Skip to main content
Infisical supports connecting to Azure DNS using a Service Principal with Client Secrets for secure access to manage DNS records in your Azure DNS zones.
To use client secret authentication, ensure your Azure Service Principal has the required permissions to manage DNS records in your Azure DNS Zone.
If you want to configure automatic client secret rotation for this App Connection, you also need to grant either Application.ReadWrite.OwnedBy or Application.ReadWrite.All permissions.
Prerequisites:
  • Set up Azure and have an existing DNS Zone.
  • An Azure Service Principal (App Registration) with a Client Secret.
1

Navigate to your DNS Zone

In the Azure Portal, navigate to your DNS Zone that you want to use for ACME DNS validation. Click on Access control (IAM) in the left sidebar, then click Add > Add role assignment.Navigate to DNS Zone
2

Assign DNS Zone Contributor Role

Search for and select the DNS Zone Contributor role, then click Next.Select DNS Zone Contributor Role
3

Select your Service Principal

Click Select members, search for your App Registration (Service Principal), select it, and click Select.Select Service PrincipalClick Review + assign to complete the role assignment.

Setup Azure DNS Connection in Infisical

1

Navigate to App Connections

Navigate to the App Connections page in the desired project.App Connections Tab
2

Add Connection

Select the Azure DNS Connection option from the connection options modal.Select Azure DNS Connection
3

Create Connection

Fill in the Tenant ID, Client ID, Client Secret, and Subscription ID fields with the credentials from your Azure Service Principal.Connect to Azure DNS
You can find your Subscription ID in the Azure Portal under Subscriptions. The Tenant ID and Client ID can be found in your App Registration’s Overview page.
You can optionally enable Automatic Credential Rotation for this connection. See the Automatic Credential Rotation section below for details.
4

Connection Created

Your Azure DNS Connection is now available for use in your Infisical projects.Azure DNS Connection Created

Automatic Credential Rotation

Infisical can automatically rotate the Client Secret of your Azure application on a recurring schedule. When enabled, Infisical will immediately generate a new Client Secret on connection creation and revoke the original one, ensuring that no external party retains access using the credentials you provided.
1

Locate the Key ID of your Client Secret

Before enabling rotation, you’ll need the Key ID of the Client Secret you are using to authenticate. Navigate to your App Registration in the Azure Portal, then go to Certificates & secrets. Copy the Secret ID (Key ID) of the secret you are providing to Infisical.Azure Client Secret Key ID
2

Enable Automatic Credential Rotation

When creating or editing your connection, toggle on the Automatic Credential Rotation switch.Enable Automatic Credential Rotation
3

Provide the Client Secret Key ID

Enter the Key ID you copied in the previous step into the Client Secret Key ID field. Infisical uses this to revoke your original secret after generating a new one.Client Secret Key ID Field
4

Configure the Rotation Schedule

Set the Rotation Interval (in days) to define how often the credential should be rotated, and set Rotate At to the local time of day at which the rotation should occur.
  • Rotation Interval - How many days between each rotation.
  • Rotate At - The local time of day at which the rotation will be triggered. Rotation Schedule