> For the complete documentation index, see [llms.txt](https://docs.parallels.com/landing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.parallels.com/landing/pd-ag/preparing-virtual-machines-for-deployment-and-securing-them/golden-images/distributing-golden-images-from-your-companys-azure-storage.md).

# Distributing Golden Images from Your Company's Azure Storage

If your corporate policies require hosting your company's Golden Images behind tightly controlled, authenticated access, but you would still like to keep the installation/deployment process seamless for the users, you may want to use the integration between [Parallels Management Portal](/landing/pd-ag/getting-started/configuring-golden-images-and-policies-in-the-management-portal.md) and Microsoft Azure Storage that became available in June 2026.

{% hint style="info" %}
**Note**: This method of distribution is not supported in mainland China and requires Parallels Desktop version 26.4 or newer.
{% endhint %}

### How the integration works

Whenever end users request an installation from your company's Golden Image, their copy of Parallels Desktop receives a short-lived link from the Parallels backend, which in turn fetches the file directly from your company's Azure Storage.

The files remain in your organization's Azure tenant. Parallels Management Portal only holds the reference and the metadata supplied when the file is registered, and authentication with Azure is handled server-to-server using delegated permissions you grant during setup. Download links expire automatically within minutes of being issued.

Your end users never see the storage URL, never enter Azure credentials, and are never prompted to sign in to anything. From their perspective, downloading a Golden Image works exactly as it does today.

### Setting up the integration

To set up the integration, you will need:

1. An Azure Storage account with at least one container holding the files you intend to distribute.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong>: The implementation of this feature relies on Parallels backend <strong>only</strong> for authentication and token generation, while role assignments and issuing secure, short-lived download tokens to authorized devices are handled by Entra ID.</p><p>Therefore, you do <strong>NOT</strong> need to enable <strong>Anonymous read access</strong> on your Azure Storage account or container. However, <strong>Public network access</strong> needs to be enabled.</p></div>
2. An Entra ID account with privileges to grant admin consent to a third-party application in your tenant and to assign storage roles.

{% hint style="warning" %}
**Attention**: The integration can be disabled at any time by revoking admin consent for Parallels Desktop in Microsoft Entra ID.
{% endhint %}

To commence the setup process, click on the **Settings** icon in the bottom-left of your [Parallels Management Portal](/landing/pd-ag/getting-started/configuring-golden-images-and-policies-in-the-management-portal.md) page, switch to the **Integrations** tab, locate the `Azure Storage` card in the **Storage Providers** section, and click **Connect**, launching the integration setup wizard.

<figure><img src="https://3321480841-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKtRUprxh035S97pZeygw%2Fuploads%2FM0ATKRLh7PhAGkum427C%2FPDA-2074_PMP-Settings-Integrations.png?alt=media&amp;token=10f390b7-1506-4de3-a49f-69df3eaf5a16" alt="" width="563"><figcaption></figcaption></figure>

The setup wizard guides you through four sequential steps: granting admin consent, assigning storage roles, configuring CORS, and verifying access to a specific container.

Each step must be completed before the next one becomes available, and your progress is saved automatically, enabling you to close the wizard and return later.

#### Step 1: Granting admin consent

In this first step, you authorize Parallels Desktop as a third-party application in your Entra ID tenant. This is a one-time action per [tenant](https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/azure-ad-define), not per container.

<figure><img src="https://3321480841-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKtRUprxh035S97pZeygw%2Fuploads%2FXgr0JP7H9SxISXlRyQ8B%2FPDA-2074_Azure-Storage-Connect.png?alt=media&amp;token=02b0ea6a-6c08-4efb-8c82-a4e2e0f3132f" alt=""><figcaption></figcaption></figure>

1. Click **Authorize via Microsoft**. You'll be redirected to a standard Microsoft sign-in screen.
2. Sign in with an account that has permissions to grant admin consent in your tenant.
3. Review the requested permissions and click **Accept**.

