA59_lRoV_0PzpuODHnNjA "Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Microsoft Azure accounts.").
11. Select data centers.
12. Enable the option to discover virtual machines.
13. Complete the schedule creation by selecting Finish and run.

## Result

The discovery schedule should start, and the Cloud Operations homepage should show the running status for the newly created schedule. After some time, the scheduled discovery should be completed and a new schedule for the VM
discovery is then created and run. The new VM discovery schedule utilizes the SP we created for the generation of SSH certs to authenticate with the VMs. You can observe this in the Discovery IP Affinity section for the
credential.

*[\>]: and then


