To back up Microsoft Azure for PostgreSQL database resources, you must authorize the Commvault MultiTenant app in your Azure tenant. The user who signs in must have sufficient permissions to authorize the MultiTenant app and must be assigned the required Azure roles for the database resources that you want to protect.
Before You Begin
-
If you are an MSP and you want your tenant administrators to create the Azure app, see MSP configuration for Azure.
-
To back up the Azure database accounts, you must authorize the Commvault Cloud MultiTenant app on your tenant. The user signing in must have permission to authorize the MultiTenant app and must be a member of Project Collection Administrators (PCA) group for the Azure database accounts to be backed up.
To check the permissions to authorize the app, do the following:
-
Login to Microsoft Entra admin center.
-
Browse to Identity > Applications > Enterprise applications > Consent and permissions > User consent settings.
-
Ensure the user signing in has the necessary permissions to authorize the Commvault Cloud MultiTenant app. If not, contact your administrator to grant the required permissions.
-
Login to Azure.
-
Browse to Organization Settings > General > Users.
-
Ensure the user signing in is part of the users list. If not, add the user to the list.
-
Browse to Organization Settings > Security > Permissions > Project Collection Administrators > Members.
-
Ensure the user signing in is a member of the group. If not, add the user to the group.
-
Procedure
-
On the Authorize Multi Tenant App page, choose one of the following:
-
Use existing tenant
- From Azure tenant list, select an azure tenant.
-
Authorize new tenant:
- Click Sign in with Microsoft, and then authorize the new tenant.
-
-
Click Next.
-
On the Authorized Workload App page, click Sign in with Microsoft.
A Microsoft window displays all the permissions that are required to access the Azure app.
If the browser pop-up blocker blocks the Microsoft window, allow access to the Microsoft window.
-
On the Microsoft permission requested dialog box, click Accept.
A validation message is displayed on the screen Workload app is authorized.
-
Click Next.
-
On the Assign Role page, from the Subscriptions list, select an Azure subscription.
A role is created in your tenant environment and associated with the selected subscription.
-
Click Next.
-
On the Cloud Account page, in the Name box, enter the cloud account name, and then click Next.
-
On the Summary page, click Create new instance.
The Configure Permissions page appears.