<a id="ccloud-azure-market"></a>

# Get Started with Confluent Cloud on the Azure Marketplace with Pay As You Go

To use Confluent Cloud with pay-as-you-go billing through the Azure Marketplace,
subscribe to the **Confluent Cloud - Pay As You Go** plan in Azure and link or
create a Confluent Cloud organization. With this billing model, you pay only for what
you use and get billed directly through Azure.

If you prefer a usage-based commitment with discounts, see
[Get Started with Confluent Cloud on the Azure Marketplace with Commitments](ccloud-azure-ubb.md#ccloud-azure-market-ubb).



When you sign up through the Azure Marketplace, you can create a new Confluent
organization or link to an existing Confluent Cloud account.

<a id="ccloud-azure-market-prereqs"></a>

## Prerequisites

- An Azure Marketplace account. With Azure Marketplace, you can use Confluent Cloud and
  get billed directly through Azure.

  #### IMPORTANT
  You cannot sign up for Confluent Cloud through a Microsoft Solutions Provider.
- Confluent Cloud currently requires your email address to be unique across all
  organizations. If you already used your Microsoft Entra ID (formerly Azure
  Active Directory) email address to sign up for Confluent Cloud, you must first
  remove yourself as a user from the Confluent Cloud organization where you signed up
  earlier, so you can use your Microsoft Entra email for single sign-on (SSO).
  One option is to invite an alternate email that you own as a user to the old
  organization, and then delete the user associated with your Microsoft Entra
  email from the old organization. This way, you can sign up using SSO. As
  another option, a different user in the old organization can delete your
  Microsoft Entra user ID. To find the email address associated with your
  Microsoft Entra account, follow these steps:
  1. Go to the
     [Azure Active Directory portal](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Overview).
  2. Click the **More Info** link in the **Tenant Information** section.
  3. Click **View profile** under **My feed**. Your Microsoft Entra email
     address appears in the **Identity** section under **User Principal
     Name**. Also check the **Alternate email** entry in the **Contact info**
     section.
- To buy a subscription, sign in to the
  [Azure Marketplace](https://azuremarketplace.microsoft.com/marketplace/).
  You must have permission to purchase, which means you must be the subscription
  owner or you must have contributor permissions. For more information, see
  [Azure Marketplace purchasing](https://learn.microsoft.com/en-us/marketplace/azure-purchasing-invoicing)
  in the Azure documentation.
- Your Azure policy must allow you to provision resources in the region where
  you choose to set up the Confluent resource.
- If you are using Microsoft Entra ID (the default SSO) and you want to enable
  Confluent SSO, a Global Administrator for the tenant must grant you user
  consent. For more information, see
  [Configure how end-users consent to applications](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent)
  in the Azure documentation.

## Subscribe to Confluent Cloud through the Azure Marketplace

1. Navigate to the
   [Azure Marketplace](https://azuremarketplace.microsoft.com/marketplace/)
   and search for “Apache Kafka® on Confluent Cloud.”
2. Find the Confluent Cloud tile and click it.
   ![Confluent Cloud tile in the Azure Marketplace search results.](images/_billing/azure-marketplace-tile.png)
3. Select the **Pay As You Go** plan and click **Subscribe**.
   ![Azure Marketplace Pay As You Go subscribe button.](images/_billing/azure-pay-as-you-go-subscribe.png)
4. Choose the correct subscription and either choose an existing resource group
   or create a new one.
5. In the **Instance Details** section, enter the **Region** where you want to
   launch your Azure resource and choose your **Plan** (**Confluent Cloud - Pay
   As You Go**).

   #### NOTE
   The region you select does not need to match the region where you run your
   Confluent Cloud clusters. Confluent Cloud uses the selected region to store metadata for
   this resource group, and you are not charged for this metadata storage.
6. Under **Confluent Organization details**, choose **Create a new Confluent
   organization** or **Link to an existing organization**. If you link to your
   existing Azure Marketplace subscription, Confluent Cloud prompts you for your account
   credentials.

   ### Create a new Confluent Cloud organization

   Enter the name for your new Confluent organization.
   ![Options to create a new or link an existing Confluent Cloud
   organization in the Azure Marketplace.](images/_billing/create-a-confluent-org.png)

   After you complete the Azure deployment, Confluent creates the new
   organization and links it to your Azure subscription.

   ### Link to an existing Confluent Cloud organization

   1. Click **Link to an existing organization** to navigate to the Confluent Cloud
      login page.
      ![Confluent Cloud organization details in the Azure Marketplace
      with the option to link to an existing organization.](images/_billing/link-existing-confluent-org.png)
   2. Sign in with your existing Confluent Cloud credentials.
   3. On the **Confirm billing updates** page, check each box to confirm that
      you understand the terms of service, billing terms, and SSO settings
      for both sections:
      - **Current billing info** shows the billing information before account
        linking.
      - **Updated billing with Azure** shows the new payment method for the
        account after linking.
        ![Confirm billing updates page with the current billing and
        updated billing sections and consent checkboxes.](images/_billing/azure-confirm-billing-updates.png)
   4. Click **Choose this organization**. After confirmation, the linked
      organization name appears next to **Confluent Organization Name** in
      the Azure portal.

      #### IMPORTANT
      Linking to an existing organization automatically cancels any
      active commit subscription on that organization. Before you link,
      verify that the target organization has no active commit
      subscription.

