> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://contentful.com/developers/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://contentful.com/developers/docs/_mcp/server.

# Azure connector setup

> Learn how to set up Azure connector.

## Azure connector setup guide

You can connect Azure to AI Actions using your own Microsoft account. This allows AI Actions to discover and invoke Azure foundation models using credentials you control.

## Step 1: Configure Azure connection

Fill out the following required credentials taken from Entra ID from your company Overview page in the Microsoft Azure Portal:

![Azure connector modal](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/contentful.docs.buildwithfern.com/9b497f40e29a08ee8c05c05e5b9277002ca084e85ea1e754a5fbc324214cda23/docs/assets/images/azure-connector-modal.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260929%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260929T234817Z&X-Amz-Expires=604800&X-Amz-Signature=2384d300a9d1eb3d923a559f602563ff542b9f5982bfc5d119248233687c7c6a&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

* **Azure tenant ID** - identifies your organization's Azure Active Directory instance used for authentication.
* **Subscription ID** - specifies the Azure subscription that contains your resources and billing context.
* **Resource Group** - the container that holds your Azure resources, including your OpenAI service.
* **OpenAI resource name** - the name of your Azure OpenAI resource used to route requests to the correct service instance.

Once completing all of the fields, you will be redirected to register the Contentful connector in the [Azure Portal](https://azure.microsoft.com/en-us/get-started/azure-portal).

## Step 2: Register your model

1. Click **Register** in your configuration modal.
2. Select your Azure account and **Accept**.

## Step 3: Create a custom IAM role

To allow Contentful to cache credentials and reduce repeated role assumptions:

1. In your Microsoft Azure account, go to **Subscriptions → Access Control (IAM)** and create a new custom role.
2. Under the JSON tab, paste the following JSON template:

```json
{
    "properties": {
        "roleName": "OpenAI Model Lister and Invoker",
        "description": "Allows listing and invoking OpenAI models.",
        "assignableScopes": [
            "/subscriptions/YOUR_SUBSCRIPTION_ID_HERE"
        ],
        "permissions": [
            {
                "actions": [
                    "Microsoft.CognitiveServices/accounts/read",
                    "Microsoft.CognitiveServices/accounts/deployments/read"
                ],
                "notActions": [],
                "dataActions": [
                    "Microsoft.CognitiveServices/accounts/OpenAI/responses/write",
                    "Microsoft.CognitiveServices/accounts/OpenAI/responses/read"
                ],
                "notDataActions": []
            }
        ]
    }
}
```

This ensures more stable access when invoking and listing the models.

3. Before deleting the original JSON, copy the **Subscription ID** from the original JSON and paste it into the new JSON template.
4. Once the original JSON is deleted and replaced with the new JSON, click **Review + create**.

## Step 4: Add role assignment

1. Navigate to **Subscriptions → Access Control (IAM)**.
2. Choose **Add role assignment**.
3. In the table search bar, locate the recent CustomRole type.
4. Under the **Members** tab of the Custom Role, choose **OpenAI connector** from the **Select Members** option.
5. Select **Review + assign**.

## Step 5: Complete setup

1. Select the model(s) to enable AI Actions to invoke Azure model(s).
2. Click **Add provider** to complete the configuration.

## Troubleshooting

If you are encountering errors in registration, verify the credentials are correct by checking the information in the Microsoft Azure portal. This can be caused by insufficient permissions or delay time.