--- title: "Azure onboarding prerequisites" slug: "azure-onboarding-prerequisites" updated: 2026-05-24T14:23:43Z published: 2026-05-24T14:23:43Z canonical: "docs.zesty.co/azure-onboarding-prerequisites" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.zesty.co/llms.txt > Use this file to discover all available pages before exploring further. # Azure onboarding prerequisites This topic describes how to verify that an Azure account has the required permissions to onboard to Zesty. These permissions are required before onboarding: - [Billing account Owner on an MCA billing account, or Enterprise Administrator on an EA billing account](/docs/azure-onboarding-prerequisites#_ghbvk2ycarj1) - [Owner or Contributor on the root management group](/docs/azure-onboarding-prerequisites#_hlscpydkknql) - [Global administrator, with elevated access to management groups or subscriptions.](/docs/azure-onboarding-prerequisites#_de6rzf6lwqqz) ### Billing account Owner on an MCA billing account, or Enterprise Administrator on an EA billing account The account used for onboarding must be one of the following: - Billing account Owner on an MCA billing account - Enterprise Administrator on an EA billing account **To determine whether your billing type is MCA billing account or EA billing account, click here.** 1. Log in to the Azure portal. The login user must have billing permissions. 2. Search for and open **Cost Management + Billing**. 3. From the **Billing** menu, choose **Settings > Properties** (A). 4. Verify the billing type in the **Other details > Type** (B) field: ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/azure-onboarding-prerequisites-image-33h5qfvr.png) Proceed to the section for your billing type. **To verify if the user is a Billing account Owner on an MCA billing account**: 1. Log in to the Azure portal. The signed-in account must have permission to view the billing account and its role assignments. 2. Open **Cost Management + Billing**. 3. Open the MCA billing account (A). 4. From the billing account menu, select **Access control (IAM)** (B). 5. Enter the user name in the search field (C). 6. In the **Role** column, verify whether the user is assigned the **Owner** role (D). ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/azure_prereqs_billing_account_owner.png) **To verify if the user is an Enterprise Administrator on an EA billing account:** 1. Log in to the Azure portal. The login user must have EA enrollment permissions to access the enrollment management area. 2. Open **Cost Management + Billing**. 3. Select **Billing scopes**, then select the EA billing account. 4. Select Access Control (IAM) 5. In the **role assignments list**, locate the user and verify their role is **Enterprise Administrator**. ### Owner or Contributor on the root management group 1. Log in to the Azure Portal. The signed-in account must have permission to view role assignments on the root management group. 2. From Azure Resource Manager, search for **Management groups**. 3. From the Management groups tab, click **Tenant Root Group** (A). ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/azure_prereqs_mgmt_group_owner_1.png) 4. From the Tenant Root Group tab, select **Access control (IAM)** (B). 5. Select the **Role assignments** tab (C). 6. Search for the user name (D). 7. In the **Role** field, verify whether the user is assigned the **Owner** or **Contributor** role (E). ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/azure_prereqs_mgmt_group_owner_2.png) ### Global administrator, with elevated access to management groups or subscriptions. There are 2 permissions that need to be verified: - The user is a **Global Administrator**. - The user has **elevated access** to either management group or subscriptions. **To verify Global Administrator role through the Users menu:** 1. Log in to the Azure portal with the user ID whose permissions you want to verify. 2. From the menu, select **Users**. 3. From the Users page, search for the user name. 4. Click the user name to view their unique user information. The user name is shown at the top left. 5. From the user menu, click **Assigned roles** (A). 6. In the **Role** field, verify the user is a **Global Administrator** (B). ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/azure_prereqs_global_administrator_users.png) You can also verify using **Roles and administrators** > **Global Administrator**. **To verify elevated access:** 1. From the user verified as Global Administrator, open **Microsoft Entra ID**. 2. From the tenant menu, select **Manage** > **Properties**. 3. Under **Access management for Azure resources**, verify the selection is **Yes**. ![](https://cdn.document360.io/0eb80240-664b-49f5-9181-5713ddf9f725/Images/Documentation/azure_prereqs_elevated_access_users.png) If it’s not, set it to **Yes**, then click **Save**. You can also verify using **Microsoft Entra ID > Properties**.