   Watch the following video for a walkthrough of linking an existing
   Confluent Cloud organization from the Azure Marketplace.
   <iframe width="560" height="315" src="https://www.youtube.com/embed/GiEgQYSq4oc" title="How to Link Your Confluent Cloud Account to Azure for Centralized Billing" frameborder="0" allow="accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" loading="lazy" allowfullscreen></iframe>
7. Optionally enter **Tags** for your project.
8. Click **Review and create**.
9. After organization validation completes, you can create the resource. Review
   the terms of your plan and click **Create**.
   ![Review and create page for the Confluent resource in the Azure
   portal.](images/_billing/azure-create-org-review-create.png)

   Your deployment starts. This could take up to a minute.
   ![Azure deployment in progress message.](images/_billing/azure-deployment-in-progress.png)
10. After Azure deploys your resources, a confirmation message appears. Click **Go
    to resource** to view the deployed resource on the Azure portal.
    ![Deployed Confluent resource page in the Azure portal.](images/_billing/azure-resource-deployed.png)
11. Click the **Confluent SSO URL** link or the **Launch** button to sign in to
    Confluent Cloud using your Microsoft Entra account. You might be asked to choose
    an account for SSO.

    If you want to enable Confluent SSO instead of the default Microsoft
    Entra ID SSO, a Global Administrator for the tenant must grant you user
    consent.
12. If you are using Microsoft Entra ID (the default SSO), click **Accept** to
    grant permission for Confluent Cloud. You are signed in.
    ![Microsoft SSO permissions requested dialog.](images/_billing/microsoft-sso-permissions-requested.png)

    You can now manage your resources on Confluent Cloud.
13. You can invite more users to your organization by creating a Confluent Cloud
    account. Use a Microsoft Entra user, or a non-SSO user with an email
    address and password. For more information, see [Add a local user
    account](../security/authenticate/user-identities/user-accounts/manage-local-user-accounts.md#add-local-user-console) and [Add an SSO user](../security/authenticate/user-identities/user-accounts/manage-sso-user-accounts.md#add-an-sso-user).

    #### IMPORTANT
    Microsoft Entra ID is the default SSO identity provider when you
    subscribe to Confluent Cloud through the Azure Marketplace. To change your SSO
    identity provider, see [Use Single Sign-On with Azure Marketplace on Confluent Cloud](../security/authenticate/user-identities/user-idps/sso/az-oidc-sso.md#az-oidc-sso) and [Switch from Azure Marketplace SSO to SAML SSO](../security/authenticate/user-identities/user-idps/sso/az-oidc-sso.md#edit-sso-settings).

## Manage Confluent Cloud from Azure

After you create or link a Confluent Cloud organization, you can manage access and
resources:

- Manage Kafka clusters in Confluent Cloud. For more information, see
  [Create a Kafka Cluster](../clusters/create-cluster.md#cloud-create-cluster) in the Confluent Cloud documentation.
- Enable single sign-on (SSO) for your organization. For more information, see
  [Single sign-on](https://learn.microsoft.com/en-us/azure/partner-solutions/apache-kafka-confluent-cloud/manage?tabs=azure-portal)
  in the Azure documentation.
- Enable just-in-time (JIT) user provisioning to automatically create Confluent Cloud
  user accounts in Azure. For more information, see
  [Support for Azure Marketplace organizations](../security/authenticate/user-identities/user-idps/sso/jit-user-provisioning.md#jit-user-provisioning-az).
- Add users and assign permissions to your Confluent Cloud organization from within
  Azure. For more information, see
  [Use Confluent Access Management in the Azure Portal](https://learn.microsoft.com/en-us/azure/partner-solutions/apache-kafka-confluent-cloud/manage-access)
  in the Azure documentation.
- Use Azure Functions and Azure Cosmos DB connectors. For more information, see
  [Connect a Confluent Organization to Azure Compute Services](https://learn.microsoft.com/en-us/azure/partner-solutions/apache-kafka-confluent-cloud/add-connectors)
  in the Azure documentation.
- Manage Confluent connectors from the Azure portal. For more information, see
  [Use Confluent Connectors in Azure (preview)](https://learn.microsoft.com/en-us/azure/partner-solutions/apache-kafka-confluent-cloud/add-confluent-connectors)
  in the Azure documentation.
- Use the Azure CLI to manage your Confluent Cloud organization. For more information,
  see [az confluent command reference](https://learn.microsoft.com/en-us/cli/azure/confluent?view=azure-cli-latest)
  in the Azure documentation.



For more information about managing and using Confluent Cloud resources with Azure, see
[Apache Kafka & Apache Flink on Confluent Cloud, an Azure Native Integrations service](https://learn.microsoft.com/en-us/azure/partner-solutions/apache-kafka-confluent-cloud/)
in the Azure documentation.

#### IMPORTANT
To manage Confluent Cloud users from within Azure, your Azure user account must be a
member of at least the Azure RBAC Contributor role, in the Confluent Cloud
organization linked to the Azure account, and using the same email address on
Confluent Cloud as in Azure. For more information, see the
[Azure documentation](https://learn.microsoft.com/en-us/azure/partner-solutions/apache-kafka-confluent-cloud/manage-access#prerequisites).

## Next steps

To create a Kafka cluster and start producing and consuming messages, see the
[Quick Start for Confluent Cloud](../get-started/index.md#cloud-quickstart).

For help with sign-up, linking, and subscription issues, see
[Troubleshoot Confluent Cloud Billing](troubleshoot-billing.md#cloud-billing-troubleshoot).
