All pages
Powered by GitBook
1 of 9

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Azure onboarding

Add an Azure MCA account

The Client Portal supports both legacy Enterprise Agreement and modern Microsoft Customer Agreement models. This topic describes how to add an Azure MCA account to the Client Portal. For information on adding an EA or MPSA account, see Activating an Azure EA or MPSA account.

Before you begin

Before adding an MCA account to the Client Portal, make sure your account has the correct billing account type set up. You can verify the account type in the Azure Portal.

To verify, select Cost Management + Billing and then navigate to Settings > Properties. The account type is displayed in the right pane.

Assigning the Billing Account Reader role (Azure Portal)

To assign the Billing account reader role to the Client Portal through Azure:

  1. In the Azure Portal, search for Cost Management + Billing.

  2. In the left navigation pane, select Billing scopes and then select your MCA billing scope.

  1. Select Access Control (IAM) to start assigning permissions.

  1. On the Access Control (IAM) tab, select Add > Add role assignment. The Add role assignment pane opens. From the Role list, select the Billing account reader role.

  1. For Members, select SoftwareOne Cloud Consumption (formerly PyraCloud Azure) application to give access to the Client Portal.

  1. SelectSave. Your MCA billing data will be synchronized with the Client Portal after 24 hours.

After assigning permissions to the billing account, you can add the tenant to the Client Portal via Cloud tenant setup, found under Cloud tools in the main menu.

For instructions on how to add the tenant, see .

Activate an Azure EA or MPSA account

This topic describes how you can activate an Azure EA or MPSA account.

Before you begin

Before adding an account, make sure that you have the following details:

  • Account Information - You must have the tenant ID or domain name of the tenant that contains your Azure or Office 365 subscriptions. The tenant ID and domain name are available in your Azure account. For information on how to find these details, see Find IDs and domain names in the Microsoft documentation.

  • Permissions - You must have sufficient permissions to complete the onboarding process. The setup will fail if the permissions are not configured in the Microsoft Azure Portal.

    • For an Azure account, you must have owner permission for the subscription you want to add.

    • For an Office 365 account, you must be a Global Administrator of the tenant that contains the subscriptions.

To add a new cloud account to the Client Portal:

  1. On the page, select Add Cloud Account.

  2. On the Add Cloud Account page, click Azure and provide the following details:

    1. Friendly Name - Provide a name for your Microsoft tenant.

  1. On the consent page, review the permissions required by the Client Portal and click Accept to grant consent.

After clicking Accept, you'll be redirected to the Cloud Tenant Setup details page to view the new tenant and its activation progress. After activating your tenant, you can add subscriptions and allow the Client Portal to write tags back to your Azure resources.

When you return to the Client Portal, you might see a blank page for a few seconds. To learn about the process that takes place after you provide consent, see

Many organizations have several Azure subscriptions in a single Microsoft tenant. In some cases, it's not always the same person who has Owner permissions on all those subscriptions. In such cases, each subscription owner must activate their subscriptions.

Follow these steps to add more subscriptions:

  1. On the Cloud Tenant Setup page, select Manage.

  2. Select Add Existing Subscriptions to add more subscriptions.

  3. In Add New Subscription, choose the type of subscription and select Add.

When you activate your Azure subscriptions for the first time, the Client Portal assigns the Reader role by default. This means that the Tags and Resources feature can import your resources and tags from Azure, but it cannot synchronize any tag changes you make in the Client Portal back to Azure.

For Tags and Resources to synchronize tags back to Azure, you must change the level of access the Client Portal has for your Azure subscription.

To change the level of access:

  1. On the Cloud Tenant Setup page, select Manage.

  2. Select Change Access for the subscription you want to modify.

  3. Select one of the following access levels and click Change:

Microsoft Tenant ID or Tenant Domain - Provide the tenant ID or domain.

  • License Model - Select the license model (Enterprise Agreement or Microsoft Customer Agreement).

  • Enrollment Number - Provide the enrollment number. Note that this field is displayed only if you select Enterprise Agreement as your license model.

  • Select Add Cloud Account.

  • Sign in to the Microsoft portal using the credentials of a user who has Owner permissions to the Azure subscriptions you want to add.

  • If you select Azure, the user performing consent must be the Owner of the Azure subscriptions being added.
  • If you select Office 365, the user performing the consent must be a Global Administrator of the tenant.

  • Sign in to the Microsoft portal using the credentials of the user with Owner permissions to the Azure subscriptions you want to add.

  • On the consent page, review the permissions and select Accept to grant consent. After granting consent, you'll be redirected to the Client Portal.

