> For the complete documentation index, see [llms.txt](https://docs.inogic.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.inogic.com/next-best-action/configuration/configure-nba-ai-ml-engine.md).

# Configure NBA AI/ML Engine

Follow the steps below to retrieve the required configuration details from the NBA Engine deployment in Azure:

* Navigate to **Managed Applications** and open **NBAEngine**.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FmsNXQNtc6QmaXD7A13vE%2Fnba%20engine%20config%201.png?alt=media&amp;token=7ded5db2-8993-4d54-acd4-f860115b19b8" alt=""><figcaption></figcaption></figure>

* On the **Overview** page, click **Managed Resource Group**.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FqzToP0XW3qcI5zitgsxB%2Fnba%20engine%20config%202.png?alt=media&amp;token=4bcf7026-3ccc-4e1d-8453-567c97f09f43" alt=""><figcaption></figcaption></figure>

* In the Managed Resource Group -> click **Resource visualizer** -> locate and open the **Key Vault** resource.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2Faz9lle6Cu5pxaE2AOY8h%2Fnba%20engine%20config%203.png?alt=media&amp;token=f27a7d75-2e34-4784-ba5e-29367ab0d1fe" alt=""><figcaption></figcaption></figure>

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FVxejUBfFKCCKCD7u1reG%2Fnba%20engine%20config%204.png?alt=media&amp;token=b7ff462a-0398-4501-89e7-47ca63d01b1f" alt=""><figcaption></figcaption></figure>

* In the Key Vault, navigate to **Objects** → **Secrets**.

  &#x20;

  Locate the following secrets:

  * Client ID
  * Client Secret
  * Tenant ID

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2Fqy5ns0h9PwZ9kLDTpBiy%2Fnba%20engine%20config%205.png?alt=media&amp;token=d2987eae-bfc9-4ed0-a23d-081b09d8bde9" alt=""><figcaption></figcaption></figure>

* Open each secret individually and copy its value for later use in the configuration.
* Return to the Managed Resource Group and locate the nba-container-app resource.
* Open nba-container-app and, from the Overview page, copy the Application URL.
* Under Security, select **Secrets**.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FfmxBeFzu6AxCdVWoB1rD%2Fnba%20engine%20config%206.png?alt=media&amp;token=7e641c28-3464-4ca9-b2c0-87f303b9409b" alt=""><figcaption></figcaption></figure>

* Locate the **API Key** and copy its value.
* Click **Create**.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2F6PfR1vQ5Xz2Wg9J0OvOX%2Fnba%20engine%20config%207.png?alt=media&amp;token=480c27d1-3a9d-4598-b546-261e9075cbcb" alt=""><figcaption></figcaption></figure>

### Locate the Container App and Copy the Endpoint URL

* From the list of resources, open the Container App (example name: nba-container-app).

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FdV1bNhmPdJgw3PyobEKc%2Fcontainer%201.png?alt=media&amp;token=796ae1b0-3566-42c6-992b-400a8dbf25d0" alt=""><figcaption></figcaption></figure>

* Inside the Container App, copy the **Application URL** - This is the **endpoint URL that** you will use on the Next Best Action home page to connect the app to the container. **Save this URL** for later.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2F7nLUKyCplmmSrSdl5BQ2%2Fcontainer%202.png?alt=media&amp;token=781f006a-0fe5-4052-a365-2b5ebd376946" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:** The Container App URL contains the container app name you set during deployment; choose that name carefully earlier.
{% endhint %}

### **Container App: Cool-Down Period (Optional Adjustment)**

* (Optional) In the Container App settings, you can change the cool-down period. By default, it’s 900 seconds.
* The cool-down period is the idle timeout after which the container app becomes idle to save costs; a request sent after this idle period may require a few seconds for the app to spin up. Adjust this value based on usage and cost tradeoffs.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FoGtJ2cC88smm7O0pHUNY%2Fcontainer%203.png?alt=media&amp;token=7439f47d-a787-4246-ad22-49c28c83fe96" alt=""><figcaption></figcaption></figure>

#### **Add Dataverse (D365) Credentials to Container App Secrets** <a href="#add-dataverse-d365-credentials-to-container-app-secrets" id="add-dataverse-d365-credentials-to-container-app-secrets"></a>

* In the Container App navigate to Security → Secrets. You must add values for the following three secret keys:
* d365-client-id
* d365-client-secret
* d365-tenant-id

These values connect the container app to your Dataverse (Dynamics 365) environment.

[Click here](https://docs.inogic.com/next-best-action/configuration/configure-application-user) to configure Application User.

#### **Fill Container App Secrets with the Three Keys** <a href="#fill-container-app-secrets-with-the-three-keys" id="fill-container-app-secrets-with-the-three-keys"></a>

Return to the **Container App → Security → Secrets**. For each secret key:

Click the secret → click the Edit icon.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2Fj2J4gbiykjlJL6ff5A9q%2Fcontainer%204.png?alt=media&amp;token=1f39c531-b074-465a-aba9-9abbf051692a" alt=""><figcaption></figcaption></figure>

#### **Copy the Container App API Key** <a href="#copy-the-container-app-api-key" id="copy-the-container-app-api-key"></a>

In the Container App secrets list, copy the api-key value. This API key is the secured authentication key used by **Next Best Action** to talk to the container app. Save this key.

<figure><img src="https://272130504-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0QoyqUVI8_HaZ9FOSL%2Fuploads%2FVsfSdtQiYSTDL6gyyqkx%2Fcontainer%205.png?alt=media&amp;token=83c7ce6f-9fd7-458a-bd70-9836082e136e" alt=""><figcaption></figcaption></figure>

#### **Validate Endpoint & API Key in Next Best Action App** <a href="#validate-endpoint-and-api-key-in-predict4dynamics-app" id="validate-endpoint-and-api-key-in-predict4dynamics-app"></a>

Open the Next Best Action home page. Enter the **Endpoint URL** (container app URL) and the API Key you copied, then click Validate.

On successful validation, you will receive a success notification on the form, then click Save to persist the connection.

**Tip:** If validation fails, re-check that the container app URL is correct and that the API key copied matches exactly; also ensure the container app is running and not idled (cool-down) when testing.

#### **Troubleshooting (Common Issues)** <a href="#troubleshooting-common-issues" id="troubleshooting-common-issues"></a>

* Insufficient subscription / missing permissions: Confirm the Azure subscription is active and you have permissions to create resources (Owner or Contributor role).
* Model/token selection errors: Check that the selected model and token are available in your Azure tenant; if not, choose a supported model/token or provision required resources.
* Managed Resource Group: Use the resource visualizer to confirm all resources were created correctly.
* Cool-Down Period: Default 900s - adjust if frequent cold starts are a problem.
* App Registration Secret Visibility: The client secret value is available only once at creation. Copy and securely store it immediately.
* Tenant Differences: The Azure AD tenant that hosts Dataverse may differ from the tenant where the container app is deployed, ensure you register the app in the correct tenant.
* Permission Scope: Ensure user\_impersonation permission for Dynamics CRM is added and admin consent granted; otherwise, API calls will fail.
* Validation Failures: If Next Best Action validation fails during the endpoint/API key step, check the container app running state, the secrets accuracy, and that the container app endpoint is reachable from your network.
