Request New Entra Applications
Collect business purpose, responsible owners, metadata, credential requirements, and initial API access before AZExecute provisions the application registration and service principal.
Application Governance + ACME Certificates + Hybrid Automation
Govern the Entra application lifecycle, run end-to-end ACME certificate automation, and turn repeatable IT operations into approved self-service. AZExecute collects the right information, routes every decision, executes across cloud and on-premises systems, and records the complete result.
Built For Governed Operations
Replace Common IT Requests
Collect business purpose, responsible owners, metadata, credential requirements, and initial API access before AZExecute provisions the application registration and service principal.
Handle application roles, delegated permissions, Microsoft Graph access, justification, owner approval, tenant approval, and consent in one visible request flow.
Publish approved identity, user, group, and directory updates as guided operations instead of relying on free-form tickets, scripts, or broad administrative access.
Turn repeatable Azure, server, service, virtual machine, DNS, file, and connected-system actions into controlled self-service operations.
Issue and renew certificates through Let's Encrypt, GlobalSign Atlas, DigiCert CertCentral, or custom ACME v2 services, with automated DNS validation and post-renewal deployment.
Let support staff run approved diagnostics and remediation with validated inputs while administrators control access, approvals, and the underlying automation.
From Request To Recorded Result
Capability 1
Replace a technical ticket with a form designed for the operation. Required fields, validation, protected values, and live directory or infrastructure lookups collect complete information the first time.
Capability 2
Publish the request only to the right users and groups. Route sensitive application, permission, identity, and infrastructure changes to the responsible owner or administrator before execution.
Capability 3
Create the app registration and service principal after approval, retain business metadata and ownership, and handle internal or external API access through the correct consent path.
Capability 4
Run reusable workflows across Azure, Azure Arc, on-premises agents, scripts, runbooks, pipelines, directories, DNS, certificates, and connected platforms from the same request.
Capability 5
Use SignalR-powered agents and live execution updates to show current status, console output, decisions, and results without waiting for a ticket to be manually updated.
Capability 6
Keep the request, approval, execution history, output, and result together. Let events start remediation, create an incident, notify owners, or trigger the next workflow automatically.
Three Core Capabilities
Use each capability independently or connect them: provision an application, issue its certificate, and let the automation engine deploy and rotate it wherever it is needed.
Give teams a guided way to request applications and permissions while administrators retain ownership of policy, approval, provisioning, credentials, consent, and lifecycle decisions.
Replace certificate spreadsheets and manual renewal runbooks with governed accounts, reusable templates, automated DNS-01 validation, scheduled renewal, and deployment workflows.
Compose reusable automation from native steps, scripts, agents, runbooks, pipelines, events, and connected systems—then publish it as controlled self-service.
Start With One High-Volume Request
Step 1
Sign in with Entra ID, complete tenant setup, and connect the Azure, agent, directory, certificate, or integration endpoints needed for the first operation.
Step 2
Start with a high-volume application, permission, identity, certificate, DNS, or infrastructure request that currently requires manual administrator work.
Step 3
Choose the required input, responsible approvers, permitted users, workflow steps, notifications, and follow-up while keeping existing identity and access boundaries.
Step 4
Release the operation as self-service, follow every run through live status and structured history, then reuse the same controls for the next request.

For Requesters, Support, And Administrators
Requesters get clear forms and visible progress. Support staff can start approved operations without scripts or broad privileges. Administrators define the inputs, approvals, access, and automation once, then retain control of every execution.
Which Request Should You Stop Handling Manually?
Start with application governance, ACME certificate automation, or one high-volume infrastructure operation. Keep your existing access model while AZExecute adds guided input, approval, automated execution, live status, and complete history.