  • Sync resources only, no tags – write back of tags disabled - Tags and Resources will download your resources to the Client Portal without the tags currently assigned in Azure. Any changes to tags will be stored in the Client Portal only. This setting requires the “Reader” role in your Azure subscription and will not make any changes to resources or tags in your Azure subscription.
  • Sync resources and tags – write back of tags disabled - Tags and Resources will download your resources, including the tags currently assigned in Azure. Any changes to tags will be stored in the Client Portal only. Any tags assigned to resources in Azure will overwrite the tags for the corresponding resource in the Client Portal. This setting requires the Reader role in your Azure subscription and will not make any changes to resources or tags in your Azure subscription.

  • Sync resources and tags – write back of tags enabled - Tags and Resources will download your resources to the Client Portal, including the tags currently assigned in Azure. Any changes to tags will be synchronized back to your resources in Azure. This setting requires the “Tag Contributor” role in your Azure subscription and will only make changes to tags.

  • Sign in to the Microsoft portal using the credentials of the user with Owner permissions to the Azure subscriptions for which you wish to modify the access level.

  • On the consent page, review the permissions and select Accept to grant consent. After granting consent, you'll be redirected to the Client Portal to view the updated access level. If you notice a blank screen, refresh the page.

  • Activate your cloud account

    If you wish to add more Azure subscriptions owned by other users, you can do this later. For instructions, see .

    Add more Azure subscriptions

    Sync your tags to Azure

    Cloud tenant setup
    What happens after I grant consent.

    Next steps

    Activate your cloud account
    Billing scopes
    Access Control (IAM)
    Add role assignment
    Select members
    Add more Azure Subscriptions

    Integrate your Microsoft tenant manually

    This topic describes how to manually integrate your Azure tenant and assign the Reader and Tag Contributor roles to the Client Portal using Azure Management Groups.

    Integrating a Microsoft tenant involves the following steps:

    1. Granting consent to the Client Portal in your Azure tenant.

    2. Assigning the Tag Contributor and Reader access roles to the Client Portal using Azure Management Groups. The Tag Contributor and Reader roles allow the Client Portal to read a list of all the resources in your Azure subscription and read and write tags on those resources. You can control whether you want the Client Portal to write tags back to resources in your Azure subscription. For more information, see .

    3. Providing the details to SoftwareOne to complete your onboarding.

    To grant consent through your Azure tenant:

    1. Select one of the following links:

    To assign the Tag Contributor and Reader access roles:

    1. Launch the and search for Management groups.

    2. On the Management groups page, select Start using management groups.

    3. Provide the Group ID and a display name for your group. Select Submit. The new group is created and displayed under the Tenant Root Group.

    After completing the integration steps, provide the following details so we can complete the onboarding of your tenant:

    • Your Microsoft Tenant ID (or domain).

    • A friendly name for your tenant to recognize easily across the Client Portal.

    • The start and end date of your Enterprise Agreement.

    After we have added your tenant, you'll need to provide an access token from the EA Portal.

    On the
    Permissions Requested
    page, review the permissions, and select
    Accept
    .
  • After granting consent, launch the Azure Portal and navigate to Azure Active Directory > Enterprise applications to make sure that SoftwareOne Cloud Consumption (formerly PyraCloud) is listed in your enterprise applications.

  • Select the newly created management group and then from the left sidebar, select Access Control (IAM).
  • Navigate to Role assignments and select Add > Add role assignment from the dropdown.

  • Assign the Reader role to the Client Portal:

    1. Choose Reader from the list of roles and select Next.

    2. On the Members tab, click Select Members.

    3. Search for SoftwareOne Cloud Consumption (formerly PyraCloud Azure for Azure or PyraCloud Office 365 for Office 365) and then select it from the search results. Click Save.

  • Assign the Tag Contributor role to the Client Portal:

    1. Choose Tag Contributor from the list of roles. Select Next.

    2. On the Members tab, click Select Members.

    3. Search for SoftwareOne Cloud Consumption (formerly PyraCloud Azure for Azure or PyraCloud Office 365 for Office 365) and then select it from the search results. Click Save.

  • Select Review + assign and then Review + assign again. The new roles are displayed on the page.

  • Granting consent through your Azure tenant

    Assigning the Tag Contributor and Reader access roles

    Providing the details to SoftwareOne

    Removing the Azure role assignment

    The Reader role is mandatory for all consumption modules including Reporting, Budgeting, Resources, and Tag Management.

    The Tag Contributor role is required for the Client Portal to write back resource tagging information to the publisher (Azure). It is recommended to grant such a role to have consistent resource tag representation between Azure and the Client Portal. However, the Tag Contributor role can be revoked and the Client Portal will use Virtual Tags that will be visible only in the module.