When Microsoft redirects you back to the Portal, **Step 1** is marked complete and [**Step 2**](#step-2-assign-storage-roles) becomes active. If authorization fails or is cancelled, the wizard shows an inline error, and you can retry. If the failure is persistent, check with your Entra tenant's designated administrator, as admin consent is sometimes restricted to specific accounts by policy.

#### Step 2: Assign storage roles

For Parallels Desktop to read files from your container and to mint download links on the fly, two Azure roles must be assigned to the Parallels Desktop application: **Storage Blob Delegator** and **Storage Blob Data Reader**. Each is assigned at a different level of your Azure resource hierarchy.

1. Click **Assign in Azure Storage** to open the Azure Storage center, which lists all storage accounts in your subscription. Open the storage account you plan to use for Golden Image distribution.
2. Assign **Storage Blob Delegator** at the storage account level:
   1. From the storage account sidebar (without navigating into any specific container), open **Access control (IAM)**.
   2. Click **+ Add** > **Add role assignment**.<br>

      <figure><img src="https://3321480841-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKtRUprxh035S97pZeygw%2Fuploads%2FLwMb2Wg2BHlxqVIZtrbh%2FPDA-2074_Azure-Storage-Account-Role-Assignment.png?alt=media&amp;token=115ca6a5-0d11-40f2-8bba-9e70ba4b39dc" alt="" width="563"><figcaption></figcaption></figure>
   3. Search for **Storage Blob Delegator** and select it. Click **Next**.<br>

      <figure><img src="https://3321480841-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKtRUprxh035S97pZeygw%2Fuploads%2F8a0FcTXwJNI8SAyZXGv3%2FPDA-2074_Azure-Storage-Account-Role-Blob-Delegator.png?alt=media&amp;token=239b2702-4f2d-4dc3-9a38-f68335e40c7b" alt="" width="563"><figcaption></figcaption></figure>
   4. Click **+ Select members**, find and select `Parallels Desktop`, then click **Select** and **Next**.<br>

      <figure><img src="https://3321480841-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKtRUprxh035S97pZeygw%2Fuploads%2F2qELCQ4JZBpjgPZHJQx0%2FPDA-2473_PD-App-Azure-IAM-2.png?alt=media&amp;token=530decc2-c8ff-4de4-98a6-9121e10c8385" alt=""><figcaption></figcaption></figure>
   5. Click **Review + assign**.
3. Assign **Storage Blob Data Reader** at the container level:
   1. From the storage account, navigate into the specific container you plan to use.
   2. From the container sidebar, open **Access control (IAM)**.
   3. Click **+ Add** > **Add role assignment**.
   4. Search for **Storage Blob Data Reader** and select it. Click **Next**.
   5. Click **+ Select members**, find and select `Parallels Desktop`, then click **Select** and **Next**.
   6. Click **Review + assign**.

{% hint style="info" %}
**Note**: Azure role assignments can take up to 30 minutes to propagate. If verification in [**Step 4**](#step-4-verify-access-to-a-container) fails immediately after assigning roles, wait a few minutes and try again before troubleshooting elsewhere.
{% endhint %}

When both roles are assigned, return to the wizard and click **Mark as complete**.

#### Step 3: Configure CORS

This step allows your browser, while you're signed in to Parallels Management Portal, to list files in your container — for example, when you're picking a file to attach to a golden image record. Without a CORS rule, file selection from the Portal UI won't work, although end-user downloads to Parallels Desktop will still function.

To add the CORS rule, click **Configure in Azure Storage**. This opens the Azure Storage center; select the storage account you're using for the integration, then navigate to **Settings** > **Resource sharing (CORS)** and in the **Blob service tab** add a new rule with the following values:<br>

<figure><img src="https://3321480841-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKtRUprxh035S97pZeygw%2Fuploads%2FXhA1kynk53FkHBj6dS2Y%2FPDA-2074_Azure-Storage-Account-CORS-Settings.png?alt=media&amp;token=c1c03bf1-6000-4cc2-b31e-7619ebe1c2f0" alt=""><figcaption></figcaption></figure>

1. Allowed origins: `https://desktopadmin.parallels.com`
2. Allowed methods: `GET`
3. Max age: `86400`

Save the rule, then return to the wizard and click **Mark as complete**.

