When you onboard an Azure subscription, Druva automatically creates backend resources to manage your data protection. These resources include:
A Resource Group
Two Key Vaults (primary and secondary)
A user-assigned Managed Identity
Many organizations use Azure Policy to enforce strict resource-tagging strategies. If your target subscription requires specific tags during resource creation, Azure will block Druva from deploying these backend components, causing onboarding to fail.
To ensure a seamless deployment without changing your security or governance posture, you can supply your required organizational tags before onboarding. Druva automatically detects these tags and applies them to all created resources.
Prerequisites
Before starting onboarding, ensure you have the following access:
You must have the Owner or User Access Administrator role on the target Azure subscription.
Tag formatting
Druva looks for a specific tag on your Azure subscription to identify the tags you want to apply.
Tag Name: DRUVA_CUSTOM_TAGS
Tag Value: Enter your tags as comma-separated key-value pairs using the format Key:Value.
Important! Do not include spaces before or after the colons or commas.
Correct: Environment:Production,CostCenter:1024
Incorrect: Environment : Production , CostCenter : 1024
Step 1: Add the tag to your Azure subscription
Sign in to the Azure portal.
Search for and select Subscriptions.
Select the subscription you want to onboard to Druva.
On the left menu, select Tags.
In the Name field, type DRUVA_CUSTOM_TAGS.
In the Value field, type your comma-separated tags (for example: Environment:Production,CostCenter:1024).
βSelect Apply.
β
Step 2: Complete onboarding in Druva
Once the subscription tag is applied in Azure, proceed to the Enterprise Workloads Management Console and complete your subscription onboarding workflow. Druva will automatically read the DRUVA_CUSTOM_TAGS value and apply your individual keys and values to the newly deployed infrastructure.
Tagged resources
Druva applies tags to the following resources created during onboarding:
Resource Group
Key Vaults
Managed Identity
Limitations
Be mindful of the following limitations when configuring tag propagation:
Character limits: The total string length within the DRUVA_CUSTOM_TAGS value cannot exceed 256 characters.
Special characters: Tag keys and values can only contain alphanumeric characters, spaces, and the following symbols: +, -, =, ., _, :.
Onboarding updates: If you modify your subscription tags in the Azure portal after initial onboarding, Druva does not automatically sync those changes to existing resources. The new tags only apply to resources deployed after the modification.