    However, the Tag Contributor role can be revoked and the Client Portal will use Virtual Tags that will be visible only in the module.

    To remove the Tag Contributor role

    1. Go to the scope where the role was granted (Subscription, Management Groups, or Root Management Group).

    2. From the left sidebar, select Access control (IAM) and go to the Role assignments tab.

    3. Choose the role that you want to remove and select Remove.

    4. Select Yes to confirm the role removal.

    Syncing your tags to Azure
    Azure
    Office365
    Azure Portal

    Assign Reader and Tag Contributor roles (multiple subscriptions)

    You can use Azure Management Groups to grant the Client Portal access to your Azure subscriptions. This approach has the following benefits:

    • You can assign access to multiple subscriptions in a single step.

    • If you create more Azure subscriptions in the future, access will be automatically granted. It means that when you add an Azure subscription to your tenant, activating it in the Client Portal is unnecessary.

    When you onboard your tenant to the Client Portal, an Enterprise Application called SoftwareOne Cloud Consumption (formerly PyraCloud) is created in your tenant. You must then assign the Tag Contributor and Reader roles to the "PyraCloud (Azure)" Enterprise Application:

    These roles allow the Client Portal to read a list of all the resources in your Azure subscriptions and read and write tags on those resources. You can choose whether you want the Client Portal to write tags back to resources in your Azure subscription using the Cloud Tenant Setup feature.

    Use the following commands to onboard your Azure subscriptions:

    The following table explains these commands:

    Command
    Description

    Before granting access through the Azure Portal, note the following points:

    • Ensure that you have .

    • Ensure that you have the correct permissions to manage access to all Azure subscriptions and management groups in your tenant. For instructions, see in the Microsoft documentation.

    1
    1. Launch the and search for Management groups.

    2. On the Management groups page, select Tenant Root Group. Note that regardless of your organization's configuration, you'll always have a Tenant Root Group. It might have been renamed, but it always appears at the top of the hierarchy.

    2

    Create the PyraCloud (Azure) service principal (Enterprise Application) in your tenant.

    $root_mg=$(az account management-group list --query "[?displayName == 'Tenant Root Group'] | [0] | id" --output tsv)

    Get the ID of your Tenant Root Group.

    az role assignment create --assignee "2a4807a4-d9e4-457d-b32f-a455e0d3662a" --role "Reader" --scope "$root_mg"

    az role assignment create --assignee "2a4807a4-d9e4-457d-b32f-a455e0d3662a" --role "Tag Contributor" --scope "$root_mg"

    Assign the Reader and Tag Contributor roles to the PyraCloud (Azure) application in your Tenant Root Group.

    Open the Add role assignment page

    1. From the left sidebar, select Access control (IAM).

    Access control (IAM)
    1. Select Add > Add role assignment. The Add role assignment page opens.

    Add role assignment
    3

    Assign the Reader role

    1. On the Role tab, select Reader as the role and then select Next.

    Reader role
    1. On the Members tab, select User, group, or service principal if it's not selected by default. Then, choose Select members.

    Select Members
    1. In the Select members panel, search for SoftwareOne Cloud Consumption (formerly PyraCloud Azure).

    2. Use Select to add the enterprise application to the Members list. After the app has been added, select Review + assign.

    3. On the Review + assign tab, review the details and select Review + assign to confirm the role assignment.

    4

    Assign the Tag Contributor role

    To assign the Tag Contributor role, follow all the steps in Step 3: Assign the Reader role, but choose Tag Contributor as your role instead of Reader.

    After completing the steps, the roles are assigned and displayed on the Role assignments tab.

    Role assignment
    az login
    
    az rest --method post --url "/providers/Microsoft.Authorization/elevateAccess?api-version=2016-07-01"
    
    az ad sp create --id 2a4807a4-d9e4-457d-b32f-a455e0d3662a
    
    az ad app permission grant --id 2a4807a4-d9e4-457d-b32f-a455e0d3662a --api 00000003-0000-0000-c000-000000000000 --scope "User.Read"
    
    $root_mg=$(az account management-group list --query "[?displayName == 'Tenant Root Group'] | [0] | id" --output tsv)
    
    az role assignment create --assignee "2a4807a4-d9e4-457d-b32f-a455e0d3662a" --role "Reader" --scope "$root_mg"
    
    az role assignment create --assignee "2a4807a4-d9e4-457d-b32f-a455e0d3662a" --role "Tag Contributor" --scope "$root_mg"

    az login

    Log in to your Microsoft tenant.

    az rest --method post --url "/providers/Microsoft.Authorization/elevateAccess?api-version=2016-07-01"

    Elevate your permissions to manage all Azure subscriptions and management groups. See Microsoft Documentation.

