> For the complete documentation index, see [llms.txt](https://docs.nannyml.com/cloud/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nannyml.com/cloud/v0.20.2/deployment/azure/azure-managed-application/enabling-access-to-storage.md).

# Enabling access to storage

How to ensure NannyML can access data stored in Azure Storage

## Using role assignments

As a part of the deployment process, NannyML Cloud creates a managed identity aptly called **nannyml**.&#x20;

By granting that managed identity the correct roles and permissions, you can have the NannyML Cloud instance read data from a storage container!<br>

### Setting permissions on your storage account

1. Navigate to your storage account using the Azure portal. In this example, we have a storage account with a container called **model-monitoring.** The access level has been set to private.\
   \
   There are three files present, representing reference data, analysis data, and target data.

2. Navigate to the **Access Control (IAM)** pane.<br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FtGyAw0VanmwcT6tJqX0g%2Fimage.png?alt=media&amp;token=0731e070-608d-425b-820c-290e907d7b4a" alt=""><figcaption><p>Accessing the access control settings for our storage container</p></figcaption></figure>

3. Now click the **Add role assignment** button in the bottom left corner.<br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FH5pE1qpjY1GXCTfjhz9I%2Fimage.png?alt=media&amp;token=8617d40c-3008-4a5c-867d-0efb50985f95" alt=""><figcaption><p>Navigating to the role assignment screen</p></figcaption></figure>

4. This window will give you a very long overview of available roles. You can select any applicable role here, but something like **Blob Data Reader** should give sufficient permissions to read the data in this storage container.\
   \
   Search for the role using the search bar, select it and hit the **Next** button in the bottom left corner.\ <br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FqCZp2CVcmQa7DEniPX5K%2Fimage.png?alt=media&amp;token=216331c3-4672-4ac3-b70b-0350df7c6112" alt=""><figcaption><p>Selecting a role to assign</p></figcaption></figure>

5. Now you'll select the member to assign the role to. In this case you'll assign it to a **managed identity**, so select that option. Then hit the **+ Select members** link to open up the search pane.\ <br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FqVoed0rFkokaB0aLplRA%2Fimage.png?alt=media&amp;token=c4081ba0-3370-4487-b41f-405d36269b2a" alt=""><figcaption><p>This is the managed identity you're looking for</p></figcaption></figure>

6. In the search pane, first, select the subscription under which the NannyML Cloud managed application was deployed.\
   \
   In the **Managed identity** dropdown, select the **User-assigned managed identity** option. \
   \
   Finally, in the search bar under the **Select** header, filter for **nannyml** and select the correct option.<br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2F9AtnZXhYHHrdliFUe3Zn%2Fimage.png?alt=media&amp;token=74d22f77-ec5d-419f-b2ac-45d0aa7a4bf9" alt=""><figcaption><p>Searching for the correct managed identity</p></figcaption></figure>

7. Confirm the selected member and hit the **Select** button.\ <br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FsEg59FqNW7JrksRQn3dp%2Fimage.png?alt=media&amp;token=0caaae44-a695-42d2-ab37-170b760c7f83" alt=""><figcaption><p>Confirming once more</p></figcaption></figure>

8. Now click the **Review + assign** button in the bottom left to create the role assignment.

<figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FbsgXzAhct2XKT42RNkLT%2Fimage.png?alt=media&amp;token=53c4a6c7-9ab4-463c-a922-560340317c7b" alt=""><figcaption><p>Finally, let's assign the role!</p></figcaption></figure>

### Setting up the data source in NannyML Cloud

Now you can use the details of the storage container to access your data within NannyML cloud.

1. Set up a new model in NannyML Cloud. Select the **Upload via Azure Blob Storage** option.<br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FbRGgavfbmV4GssGCT6MY%2Fimage.png?alt=media&amp;token=30264708-475c-4ef2-86b8-1eadd5bae090" alt=""><figcaption><p>Using Azure Blob Storage</p></figcaption></figure>

2. Now provide the details about the storage container we've just tweaked the access control for. \
   Note that we don't have to provide any kind of authentication token or key.<br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FHdhydmxeczG687Q09tKv%2Fimage.png?alt=media&amp;token=f6f0278c-5707-4a7b-b523-29c39eebb8ac" alt=""><figcaption><p>Look mom, no credentials!</p></figcaption></figure>

3. We now have access to the file!\ <br>

   <figure><img src="https://2363051145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWcs3xQupCdtvmF6k2Sun%2Fuploads%2FC7Nl2wc0CpfPs48ajVnr%2Fimage.png?alt=media&amp;token=bc676b9f-5208-4184-b449-76b321a0cf80" alt=""><figcaption><p>All file details are available!</p></figcaption></figure>
