Credential provisioning

To allow Cloudera to create resources on your Azure account, you must create app-based or certificate-based credentials. The credential allows Cloudera to access and provision a set of resources in your Azure account.

Cloudera uses an app-based credential or a certificate-based credential to authenticate your Azure account and obtain authorization to create resources on your behalf.

The app-based credential requires that you manually configure the service principal created within your Azure Active Directory. The app-based method requires Owner role to create a service principal, which must be given Contributor or equivalent role.

Certificate-based authentication uses asymmetric authentication based on private keys and public keys, and does not rely on sharing secrets. When using the certificate-based credential, Cloudera generates a private key and a certificate (public key) pair, and shares the certificate with you. After the certificate is shared, you must register it with Azure.

To meet Azure prerequisites for Cloudera:
  1. Review the provided policies.
  2. Obtain the subscription and tenant ID.
  3. Create an app registration on Azure or generate and register an Azure certificate credential.

Your Azure administrator must create custom roles in the Azure subscription.