    Granting access using Azure CLI

    Before granting access using Azure CLI, note the following points:

    • Ensure that you've installed PowerShell and Azure CLI. For installation instructions, see Install PowerShell and Install Azure CLI.

    • The script utilizes PowerShell variables; therefore, you must execute this script at a PowerShell prompt instead of a normal command prompt.

    Granting access using the Azure Portal

    Search for Management Groups

    onboarded your tenant
    Elevate access to manage all Azure subscriptions and management groups
    Azure Portal
    Tenant Root Group

    az ad sp create --id 2a4807a4-d9e4-457d-b32f-a455e0d3662a

    az ad app permission grant --id 2a4807a4-d9e4-457d-b32f-a455e0d3662a --api 00000003-0000-0000-c000-000000000000 --scope "User.Read"

    Migrate to Azure Cost Management APIs

    Microsoft will retire the legacy Azure Enterprise Reporting APIs on 1 May 2024. Currently, the Client Portal uses these APIs to get your Azure EA consumption data.

    If you have an Azure Enterprise Agreement (EA), you must migrate to the new Azure Cost Management APIs to maintain your cost and usage data in the Client Portal.

    Before you begin

    Before migrating to the new Cost Management APIs, note the following points:

    • The new APIs don't require access tokens because the authorization is done through Microsoft Entra ID (also known as Azure Active Directory) using service principals.

    • Only individuals with the Azure EA Enterprise Administrator role permission can carry out the migration steps. If you have trouble finding out who is your EA admin in Azure, see Microsoft's documentation on .

    • During the consent flow, the SoftwareOne Cloud Consumption app is added to the organization tenant. This enterprise application is granted the EA Reader permission, which allows us to read the consumption data. To add the application to the tenant, you'll need permission to approve an Enterprise Application.

    • If your EA admin doesn't have access to the Client Portal, you can collaborate with them by sharing your screen, so your EA admin can sign in and complete the authorization required for migration.

    • During migration, our system automatically assigns the to the service principal.

    If you've already onboarded your EA cloud account to the Client Portal and have appropriate permissions to approve Enterprise Applications, follow these steps to transition to the new API:

    1. Open the page. EA cloud accounts that haven't been migrated will display EA API migration required in the Status column.

    1. Select Migrate EA API.

    2. In the Migrate to EA API window, enter the enrollment number and select Migrate.

    1. Sign in to the Microsoft portal using the credentials of a user with Enterprise administrator permission.

    2. On the consent page, review the permissions required by the Client Portal and select Accept to grant consent.

    You'll be redirected to the Cloud Tenant Setup details page.

    The system will mark the enrollment number you provided as migrated, and automatically assign the Enrollment reader permission to the SoftwareOne Cloud Consumption (formerly PyraCloud Azure) application. When the migration has been completed, the consumption data is fetched from Microsoft.

    If you can't provide consent to approve enterprise applications or have environment restrictions, you can follow these steps to migrate and assign permissions manually:

    1. On the page, locate the required EA cloud account with the status EA API Migration required.

    1. In the Actions column, select Migrate EA API.

    2. In the Migrate to EA API window, enter the enrollment number, then select Migrate without consent.

    1. On the details page of the tenant, select the Enrollment Numbers tab and select Show manual steps.

    2. In Manual steps, assign permissions using Cloud Shell or REST API and select Close. Note that you must have the Azure EA Enterprise Administrator role to assign permissions.

    The Enrollment Numbers tab on the details page of the cloud tenant displays the enrollment numbers that are migrated to the new API, along with the respective enrollment status:

    • Connected - Indicates that the system is connected and working as expected.

    • Cannot connect - Indicates that the Client Portal doesn't have access to the new Azure Cost Management API and the EnrollmentReader permission is missing. You can assign permissions using the Azure Cost Management API or Azure Cloud Shell.

    • Activation required - Indicates that the Client Portal can access the enrollment data, but the cloud account has not been set up as an EA account type.

    If you're adding a new EA cloud account to the Client Portal, you'll need to provide the enrollment number while adding the account. For information on how to add a new EA account, see .

    Complete your Microsoft 365 or Azure activation

    If you purchased SoftwareOne's Digital Workplace Essentials/365Simple, and Azure Essentials/ AzureSimple services, you must activate your cloud account in the Marketplace Platform.

    Cloud accounts that require activation are displayed on the Cloud tenant setup page and have the Activation Required status and links to activate Microsoft 365 and Microsoft Azure, depending on the service you purchased.

    This topic describes how you can access the Cloud tenant setup page and complete the activation.

