BETA Free plan, no card required.

Sign in first. Connect after.

Signing in creates your account and shows you the walkthrough. It gives Kronikl no access to your Azure environment at all — that is a separate step, on a later screen, and your own administrator approves it.

Sign in with Microsoft Read the three steps first

Your existing work account · No Kronikl password · Nothing installed in your tenant

What happens after you press it

Three screens, in this order. Only the second one asks your organization for anything, and only the third gives Kronikl anything to read.

1

Microsoft asks who you are

Your ordinary work or school account, on Microsoft's own sign-in page. There is no Kronikl password to choose, and the first sign-in creates your organization from the tenant you signed in from.

2

Your administrator approves the read permissions

The five below, on Microsoft's own consent screen. This is the step that needs a Global Administrator, and it is the one worth reading before you reach it.

3

You assign the Azure role, with your own credentials

Kronikl cannot grant itself anything. Either you create the assignment in one click — signed in as yourself, spending your own Azure privilege, logged in your Activity Log under your name — or you copy the command and run it wherever you prefer. Until one of those happens, Kronikl can see your directory and none of your resources.

What Kronikl will ask for

A Global Administrator approves these on Microsoft’s own screen, in exactly these words and with no reasons attached. Here are the reasons.

Permission Why we ask
Read directory data Turns an account ID into a person.
Read all directory RBAC settings Shows who holds admin roles.
Read all audit log data Shows why someone activated a role, not just who.
Sign in and read user profile Your name and email, so you can sign in.
Access Azure Resource Manager as organization users Lists the subscriptions you can already see, so you can pick one.
  • Your directory only — resources are step 2.
  • Revoke any time: Entra ID > Enterprise applications > Kronikl > Delete.

Not the person who can approve it?

That is the normal case, and it is better known now than three screens in. You can still sign in and get as far as the consent screen — Kronikl remembers where your tenant actually got to, so whoever holds the rights can pick it up from there rather than starting again.

Sign in with Microsoft What to ask your administrator for

Ready when you are

Sign in with the Microsoft account you already have. Connecting a tenant is the step after, and you approve it yourself.

Sign in with Microsoft Read the security section first