#### Step 4: Verify access to a container

In the final step, you point Parallels Management Portal at a specific container and confirm that everything is wired up correctly.

1. **Container link**: The full URL of the container, e.g., `https://yourstorage.blob.core.windows.net/golden-images`. You can find this URL in your Azure portal by navigating to the container and copying the URL from its **Properties** page.
2. \[OPTIONAL] **Container name**: A friendly name for this container as shown in the Portal, e.g., `Windows 11 images for accountants`. If left empty, the name will be taken from the provided container URL.
3. Click **Verify Configuration**.

The verification probes the container with the credentials and permissions you set up in the previous steps. If everything checks out, the integration is set to active and you can start using it. Otherwise, the wizard returns you to the relevant earlier step with an explanation of what went wrong — missing roles send you back to [**Step 2**](#step-2-assign-storage-roles), an incorrect CORS rule to [**Step 3**](#step-3-configure-cors), and an authorization problem to [**Step 1**](#step-1-granting-admin-consent).

Once the integration is active, the Azure Storage card in the Integrations tab shows the connected container and the time of the most recent successful verification.

### Using a connected container

With the integration active, you can browse your container directly when creating or editing a [Golden Image](/landing/pd-ag/preparing-virtual-machines-for-deployment-and-securing-them/golden-images.md#standard-image-based-deployment) record.

1. In the Golden Image record, locate the **Image file** field.
2. Click **Browse storage**. The Portal opens a file picker scoped to your connected container.
3. Select the appropriate file.
4. Supply the [SHA-256 checksum](/landing/pd-ag/preparing-virtual-machines-for-deployment-and-securing-them/golden-images/creating-and-uploading-virtual-machine-images.md) of the file. The Portal does not compute checksums for you; the value should match what your build pipeline records when the file is uploaded to the container.
5. Save the Golden Image record.

When an end user's Parallels Desktop downloads this golden image, it requests a short-lived signed download URL for the specific file from the Portal. The Portal issues the URL only if the user's copy of Parallels Desktop is activated with your company's license. The user is never prompted to sign in, never provides credentials, and never sees the storage URL.

### Managing the integration

You can manage your integration at any time under **Settings** > **Integrations** > **Azure Storage** > **Manage**. You can do one of the following things:

* Rename a container to give it a friendlier display name in the Portal. The change is internal to the Portal and does not affect the container in Azure.
* Remove a container to disconnect it from the Portal.

{% hint style="info" %}
**Note**: Once you remove a container, the Portal can no longer issue download links for files in it, so any Golden Images referencing those files become unavailable for new deployments.\
\
Reconnect the container or move the files elsewhere to restore availability. Downloads already in progress continue until their existing download link expires.
{% endhint %}

* Reset the integration to fully disconnect Parallels Management Portal from your Azure tenant. This deletes the container record and the file references on the Portal side.

{% hint style="warning" %}
**Attention**: Resetting the integration on the Portal side does not affect your Azure tenant. To complete the disconnection cleanly and avoid leaving behind orphaned role assignments, perform the following in your Azure portal, in this order:

1. Remove the **Storage Blob Data Reader** role assignment from the container's **Access control (IAM)**.
2. Remove the **Storage Blob Delegator** role assignment from the storage account's **Access control (IAM)**.
3. Remove Parallels Desktop from **Microsoft Entra ID** > **Enterprise Applications**.
   {% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.parallels.com/landing/pd-ag/preparing-virtual-machines-for-deployment-and-securing-them/golden-images/distributing-golden-images-from-your-companys-azure-storage.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
