---
title: "Enable vDiscovery in Azure"
canonical: "https://docs.infoblox.com/space/DeploymentGuidevNIOSforAzure/736396615/Enable%20vDiscovery%20in%20Azure"
format: markdown
---
In order to use vDiscovery in Azure, you must integrate the discovery application with Azure Active Directory (AAD) for secure authentication and authorization.

### **Create an App Registration in Azure AD**

1. In the Azure Portal, click the menu.
2. Select **Azure Active Directory**.

![image](media://e2abb1bd-9139-43e1-b143-6f35bf794829)

3. Click on **App registrations**.
4. Click **New registration**.


![image](media://4c6c0454-bffd-4937-82d6-61c8869c4fbe)

5. Type a **Name** for your App.
6. Ensure **Accounts in this organizational directory only** is selected under **Supported account types**.
7. Click **Register**.

![image]()

8. On the App’s Overview page, hover over **Application (client) ID**.
9. Click to copy the value to the clipboard. Save this ID.

![image](media://d81d92a8-a2ba-430d-9c04-7c2310a81ce4)

10. Click on **Endpoints**.
11. Hover over the **OAuth 2.0 token endpoint (v1)** and click to copy the value to the clipboard. Save this Endpoint.

![image](media://349fe279-1e89-46be-8aa5-ebe98a7c16d8)

12. Click on **API permissions**.
13. Click **Add a permission**.

![image](media://b44f2a0a-afa2-4d5f-8e41-f58cd1cf2222)

14. Select the **Azure Service Management** API.

![image](media://67b99a11-dcfe-4004-96d0-1cf01a90bb67)

15. Select the checkbox for** user_impersonation**.
16. Click **Add permissions**.

![image](media://8d4b7085-a43a-4d4f-b7fa-74cbbd43caa0)

17. Click on **Certificates & secrets**.
18. Click **New client secret**.

![image](media://f3858eda-4229-4201-8f0d-91efe95be328)

19. Enter a **Description**.
20. Select when the secret **Expires**.
21. Click **Add**.


![image](media://9a357cb9-3cf4-42eb-ad11-22612f7cb862)

22. Hover over the key **Value **of your new secret and click to copy the value to the clipboard. Save this Client Secret.

![image](media://d952dbbf-1cab-489f-838f-051b4eaeff13)

### **Add Role Assignment to Subscription**

For each Azure subscription where vDiscovery will be conducted, the new App needs to be added as a Reader. Alternatively, Reader permissions can be assigned at the Resource Group level for more granular control of what is included for vDiscovery.

1. In the Azure Portal, type **subscription** into the search box.
2. Click on **Subscriptions**.

![image](media://5429f72b-f2f4-45ba-9fc3-7c556aa6171d)

3. Select your desired subscription from the list.

![image](media://a6fd3667-8a00-4f9d-8b89-f148b859cfed)

4. On the Subscription blade, select **Access control (IAM)**.
5. Click on **Add**.
6. Select **Add role assignment** from the dropdown.

![image](media://2aa0ded3-9360-444c-9702-3dd6d419fa0b)

7. Select **Reader** from the Role dropdown.
8. Type the name of your App in the Select box.
9. Select your new App registration.
10. Click **Save**.

![image](media://bca45640-95da-40c3-bf0d-b4b28cb800a2)