iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To set up Azure for a new project, create a subscription through Subscriptions > Add, create a resource group through Resource groups > Create, then add a directory identity through Microsoft Entra ID > Users > New user. Subscription creation depends on your billing agreement and billing permissions; creating an Entra user does not automatically give that person access to Azure resources.
Before you start: check your billing agreement and permissions
An Azure subscription is a billing and resource-management scope. It contains resource groups and is associated with one Microsoft Entra tenant, which supplies identities used to authenticate and authorize access. Your billing agreement determines which subscription-creation form and permissions apply.
| Billing agreement | Permission Microsoft lists | Fields in the portal flow |
|---|---|---|
| Microsoft Customer Agreement (MCA) | Owner or Contributor on the invoice section, billing profile, or billing account; alternatively, Azure subscription creator on the invoice section. | Billing account, billing profile, invoice section, Azure plan, subscription directory, and owners. Tags are optional. |
| Enterprise Agreement (EA) | Enterprise Administrator or Account Owner on the enrollment account. | Billing account, enrollment account, offer type, directory, and subscription owners. |
These are distinct workflows, not interchangeable versions of one universal form. Use the route that matches your billing account and the labels currently shown in your portal. See Microsoft’s MCA subscription instructions and EA subscription instructions.
For an MCA subscription request intended for another tenant, the recipient must accept the request before the subscription is created. This is a separate cross-tenant path; see Microsoft’s instructions for requesting an MCA subscription.
#1 Best Overall
Create the Azure subscription
- Sign in to the Azure portal and open Subscriptions.
- Select Add.
- Enter a subscription name and complete the billing fields for your agreement. For MCA, select the billing account, billing profile, invoice section, and Azure plan. For EA, select the billing account, enrollment account, and offer type.
- Open the advanced settings and confirm the subscription directory. Choose the intended subscription owners. In these MCA and EA flows, owners must be users or service principals in the selected directory; guests from another directory cannot be selected as owners.
- Add tags if they will help you organize or identify the subscription, review the selections, and submit after validation succeeds.
In the MCA flow for the current tenant, the subscription is created immediately. For the cross-tenant MCA request flow, the recipient must accept first. Portal labels and required fields may differ according to the billing account. Microsoft’s MCA guide and EA guide describe their respective paths.
Create a resource group inside the subscription
- In the Azure portal, open Resource groups and select Create.
- Choose the subscription that should contain the group.
- Enter a resource-group name and select a location.
- Select Review + Create, check the settings, then select Create.
- Refresh the resource-group list or open the group from the creation notification.
A resource group organizes related Azure resources. Its location applies to the resource-group metadata; it does not force every resource in the group to be deployed in that region. For the portal workflow, see Microsoft’s resource-group management guide.
Create a Microsoft Entra ID user
The following portal steps create a user directly in the directory. They are not the workflow for an account synchronized from on-premises or for inviting an external guest.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute- Sign in to the Azure portal with a Global Administrator or User Administrator account.
- Search for and open Microsoft Entra ID.
- Select Users, then New user.
- Enter the person’s name and user name. Add any needed group, directory-role, or job information.
- Record the generated initial password and provide it to the user through your organization’s secure process.
- Select Create.
Microsoft’s user-creation troubleshooting guide documents the portal procedure and required roles.
Rank #3
Assign Azure resource access separately
A new Entra user is an identity record, not an Azure resource permission. The user must exist in the directory associated with the subscription, and an Azure role assignment is needed to access the subscription or its resources. Use Azure role-based access control (Azure RBAC) to assign access at the narrowest suitable scope: subscription, resource group, or individual resource. Microsoft Entra roles govern directory objects; Azure roles govern Azure resources. See Microsoft’s guide to adding users and assigning access to an Azure subscription.
Resolve common setup problems
You cannot add a subscription
Check which billing agreement applies and whether your account has the necessary billing role on the relevant billing account, profile, invoice section, or enrollment account. MCA and EA use different permissions and portal fields; consult the matching MCA or EA instructions.
Rank #4
The directory you want is not available
Confirm that the subscription should be associated with that tenant. A subscription trusts one Microsoft Entra tenant at a time, although a tenant can be associated with multiple subscriptions; subscriptions can also be moved between tenants. Microsoft explains the relationship in its guide to adding an existing subscription to a tenant.
The new user cannot see subscription resources
Check that the user belongs to the directory associated with the subscription and has an Azure RBAC assignment at the scope needed for the task. Directory membership alone does not grant resource access.
Best Value
You are following an older pay-as-you-go signup instruction
Microsoft’s EA guidance says a Microsoft Online Services Program (MOSP, pay-as-you-go) subscription can be started in the portal and completed at signup.azure.com, while its MCA guidance says MOSP billing accounts can no longer add subscriptions at that address. Because the directions differ by account type, identify your billing-account type and follow its current official instructions rather than treating signup.azure.com as a universal route. See the respective EA and MCA pages.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Can you create the subscription with Azure CLI?
Microsoft documents an az account create command, but the cited command reference marks it as preview and its documented form requires EA-specific parameters. It is not a general replacement for the portal steps above. Check the current Azure CLI account reference and confirm that its offer and parameters match your agreement before using it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

