For the complete documentation index, see llms.txt. This page is also available as Markdown.

Onboarding using Azure CLI

Manual CLI Setup

Some enterprise Azure tenants enforce security policies that block Global Admin consent for OAuth-based third-party application provisioning. This page covers the CLI/RBAC onboarding path — Archera's alternative for restricted tenants.

Instead of the standard OAuth authorization screen, a privileged admin in your organization downloads a pre-generated bash script from the Archera platform and runs it in Azure Cloud Shell or a local terminal. The script applies the required RBAC role assignments directly — no user-impersonation consent required.

Note: This path must be enabled for your organization by Archera support before you begin. If you haven't already confirmed this with your Archera contact, email support@archera.ai.


Prerequisites

  • An eligible Azure billing account type (Microsoft Customer Agreement, Microsoft Partner Agreement, or Enterprise Agreement). See Supported Account / Subscription Types.

  • The person running the script must have Owner or User Access Administrator on the target subscriptions.

  • Access management for Azure resources enabled in Microsoft Entra ID — required to create custom roles at tenant scope. See the Prerequisite Checklist.

  • Access to Azure Cloud Shell or a local terminal with the Azure CLI installed.


Choosing Your Environment


Download and Run the Script

Step 1 — Select the CLI/RBAC path in the onboarding wizard

When you reach the authorization step in the Archera onboarding flow, you will see two options:

  • Standard OAuth — for tenants without Global Admin consent restrictions

  • CLI/RBAC script — for restricted tenants

Select CLI/RBAC script.

Step 2 — Download the generated script

Archera generates a bash script pre-populated with your organization's tenant ID, subscription IDs, and Archera's service principal. Download it from the onboarding screen.

Step 3 — Run the script

The platform provides run instructions for both environments:

Azure Cloud Shell (recommended)

  1. Launch Cloud Shell in Bash mode

  2. Upload the script via Manage files → Upload

  3. Run: bash archera-azure-onboarding.sh

Local terminal

  1. Ensure the Azure CLI is installed: az --version

  2. Log in to the correct tenant: az login --tenant <your-tenant-id>

  3. Run: bash <your-downloaded-script-name>.sh

The script will:

  1. Validate your Azure session and target subscriptions

  2. Register the required resource providers

  3. Create the Archera custom RBAC role at tenant scope

  4. Assign the required built-in roles to Archera's service principal

  5. Create the resource group and storage account for cost exports

  6. Print a completion summary

You will be asked to confirm before any resources are created.

Step 4 — Verify completion

Once the script finishes, return to the Archera platform. The onboarding wizard detects that the required permissions have been applied and advances automatically.

Expected state after a successful run:

  • No outstanding permission errors in the wizard

  • Green confirmation state on the authorization step

If the wizard does not advance, refresh the page and allow 2–3 minutes for Azure RBAC propagation before retrying.


Role Summary

The script assigns the following permissions to Archera's service principal:

Role
Scope
Purpose

Archera Custom Role (read)

Each selected subscription

Billing, cost management, resource reads

Reader and Data Access

Storage account

SAS token generation for cost export reads

Storage Blob Data Reader

Storage account

Direct blob read access

User Access Administrator

Storage account

Grant write access to Cost Management export managed identity

Reservation Reader

/providers/Microsoft.Capacity

Read existing Reserved Instances

Reservation Purchaser

/providers/Microsoft.Capacity + management subscription

Purchase Reserved Instances

Savings Plan Reader

/providers/Microsoft.BillingBenefits

Read existing Savings Plans

Savings Plan Purchaser

/providers/Microsoft.BillingBenefits + management subscription

Purchase Savings Plans

Advisor Recommendations Contributor

/providers/Microsoft.Advisor

Read Advisor recommendations


Troubleshooting

Script exits with a permissions error The user running the script lacks sufficient rights to assign RBAC roles. Confirm the running account has Owner or User Access Administrator on the target subscriptions and that Access management for Azure resources is enabled in Microsoft Entra ID.

Wizard does not advance after the script completes Allow 2–3 minutes for Azure RBAC propagation and refresh. If the issue persists, confirm the script ran against the correct subscriptions — a mismatch between the subscriptions Archera expects and what the script targeted is the most common cause.

CLI/RBAC option not visible in the onboarding wizard This path requires a feature flag enabled by Archera on your account — it is not self-service. Contact your Archera representative or email support@archera.ai to request it before attempting onboarding.


  • Azure Onboarding — Prerequisite Checklist

  • Azure Onboarding — Required Permissions

  • How Does Archera Access My Azure Environment?

  • Azure Offboarding

Last updated

Was this helpful?