Prerequisite Checklist | Help Center | Archera

Azure Onboarding Prerequisite Checklist

Azure onboarding requires two checks before you begin.

1. User Access Administrator role at root scope

Archera creates a custom RBAC role inside your Azure tenant. Make sure your onboarding user has Access management for Azure resources enabled. This is a hard requirement BEFORE beginning Archera's Azure onboarding. If you don't verify or action this step, the onboarding will fail.

NOTE: The "onboarding user" will be whoever from your company executes the Archera onboarding process.

We are NOT asking for you to grant Archera these permissions. We are ensuring your personnel has sufficient permissions in your environment to complete the process.

Global Administrator + Entra properties toggle on

  1. Go to Microsoft Entra ID → Users.
  2. Select the onboarding user.
  3. Open Assigned roles.
  4. Add Global Administrator in the role directory.
  5. Go to Microsoft Entra ID → Overview → Properties.
  6. Turn on Access management for Azure resources if it is off.
  7. Click Save to apply.

You can find this setting in: Microsoft Entra ID > Overview > Properties. This toggle only needs to be enabled for your personnel for the duration of onboarding. You can disable it after onboarding completes.

2. Contributor role at subscription scope

Your designated "onboarding user" needs Contributor RBAC role at subscription scope.

NOTE: The "onboarding user" will be whoever from your company executes the Archera onboarding process. We are NOT asking for you to grant Archera these permissions. We are ensuring your personnel has sufficient permissions in your environment to complete the process.

This contributor access is only required for the single subscription as detailed below.

Yes, you can onboard more than one subscription at a time. We just need one of your subs earmarked to hold the cost exports for all of the subscriptions you choose to onboard into Archera.

Related Resources