Adding Microsoft Azure Accounts

In plugin, you can add Microsoft Azure connection accounts.


The account you want to use for connection must be granted permissions specified in the Plug-In Permissions section of the Veeam Backup for Microsoft Azure User Guide.

Creating Microsoft Azure Account

To create a new Microsoft Azure account:

  1. Log in to Veeam Service Provider Console.

For details, see Accessing Veeam Service Provider Console.

  1. At the top right corner of the Veeam Service Provider Console window, click Configuration.
  2. In the configuration menu on the left, click Plugin Library.
  3. Click the Veeam Backup for Public Clouds plugin tile.
  4. In the menu on the left, click Accounts and navigate to Public Cloud.
  5. At the top of the list, click New > Microsoft Azure.

Veeam Service Provider Console will open the New Azure Account wizard.

  1. On the Account Info step of the wizard, specify account settings:
  • In the Site field, select Veeam Cloud Connect site on which you want to register the account.
  • In the Name field, specify account name.
  • In the Description field, specify account description.

Specify Account Name and Description

  1. On the Account Type step of the wizard, select the Microsoft Azure environment where the account will reside and specify whether you want to create a new service account or use an existing account.

Specify Account Type

  1. [If you selected to create a new service account] On the Microsoft Azure step of the wizard, log in to your Microsoft Azure account:
  1. Click Copy code to copy an authentication code.
  2. Click the Microsoft authentication portal link.

A web browser window will open.

  1. On the Microsoft Azure device authentication page, paste the code that you have copied and sign in to Microsoft Azure.

Make sure to sign in with the user account that has the User Access Administrator or the Owner role. For details, see Microsoft Docs.

  1. Return to the wizard and click Next.

Verify Microsoft Azure Account

  1. [If you selected to use an existing service account] On the Service Account step of the wizard, specify account credentials:
  1. In the Application ID field, enter the application identifier. You can find the identifier in the application settings of your Azure Active Directory. For more information, see Microsoft Docs.

The specified Azure AD application must have either a custom role or the Contributor and Key Vault Crypto Officer Azure built-in roles assigned. If the AD application has a custom role assigned, make sure the role is granted the permissions required to perform backup and restore operations. For details on how to create Azure custom roles, see Microsoft Docs.

  1. In the Client (application) secret field, provide the secret string. For details on obtaining the secret string, see Microsoft Docs.
  2. In the Tenant ID field, enter a tenant ID of the Azure AD application.

You can find the tenant ID in the application settings of your Azure Active Directory. For details, see Microsoft Docs.

Specify Existing Account

  1. On the Summary step of the wizard, review the account settings and click Finish.