Azure, without a separate console
Azure is usually the subscription with the most history and the tightest ties to the rest of the business — Entra ID, licensing, the compliance sign-off nobody wants to redo. Sencai connects to it directly, discovers what's already running, and puts provisioning, live DNS management, and a tamper-evident audit trail on the same screen as every other provider you run. Nothing about your Azure subscription moves.
Connect the way that fits your Azure setup
Connecting Azure to Sencai starts with your existing subscription — bring your own cloud (BYOC). Credentials are encrypted at rest, scoped to what Sencai needs, and revocable from Azure at any time; the subscription, the contract, and the bill stay exactly where they are today. If you'd rather not run a separate Azure relationship at all, Sencai can provision and bill Azure capacity under its own account instead: one contract, one invoice, Azure's own cost plus a 2% margin shown as its own line. Both models can sit in the same organisation — start on BYOC and add managed capacity for a new project, or the reverse, without re-platforming anything you already have running.
See what's already running, before you change anything
The moment your Azure subscription is connected, Sencai inventories what's already there — virtual machines, virtual networks, storage accounts, DNS zones — without requiring a migration or an agent on anything. That inventory sits next to whatever else you've connected: another Azure subscription, AWS, Google Cloud, Hetzner, or a rack of bare-metal servers running the fleet agent. Nothing is pulled under active management automatically; you opt in resource by resource, at your own pace, and everything else stays exactly as discovered. For a team that's been running Azure for years and has stopped trusting its own tag hygiene, this is usually the first useful thing Sencai does — an honest, current list, not a spreadsheet someone updated in a hurry six months ago.
Provision and manage DNS the same way you do everywhere else
From Sencai, you provision, start, stop, resize, and destroy Azure instances the same way you would on any of the ten other providers Sencai connects to — same screen, same audit trail, no separate Azure Portal session required for routine work. DNS is managed live: changes you make in Sencai go straight to Azure, synchronously, not to a cached copy that drifts from what Azure actually serves. Install the fleet agent on any Linux VM running in Azure and you get monitoring, patching, software inventory, and approval-gated runbooks — the same incident-response steps you'd run on a Hetzner box or a bare-metal server in your own datacenter, defined once and executed identically everywhere.
An audit trail Azure doesn't give you, and one cost view across every provider
Every action taken through Sencai — provisioning, a DNS change, a runbook run — lands in an append-only, hash-chained audit log. "Who changed this, and when" becomes a query against that log, not a hunt through Azure Activity Log plus whatever else you're running elsewhere. Cost visibility works the same way: Azure spend sits next to every other connected provider in one place, with anomaly detection watching for the spike that would otherwise show up as a surprise on next month's invoice. If your team already signs in with Microsoft Entra ID, that identity carries straight into Sencai — SSO, SCIM provisioning, role-based access, and just-in-time elevation with approval workflows, so access to Azure resources through Sencai follows the same groups and reviews your Entra tenant already enforces.
Frequently asked
Does connecting Azure move our subscription into a new account?
No. In BYOC mode, your Azure subscription, contract, and billing relationship stay exactly where they are — Sencai only holds encrypted credentials scoped to what it needs, and you can revoke access from Azure at any time. If you'd rather not manage that relationship yourself, Sencai can also provision Azure capacity under its own account and bill you on one invoice, at Azure's cost plus a 2% margin.
Can we manage Azure DNS from the same place as our other providers?
Yes. DNS changes made through Sencai for Azure go directly and synchronously to Azure — not to a cached copy — and the same screen covers DNS for every other connected provider. If you run authoritative zones on Azure and instances elsewhere, you manage both without switching consoles.
We already use Microsoft Entra ID for SSO — does that carry over?
Yes. If your organisation signs in with Microsoft Entra ID, that identity extends into Sencai: single sign-on, SCIM provisioning for user lifecycle, role-based access control, and just-in-time elevation with approval workflows. Access to Azure resources through Sencai follows the same groups and policies your Entra tenant already enforces — no separate identity system to maintain.
Is Sencai ISO 27001 or SOC 2 certified?
No, and we say so directly rather than imply otherwise. Instead, Sencai gives you the evidence a security review actually needs: an exportable audit trail, records of processing, a published sub-processor register, a data-residency statement, and a Data Processing Agreement — reviewable before you connect a single Azure credential.
What does it cost to connect Azure alongside our other providers?
A free organisation plan covers 1 user, 1 organisation, and 5 managed resources, no card required and no time limit — enough to connect Azure and try inventory and provisioning for real. Paid plans start at EUR 299/month, and a 14-day full-featured trial needs no credit card either.
Bring Azure into one control plane
Connect your Azure subscription and see what's already running in minutes — no migration, no credit card for the trial, and first deploy typically under 30 minutes.