Connect a Microsoft Azure environment to Nerdio Compass

This procedure walks you through granting Nerdio Compass the two Microsoft consents it needs to discover and manage a Microsoft Azure environment: Microsoft Entra ID / Graph API access for directory data, and Azure subscription access with the built-in Reader role for Azure Virtual Desktop discovery. This procedure applies to the Microsoft section of Nerdio Compass; other platform sections (Citrix, Omnissa, Amazon) have their own connection workflows. Before you begin, make sure you have an active Microsoft Entra ID tenant and at least one Azure subscription with sufficient permissions to consent to application permissions and assign roles on behalf of your organization.

Note

If a Microsoft consent is declined or interrupted, Nerdio Compass shows an error message and lets you select the same consent button again to retry.

Grant Microsoft Entra ID / Graph Consent

  1. Select Allow Entra ID Permissions in the Microsoft Entra ID / Graph Consent panel.

    This redirects to Microsoft's admin consent endpoint to request permissions for Nerdio Compass to read directory data, users, groups, devices, and other Entra ID information via the Microsoft Graph API.

  2. Select your signed-in Entra ID account.

    A Microsoft permissions consent screen opens, titled Permissions requested, listing the directory, device, group, and policy read permissions requested by Nerdio Compass.

  3. Select Accept to approve the requested permissions.

    The Microsoft Entra ID / Graph Consent panel shows a Completed status, and the Azure subscription access panel becomes active.

Grant Azure Subscription Access

  1. Select Connect a subscription in the Azure subscription access panel.

    This redirects to Microsoft's OAuth2 authorization endpoint to request Azure subscription access permissions.

  2. Select your signed-in Entra ID account.

    A Microsoft permissions consent screen opens, titled Permissions requested, requesting access to Azure Resource Manager on your behalf.

  3. Select Accept to approve the requested permissions.

  4. In the Select a subscription field, select your Azure subscription.

  5. Select Grant Reader access.

    Nerdio Compass assigns the built-in Reader role to its resource-access identity on the selected subscription, enabling discovery of Azure Virtual Desktop resources.

Results

Nerdio Compass now has both Microsoft consents it needs: Entra ID / Graph API access to read directory data, users, groups, and devices, and Reader access on the selected Azure subscription to discover Azure Virtual Desktop resources. As next steps, you can configure Azure Virtual Desktop host pools, set up session host management policies, and establish user assignment rules within Nerdio Compass to begin managing your AVD environment.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.