DNSMentor

Supported provider

Azure DNS DNS, in the same place as everything else.

Does DNSMentor support Azure DNS?

Yes. DNSMentor manages Azure DNS DNS through its API, showing its zones alongside the other 25 supported providers in a single estate view. Every Azure DNS change goes through the same 56 pre-flight checks, approval policy, independent verification and tamper-evident audit trail as every other provider.

Connecting Azure DNS

  1. Create the credential in Azure DNS Azure portal → Microsoft Entra ID → Overview → 'Directory (tenant) ID'. It is a GUID, and it is the customer's tenant, not yours — an MSP managing several customers needs one connection per tenant.
  2. Add the connection in DNSMentor Go to Admin → Providers & API keys, choose Azure DNS, and paste the credential. DNSMentor stores it encrypted and strips it from every log and export.
  3. Sync the estate DNSMentor discovers every zone the Azure DNS account holds and imports every record in them. This is a read operation — nothing is written to any zone.
  4. Group by client and start working Assign the imported domains to client portfolios, and the estate view, health scoring, checks and audit trail apply from that point on.

What Azure DNS asks you for

The exact fields DNSMentor needs, and where in Azure DNS to create them. Every secret is encrypted at rest and stripped by name from logs, exports and the audit trail.

Directory (tenant) ID not secret

Azure portal → Microsoft Entra ID → Overview → 'Directory (tenant) ID'. It is a GUID, and it is the customer's tenant, not yours — an MSP managing several customers needs one connection per tenant.

Application (client) ID not secret

Azure portal → Microsoft Entra ID → App registrations → your app → Overview → 'Application (client) ID'. Register one application for DNSMentor rather than reusing an app that already has other permissions.

Client secret value secret

Azure portal → Microsoft Entra ID → App registrations → your app → Certificates & secrets → New client secret. Copy the 'Value' column, not 'Secret ID' — the value is shown once and never again. Secrets expire (24 months at most), and DNS changes will start failing on the expiry date with no warning, so diarise it.

Subscription ID not secret

Azure portal → Subscriptions → the subscription holding the DNS zones → 'Subscription ID'. The app registration needs the 'DNS Zone Contributor' role assigned to it on that subscription, or on just the resource groups holding the zones you want DNSMentor to manage — scoping it to those resource groups is the safer choice and works fully.

The sharp edge in Azure DNS's API

Every provider API has one behaviour that catches integrations out. This is Azure DNS's, and DNSMentor's adapter is written around it — the sort of thing you would otherwise discover during a migration.

The Entra client-credentials exchange, then that record sets round-trip with their `@` apex.

What you get on top of the Azure DNS console

One estate, not one provider

Azure DNS zones sit beside every other provider your clients came with, grouped by the client who pays for them and searchable in one place.

56 checks before apply

The Azure DNS console will accept a second SPF record or an MX pointing at an address without comment. DNSMentor will not.

Approval and audit

A second pair of eyes where policy requires it, and a hash-chained record of who changed what — neither of which a provider console offers.

Azure DNS questions

Can I manage Azure DNS DNS alongside my other providers?

Yes. DNSMentor connects Azure DNS through its API and shows its zones in the same estate view as every other provider you connect — 26 are supported in total. Your engineers work in one interface instead of switching between provider portals, and the same checks, approval policy and audit trail apply regardless of which provider a domain happens to be with.

What credentials does DNSMentor need for Azure DNS?

DNSMentor needs Directory (tenant) ID, Application (client) ID, Client secret value, Subscription ID for Azure DNS. Azure portal → Microsoft Entra ID → Overview → 'Directory (tenant) ID'. It is a GUID, and it is the customer's tenant, not yours — an MSP managing several customers needs one connection per tenant.

Does DNSMentor move my zones away from Azure DNS?

No. Your zones stay hosted at Azure DNS and remain authoritative there. DNSMentor reads and writes through the Azure DNS API, so nothing about your resolution path changes, and if you stop using DNSMentor the zones carry on exactly as they are.

Does DNSMentor validate Azure DNS changes before applying them?

Yes. All 56 checks run against the zone as it would exist after the change, whichever provider hosts it. The change is then simulated, routed for approval if policy requires it, written through the Azure DNS API after re-reading live state, and independently verified in public DNS afterwards.

Other providers DNSMentor manages

Connect Azure DNS in about five minutes.

Paste one credential, sync, and see every zone in that account. It is a read operation — nothing is written until somebody presses apply.

No card. No trial clock. UK-hosted, and we will tell you which providers we have actually proven before you ask.

Last updated