docs/integrations/app-connections/azure-dns.mdx
Infisical supports connecting to Azure DNS using a Service Principal with Client Secrets for secure access to manage DNS records in your Azure DNS zones.
<Accordion title="Client Secret Authentication"> To use client secret authentication, ensure your Azure Service Principal has the required permissions to manage DNS records in your Azure DNS Zone.<Note>If you want to configure automatic client secret rotation for this App Connection, you also need to grant either Application.ReadWrite.OwnedBy or Application.ReadWrite.All permissions.</Note>
Prerequisites:

</Step>
<Step title="Assign DNS Zone Contributor Role">
Search for and select the **DNS Zone Contributor** role, then click **Next**.

</Step>
<Step title="Select your Service Principal">
Click **Select members**, search for your App Registration (Service Principal), select it, and click **Select**.

Click **Review + assign** to complete the role assignment.
</Step>

<Tip>
You can find your **Subscription ID** in the Azure Portal under **Subscriptions**. The **Tenant ID** and **Client ID** can be found in your App Registration's **Overview** page.
</Tip>
<Tip>
You can optionally enable **Automatic Credential Rotation** for this connection. See the [Automatic Credential Rotation](#automatic-credential-rotation) section below for details.
</Tip>
Infisical can automatically rotate the Client Secret of your Azure application on a recurring schedule. When enabled, Infisical will immediately generate a new Client Secret on connection creation and revoke the original one, ensuring that no external party retains access using the credentials you provided.
<Steps> <Step title="Locate the Key ID of your Client Secret"> Before enabling rotation, you'll need the **Key ID** of the Client Secret you are using to authenticate. Navigate to your App Registration in the Azure Portal, then go to **Certificates & secrets**. Copy the **Secret ID** (Key ID) of the secret you are providing to Infisical. 
</Step>
<Step title="Enable Automatic Credential Rotation">
When creating or editing your connection, toggle on the **Automatic Credential Rotation** switch.

</Step>
<Step title="Provide the Client Secret Key ID">
Enter the **Key ID** you copied in the previous step into the **Client Secret Key ID** field. Infisical uses this to revoke your original secret after generating a new one.

</Step>
<Step title="Configure the Rotation Schedule">
Set the **Rotation Interval** (in days) to define how often the credential should be rotated, and set **Rotate At** to the local time of day at which the rotation should occur.
- **Rotation Interval** - How many days between each rotation.
- **Rotate At** - The local time of day at which the rotation will be triggered.

</Step>