SOON Opening to the first customers.

Three steps. Nothing to install.

Kronikl connects to your Azure tenant the way a read-only integration should: you approve it in Microsoft’s own consent screen, you assign it a role, and that is the whole of it. No agent, no runbook, no resource deployed into your subscription, and nothing for you to patch afterwards.

Budget about ten minutes. Most of that is the two clicks in Microsoft’s own screens.

  1. 1

    Sign in with your Microsoft work account

    No Kronikl password is created, because there is no Kronikl password — sign-in is Entra SSO against the Microsoft work account you already have. The first sign-in creates your organization from the tenant you signed in from.

  2. 2

    Grant admin consent

    Kronikl asks Microsoft for five read permissions, and the page before you leave lists them in plain language — with Microsoft’s own wording beside each one — so you know what you are approving before you see the consent screen. This step needs a Global Administrator or Privileged Role Administrator.

    Consent alone gives Kronikl no access to your resources at all — it grants directory permissions, which is a different thing from Azure RBAC. That is why there is a third step.

  3. 3

    Assign the role, with your own credentials

    Press the button

    Kronikl shows you the scopes you can grant at, then two ways to grant. Press the button and the assignment is created there and then — signed in as you, using your own Azure privilege, recorded in your Activity Log under your name. Kronikl tells you the role, the exact object it is assigned to, and every scope path, and waits for you to confirm.

    Or take the command

    Or take the command — Azure CLI, PowerShell, Terraform or Bicep — and run it wherever you prefer. That is not the fallback path: creating a role assignment needs Owner or User Access Administrator at the scope, which a Global Administrator does not automatically hold, so for plenty of people the command sent to a colleague is the route that works.

    • What Kronikl cannot do, on either path, is grant itself anything. Its own credentials can only read; every way of creating the assignment spends an administrator’s privilege, never Kronikl’s.

    • The role is Azure’s built-in Reader. There is nothing to choose: Kronikl asks for Reader, and you decide where it applies.

    • Grant it against your entire Azure environment, or against a single subscription. Granting broadly is worth it: a subscription somebody creates next quarter is covered without anyone having to remember to come back here.

What you will need

  • A Microsoft work account in the tenant you want to record.
  • Admin consent — from a Global Administrator or Privileged Role Administrator.
  • A role assignment at the scope you choose — Owner or User Access Administrator. Often the same person under a different profile.

Nothing else. No subscription to deploy into, no Marketplace offer to accept, no VM, no agent, no script running on a schedule inside your environment.

Before you start

You can stop halfway

Step 3 is the one most likely to need a different account. Kronikl remembers where you got to, so you can sign in, get as far as consent, and hand the last step to whoever holds the rights — the walkthrough resumes where your tenant actually is, not where you left the page.

Signed in as the wrong account?

Common, and better known now than three screens in — the Azure rights often sit on a different account from the one you use day to day. Email hello@kronikl.io and we will send back the permissions to line up and the steps in order, in one message you can forward to your Azure administrator.

When can I actually do this?

Kronikl opens to its first tenants shortly. Email hello@kronikl.io and we will connect your tenant with you when it does — the steps above are what it will take, and they are not going to change.

Ready when you are

Three steps, about ten minutes, and nothing installed in your tenant.

Ask for early access See exactly what it can do