    Activate Microsoft 365

    To activate Microsoft 365:

    1. Navigate to the Cloud tenant setup using one of the following steps:

      • Select this link: .

      • Sign in to the platform. Next, select the main navigation menu and go to Cloud tools > Cloud tenant setup.

    2. On the Cloud tenant setup page, locate the account that needs activation. The status will be Activation Required.

    3. In the Actions column, select Activate Microsoft 365.

    1. On the Microsoft sign-in page, enter your username and password. Note that you must provide your Global Administrator credentials.

    2. Review the permissions and select Accept to grant consent.

    To activate Microsoft Azure:

    1. Navigate to the Cloud tenant setup using one of the following steps:

      • Select this link: .

      • Sign in to the platform. Next, open the main menu and go to Cloud tools > Cloud tenant setup.

    1. On the Microsoft sign-in page, enter your username and password. Note that you must have the Owner or User Access Administrator role for the account to activate.

    2. Review permissions and click Accept to grant consent.

    On successful validation of your credentials, your account is activated, and the Cloud tenant setup page displays the activation status as Connected.

    On the
    Cloud tenant setup
    page, locate the account that needs activation. The status will be
    Activation Required
    .
  • In the Actions column, select Activate Microsoft Azure.

  • Activate Microsoft Azure

    Cloud tenant setup
    Cloud tenant setup
    Cloud tenant setup page
    Cloud tenant setup page

    Migrating your existing EA cloud account

    Migration did not complete successfully?

    If the migration fails despite following these steps, you can use the fallback option to complete the process.

    To do so, go to the Enrollment Numbers tab of the tenant and click Show manual steps in the Actions column. When the Manual steps dialog opens, execute the commands and then click Close.

    If you are still unable to migrate, contact your support team.

    Migrating without consent

    Enrollment statuses

    Adding a new EA cloud account

    EA Billing administration on the Azure portal
    EnrollmentReader role permission
    Cloud Tenant Setup
    Cloud Tenant Setup
    Activate your cloud account
    Status column displays EA API migration required
    Migrate option
    Permissions and consent
    EA API migration required
    Migrate without consent
    Enrollment Numbers tab

    Assign Reader and Tag Contributor roles (single subscription)

    In some cases, you must configure your Azure subscription manually so that the Client Portal can access the resources and tags.

    When you onboard your tenant to the Client Portal, an Enterprise Application called SoftwareOne Cloud Consumption (formerly PyraCloud Azure) is created in your tenant. You must then assign the Tag Contributor and Reader roles to the PyraCloud (Azure) Enterprise Application.

    These roles allow the Client Portal to read a list of all the resources in your Azure subscriptio, and read and write tags on those resources. You can control whether you want the Client Portal to write tags back to resources in your Azure subscription using the Cloud Tenant Setup feature.

    Grant access to individual subscriptions

    Before granting access, ensure that you've .

    To grant access to individual subscriptions:

    1. In the Azure Portal, search for Subscriptions.

    2. On the Subscriptions page, choose the subscription you want to integrate with the Client Portal.

    1. Select Access control (IAM).

    1. Select the Role assignments tab.

    1. Select Add > Add role assignment.

    1. Select Reader from the Role menu. Then, search for SoftwareOne Cloud Consumption (formerly PyraCloud Azure) and select it from the search results. Click Save.

    1. Select Tag Contributor from the Role menu. Then, search for SoftwareOne Cloud Consumption (formerly PyraCloud Azure) and select it from the search results. Click Save.

    Access is granted.

    Assign Azure Subscription Owner rights

    As a Global Administrator, you can manage all Azure subscriptions and management groups in your tenant by elevating your access.

    When you elevate your access, you'll be assigned the role in Azure at root scope (/).  This allows you to view all resources and assign access to any subscription or management group in the directory.

    To elevate access, follow the instructions in Microsoft documentation: , or perform these steps:

    1. Sign in to Azure Portal as a Global Administrator.

    2. Open Microsoft Entra ID

    . You can use the Azure search bar to find
    Microsoft Entra ID
    .
    1. Under Manage, select Properties.

    1. Under Access management for Azure resources, set the toggle to Yes.

    1. Click Save. This will grant you permission to assign roles in all Azure subscriptions and management groups associated with this Microsoft Entra ID.

    2. If required, sign out and sign back in to refresh your permissions.

    User Access Administrator
    Elevate access to manage all Azure subscriptions and management groups
    onboarded your tenant

    This toggle is only available to users who are assigned the Global Administrator role in Microsoft Entra ID.

    Microsoft Entra ID
    Properties
    Toggle under Access Management for Azure Resources.