---
title: pulumi env setup azure | CLI commands
url: /docs/iac/cli/commands/pulumi_env_setup_azure/
---



[EXPERIMENTAL] Set up Azure OIDC integration for Pulumi ESC

## Synopsis

[EXPERIMENTAL] Set up Azure OIDC integration for Pulumi ESC

Creates, in your Azure tenant:
  - an app registration trusting Pulumi Cloud as an OIDC identity provider
  - a federated identity credential and a service principal
  - a role assignment on each selected subscription

You are asked how to authenticate: with the Azure credentials you already have (from
`az login` or environment variables), or by signing in through your browser. Both span
the whole tenant.

Each selected subscription gets its own environment, pinning that subscription.

Examples:
  pulumi env setup azure --policy Contributor
  pulumi env setup azure --policy Reader --subscription <sub-id> --yes

```
pulumi env setup azure [flags]
```

## Options

```
      --browser                     force browser sign-in instead of using existing credentials
  -h, --help                        help for azure
      --org string                  the Pulumi organization to configure OIDC for
      --policy string               the role assigned per subscription: Contributor (required for Deployments), Reader (required for Insights), or any other role definition ID; prompted for when omitted
      --project string              the ESC project that per-subscription environments are created in (default "azure-login")
      --subscription subscription   an Azure subscription to set up (repeatable; prompted for when omitted)
      --tenant string               the Azure tenant to configure, which only its own subscriptions are visible through (prompted for when omitted)
      --yes                         skip all confirmation prompts
```

## Options inherited from parent commands

```
      --color string                 Colorize output. Choices are: always, never, raw, auto (default "auto")
  -C, --cwd string                   Run pulumi as if it had been started in another directory
      --disable-integrity-checking   Disable integrity checking of checkpoint files
  -e, --emoji                        Enable emojis in the output
      --env string                   The name of the environment to operate on.
  -Q, --fully-qualify-stack-names    Show fully-qualified stack names
      --logflow                      Flow log settings to child processes (like plugins)
      --logtostderr                  Log to stderr instead of to files
      --memprofilerate int           Enable more precise (and expensive) memory allocation profiles by setting runtime.MemProfileRate
      --non-interactive              Disable interactive mode for all commands
      --otel-traces string           Export OpenTelemetry traces to the specified endpoint. Use file:// for local JSON files, grpc:// or https:// for remote collectors
      --profiling string             Emit CPU and memory profiles and an execution trace to '[filename].[pid].{cpu,mem,trace}', respectively
      --tracing file:                Emit tracing to the specified endpoint. Use the file: scheme to write tracing data to a local file
  -v, --verbose int                  Enable verbose logging (e.g., v=3); anything >3 is very verbose
```

## SEE ALSO

* [pulumi env setup](/docs/iac/cli/commands/pulumi_env_setup/)	 - [EXPERIMENTAL] Set up cloud provider OIDC integrations


