Create cloud access profiles in Azure

Last published : Sep 30, 2026
The service uses a cloud access profile to acquire permissions to the customer’s Azure account. The service uses these permissions to deploy the application delivery infrastructure in the customer-owned Azure resource group. To create this profile, you must be an Azure account administrator that has the Owner privileges for the resource group that you use for delivering your applications.
NetScaler provides a PowerShell script that simplifies creating app registrations and secrets in the Azure CLI. The script grants required permissions to App registration to create the infrastructure and deliver apps in the customer-owned Azure resource group. When you create an app registration, an application object and service principal are automatically created in your Azure home directory or tenant. The same service principal is assigned with the permissions required for both NetScaler managed application and NetScaler VPX instances.

Prerequisites

  • You have a Microsoft Azure account that supports the Azure Resource Manager deployment model.
  • You have a resource group in Microsoft Azure.
For more information on how to create an account, resource group, assign privileges, and other tasks, see the Microsoft Azure documentation.

Assign permissions to NetScaler® ADM service

The PowerShell script creates a custom role with permissions required for NetScaler Console. For the list of permissions assigned to the custom role, see Permissions assigned to NetScaler Console service. This custom role is assigned to the service principal while creating role assignments for the resource group.

Permissions assigned to NetScaler ADM service

"Microsoft.Compute/availabilitySets/read", "Microsoft.Compute/virtualMachines/instanceView/read", "Microsoft.Compute/virtualMachines/read", "Microsoft.Compute/virtualMachines/write", "Microsoft.Compute/virtualMachines/delete", "Microsoft.Compute/virtualMachines/restart/action", "Microsoft.Compute/virtualMachineScaleSets/read", "Microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read", "Microsoft.Network/virtualNetworks/read", "Microsoft.Network/virtualNetworks/subnets/read", "Microsoft.Network/virtualNetworks/subnets/write", "Microsoft.Network/virtualNetworks/subnets/delete", "Microsoft.Network/networkSecurityGroups/read", "Microsoft.Network/networkSecurityGroups/write", "Microsoft.Network/networkSecurityGroups/delete", "Microsoft.Network/publicIPAddresses/write", "Microsoft.Network/publicIPAddresses/delete", "Microsoft.Network/publicIPAddresses/read", "Microsoft.Network/dnszones/CNAME/read", "Microsoft.Network/dnszones/CNAME/write", "Microsoft.Network/dnszones/CNAME/delete", "Microsoft.Network/loadBalancers/read", "Microsoft.Network/loadBalancers/write", "Microsoft.Network/loadBalancers/delete", "Microsoft.Network/networkInterfaces/read", "Microsoft.Network/networkInterfaces/write", "Microsoft.Network/networkInterfaces/delete", "Microsoft.Resources/subscriptions/resourceGroups/read", "Microsoft.Resources/tags/read", "Microsoft.Resources/tags/write", "Microsoft.Resources/tags/delete", "Microsoft.Resources/deployments/read", "Microsoft.Resources/deployments/write", "Microsoft.Resources/deployments/delete", "Microsoft.Resources/deployments/operationstatuses/read", "Microsoft.Resources/deployments/operations/read", "Microsoft.Network/networkSecurityGroups/join/action", "Microsoft.Compute/disks/delete", "Microsoft.Compute/disks/write", "Microsoft.Compute/disks/read", "Microsoft.Network/virtualNetworks/subnets/join/action", "Microsoft.Network/networkInterfaces/join/action", "Microsoft.Network/publicIPAddresses/join/action", "Microsoft.Network/loadBalancers/backendAddressPools/join/action", "Microsoft.Network/dnszones/read", "Microsoft.Storage/storageAccounts/write", "Microsoft.Storage/storageAccounts/read", "Microsoft.Storage/storageAccounts/delete", "Microsoft.Storage/storageAccounts/blobServices/containers/write", "Microsoft.Storage/storageAccounts/blobServices/containers/read", "Microsoft.Storage/storageAccounts/blobServices/containers/delete", "Microsoft.Compute/images/read", "Microsoft.Compute/images/write", "Microsoft.Compute/images/delete", "Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read", "Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write", "Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete"

Assign permissions to NetScaler VPX™ instances

The PowerShell script also creates a custom role with permissions required for NetScaler VPX instances. For the list of permissions assigned to the custom role, see Permissions assigned to NetScaler VPX instances. This custom role is assigned to the same service principal while creating role assignments for the resource group.
Note:
The NetScaler Console service and NetScaler VPX instance use the same service principal captured in the cloud access profile.

Permissions assigned to NetScaler VPX instances

"microsoft.monitor/accounts/read", "microsoft.monitor/accounts/write", "microsoft.monitor/accounts/delete", "Microsoft.Compute/virtualMachines/read", "Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read", "Microsoft.Compute/virtualMachineScaleSets/virtualMachines/delete", "Microsoft.Compute/virtualMachineScaleSets/read", "Microsoft.Network/virtualNetworks/read", "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/read", "Microsoft.Network/networkInterfaces/read", "Microsoft.Network/publicIPAddresses/read", "Microsoft.Network/loadBalancers/read", "Microsoft.ResourceGraph/resources/read", "Microsoft.Insights/AutoscaleSettings/Read", "Microsoft.Insights/AutoscaleSettings/Write", "Microsoft.Insights/AutoscaleSettings/Delete", "Microsoft.Compute/virtualMachineScaleSets/write"

Create a cloud access profile

  1. Navigate to NetScaler Managed Apps > App Environments > Cloud Access Profiles tab, click Create and select Azure.
  2. Enter a profile name.
  3. Follow these instructions to create an app registration in Azure:
    1. Download the PowerShell script provided by NetScaler. The script creates app registrations and secrets for the app registration.
    2. Open an Azure cloud shell in a browser.
    3. Select PowerShell as the type of shell.
    4. In the Azure shell menu, select Upload/Download.
    5. Upload the Citrix-provided script and run the Connect-AzureAD command.
    6. Run the ./manage-app-registration.ps1 script. Learn more.
  4. Copy the JSON output of the script and paste it in the Details field of Create Cloud Access Profile page.
  5. Click Create to create a cloud access profile.

Run PowerShell script

One of the important steps in creating a cloud access profile is running the PowerShell script downloaded from the NetScaler Console GUI. When you run the script, you must select one of the following options:
  1. Press ‘1’ if you are a new user: Creates two role definitions, one service principal, and two role assignments for each resource group. When prompted, enter the names of the resource groups where NetScaler Console service can create and configure app infrastructure. Enter the application name and the validity period in years when prompted.
  2. Press ‘2’ to update the role: Updates the existing role definitions with the latest set of permissions required for the NetScaler Console service.
  3. Press ‘3’ to renew the credentials: Deletes the expired secrets and creates new secrets with the validity period (in years) that you enter when the script prompts.
  4. Press ‘4’ to provide access to another resource group: Extends the scope of service principal for other resource groups. When prompted, enter the resource group name where NetScaler Console service can create and configure app infrastructure. Enter the application name when prompted.
  5. Press ‘5’ to cleanup azure AAD application: Removes all role assignments, both of the role definitions, and the app registration.
  6. Press ‘Q’ to quit: Exits the PowerShell script.