Create a Microsoft Azure API Management Machine
Focus
Focus
Next‑Gen Trust Security

Create a Microsoft Azure API Management Machine

Table of Contents

Create a Microsoft Azure API Management Machine

Creating a new machine is the first step in enabling Next-Gen Trust Security to connect directly to Microsoft Azure API Management for certificate management. After you create the machine, you can provision certificates to it.

Before You Begin

You will need the following information to complete this procedure:
  • Azure tenant ID, application (client) ID, and client secret from an Azure Active Directory service principal.
  • Minimum required permissions on Azure: the service principal must have the API Management Service Contributor role, or equivalent read and write access, on the target Azure API Management instance.
  • Azure subscription ID, resource group name, and API Management service name for the target instance.
  • Credentials: Choose between user credentials or shared credentials.
    • User credentials: Enter the Azure service principal credentials manually.
    • Shared credentials: Optionally, you can use shared credentials from your credential provider (CyberArk is the only credential provider currently supported by Next-Gen Trust Security). To use this option, first set up the connection to CyberArk.
Note: No VSatellite is required. The connector operates against the Azure management plane over outbound HTTPS only.
Note: Azure Managed Identity is not yet supported as a connection option. A long-lived Azure AD application secret is required.
Note: Certificates sourced from Microsoft Azure Key Vault are flagged during discovery. Provisioning installs uploaded (Custom) certificates and converts Azure Key Vault-backed hostnames to Custom. The Azure Key Vault reference is preserved for non-targeted domains.

Connection Details

  1. (Optional) From the Credential Type drop-down, select either Enter Credentials or Select Credentials. Only users with the enabled "CyberArk shared credential" capability see this option.
    Important: Your view of credentials may be limited due to your role. System Administrators and PKI Administrators should be able to select any credential, but users with the Resource Owner role are restricted to using the credentials associated with their teams.
    Note: Enter Credentials is used to enter your Azure service principal credentials manually. Select Credentials is used to select your shared credentials from CyberArk.
    • If you choose Enter Credentials, proceed to the next step and enter your Azure credentials.
    • If you choose Select Credentials, from the Credential drop-down, select your shared credentials.
  2. Enter your Tenant ID. This is the unique identifier of the Azure Active Directory instance.
  3. Enter your Client ID. This is the unique identifier of the Azure AD application (service principal) used for authentication.
  4. Enter your Client Secret. This is the credential that authenticates and authorizes the client application when it interacts with Azure services.
    Warning: Remember to store your username and password securely when creating a new machine. For security reasons, you will not be able to modify the fields under the "Access" tab without these credentials. This ensures that only authorized individuals can modify these fields.
  5. Enter your Subscription ID. This is the Azure subscription that contains your API Management instance.
  6. Enter your Resource Group name. This is the Azure resource group that contains your API Management service.
  7. Enter your Service Name. This is the name of your Azure API Management instance.
  8. Click Test Access, then click Continue. Continue is enabled only if Test Access is successful.

What's Next?

Refer back to Create a New Machine to finish setting up your new machine by configuring discovery and provisioning scheduling.
For existing machines: