Single Subscription Setup
Connect one Azure subscription to KubeSense for read-only inventory and Azure Monitor metrics.
Before you start
Complete the collection setup first: an App
Registration with Reader and Monitoring Reader on the subscription, and its tenant ID,
client ID and client secret value to hand.
Use this path for one subscription, or a few you would rather add by hand. If your estate spans many subscriptions, Multi-Subscription Setup enrols them automatically instead.
Connect the subscription
Settings → Integrations → Azure → Add New Azure Account → Single Subscription:
| Field | What to enter |
|---|---|
| Name | A friendly label for this subscription in KubeSense, e.g. azure-prod. |
| Azure Subscription ID | The subscription GUID from the portal. |
| Directory (Tenant) ID | Your Entra ID tenant GUID. |
| Application (Client) ID | From the App Registration. |
| Client Secret Value | The Value, not the Secret ID. Stored encrypted and never displayed again. |
| Default Azure Region | A region slug such as eastus. A label only — see the note below. |
| Collection Settings | Which services to collect, and how deep. |
Select Connect. KubeSense verifies the credential immediately — it reads the subscription from ARM — and the next screen reports success or the exact error Azure returned.
About Default Azure Region: Unlike some clouds this does not narrow what is collected: ARM lists resources across the whole subscription regardless. It is a label, used as the fallback region for a resource that does not report one of its own.
Every resource type starts disabled: A subscription connected with nothing selected authenticates correctly and then collects nothing — which reads as broken rather than unconfigured. Choose your resource types on this screen; you can change them at any time from the integration's settings, and a change takes effect on the next collection cycle.
This path requires a client secret — both the client ID and secret are mandatory here — so workload identity is selectable only on the Multi Subscription path. You can still use it for a single subscription by naming just that one subscription there.
Verify
- The credential resolves. The screen after Connect reports this, and the message on failure is Azure's own.
- Resources appear. Open the integration from Settings → Integrations → Azure. Within a minute or two it shows a count per resource type.
- Metrics arrive. Allow up to 10 minutes for the first metric cycle, then open any discovered resource and confirm its charts are populated.
Troubleshooting
| Symptom | Likely cause | Action |
|---|---|---|
| "Azure rejected these credentials" | The secret is wrong or expired, or the tenant ID belongs to a different tenant than the App Registration | Confirm you copied the secret's Value, not its Secret ID |
| Connected, but nothing is collected | No resource types selected | Open the integration's settings and enable the types you want |
| Resources appear but their charts are empty | Monitoring Reader is missing on that subscription | Reader alone lists resources but cannot read metrics |
| An AKS cluster appears but has almost no metrics | Expected — cluster-level metrics from Azure Monitor are deliberately few | Deploy the KubeSense sensor to that cluster for in-cluster depth |
| Everything worked, then collection stopped | The client secret expired | Create a new secret on the App Registration and update the integration |