Why Azure, Not Your Laptop

The Security Reality

Running OpenClaw on your personal computer is risky. This is not speculation. Microsoft's Security Team warned in February 2026 that OpenClaw should be treated as untrusted code execution with persistent credentials, and should only run in a fully isolated environment such as a dedicated VM.

The core risks when running locally:

Why Azure Works

A dedicated Azure VM solves the main problems:

Key Security Rules

Regardless of where you run OpenClaw:

Create Your Azure VM

There are multiple ways to deploy OpenClaw on Azure. Below is the cheapest path that still gives you proper security. We skip Azure Bastion (which costs ~$140/month) and use IP-restricted SSH instead.

Option A: One-Click Deployment (Easiest)

The community repo aerolalit/openclaw-azure automates everything. It creates a VM, locks SSH to your IP, sets up OpenClaw, and optionally enables daily backups.

What you need before starting:

Steps:

Install Azure CLI if you haven't:

# macOS:
brew install azure-cli

# Windows: download from https://aka.ms/installazurecliwindows

# Linux:
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash

Log in to Azure:

az login

Clone the deployment repo:

git clone https://github.com/aerolalit/openclaw-azure.git
cd openclaw-azure

Configure your parameters:

cp deploy/parameters.json.example deploy/parameters.json
# Edit deploy/parameters.json with your values:
#   - Your API key
#   - Your Telegram bot token (optional)
#   - Pick a region: westeurope or northeurope for NL
#   - App name: 3-12 characters, letters/numbers only

Deploy:

./deploy/deploy.sh

This takes 5-10 minutes. Your IP is automatically restricted in the NSG.

Wait for cloud-init to finish, then test:

az vm run-command invoke \
  --resource-group <your-rg> \
  --name <your-vm> \
  --command-id RunShellScript \
  --scripts 'journalctl -u openclaw -n 50 --no-pager'

Tip: Region Choice. Use westeurope (Amsterdam) or northeurope (Dublin) for lowest latency from Europe. westeurope is usually cheaper and has the widest VM selection.

Option B: Manual Azure CLI Setup

If you prefer more control, here are the core steps:

Create a resource group:

az group create --name rg-openclaw --location westeurope

Create an NSG and lock SSH to your IP:

az network nsg create --resource-group rg-openclaw \
  --name nsg-openclaw

az network nsg rule create --resource-group rg-openclaw \
  --nsg-name nsg-openclaw --name AllowSSH \
  --priority 100 --direction Inbound \
  --source-address-prefixes <YOUR_PUBLIC_IP> \
  --destination-port-ranges 22 --access Allow \
  --protocol Tcp

Create the VM:

az vm create \
  --resource-group rg-openclaw \
  --name vm-openclaw \
  --image Ubuntu2404 \
  --size Standard_B2s \
  --admin-username openclaw \
  --generate-ssh-keys \
  --nsg nsg-openclaw \
  --public-ip-sku Standard

About VM size: Standard_B2s gives you 2 CPU cores and 4 GB RAM. This is enough for a single OpenClaw agent. If you plan to run heavier workloads later, Standard_D2as_v4 (2 CPU, 8 GB RAM) gives more headroom.

Install OpenClaw

SSH into your new VM:

ssh openclaw@<VM_PUBLIC_IP>

Install Node.js 22+:

curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs

Install OpenClaw:

npm install -g openclaw@latest
openclaw onboard --install-daemon

The onboard wizard will ask you a few questions. For now, just pick defaults. we will configure the LLM provider in the next step.

Verify it is running:

openclaw gateway status

You should see the gateway is active. If not, check the logs:

cat /tmp/openclaw/openclaw-*.log | tail -50

Connect an LLM Provider

OpenClaw is installed, but without an LLM it has no brain. You need to connect it to a language model. There are three options depending on what you prefer.

Option 1: Anthropic (Claude). simplest

If you have an Anthropic API key, this is the fastest way to get going.

openclaw config set models.providers.anthropic.apiKey "sk-ant-YOUR-KEY-HERE"
openclaw gateway restart

OpenClaw will automatically detect available Claude models. To set your default model:

openclaw config set agents.defaults.model.primary "anthropic/claude-sonnet-4-6"

Option 2: OpenAI (GPT). also simple

If you prefer OpenAI:

openclaw config set models.providers.openai.apiKey "sk-YOUR-KEY-HERE"
openclaw gateway restart

Set your default model:

openclaw config set agents.defaults.model.primary "openai/gpt-4o"

Option 3: Azure OpenAI via Foundry. advanced

If you want everything inside your Azure subscription (one bill, data stays in your tenant), you can deploy models through Azure AI Foundry instead of using Anthropic or OpenAI directly.

Set up models in Foundry:

  1. In the Azure portal, open your AI Foundry hub (or create one).
  2. Go to the Model Catalog, deploy gpt-4o (or whichever model you want).
  3. Go to Endpoints. Save these two values:
    • Endpoint URL (format: https://<YOUR_RESOURCE>.openai.azure.com
    • API Key (found under Keys in the Azure Portal)

Configure OpenClaw to use Foundry:

Edit ~/.openclaw/openclaw.json and add the following under models.providers:

{
  "azure-openai-responses": {
    "baseUrl": "https://<YOUR_RESOURCE>.openai.azure.com/openai/v1",
    "apiKey": "<YOUR_AZURE_API_KEY>",
    "api": "openai-responses",
    "authHeader": false,
    "headers": {
      "api-key": "<YOUR_AZURE_API_KEY>"
    },
    "models": [
      {
        "id": "gpt-4o",
        "name": "GPT-4o (Azure)",
        "reasoning": false,
        "input": ["text", "image"],
        "cost": {
          "input": 2.5,
          "output": 10.0,
          "cacheRead": 1.25,
          "cacheWrite": 0
        },
        "contextWindow": 128000,
        "maxTokens": 16384,
        "compat": { "supportsStore": false }
      }
    ]
  }
}

Then set it as the default:

openclaw config set agents.defaults.model.primary "azure-openai-responses/gpt-4o"
openclaw gateway restart

Important: API Key Goes in Two Places. Azure OpenAI uses the api-key HTTP header, not the standard Bearer token. Your key must appear in both the apiKey field and the headers.api-key field. The authHeader: false setting disables the default Bearer header so it does not conflict.

Which option should I pick?

You can always switch later. OpenClaw supports multiple providers at the same time.

Set Up Telegram

With the LLM connected, your agent can think. Now give it a way to talk to you.

The dashboard is available immediately - access it via SSH tunnel:

# From your laptop, create an SSH tunnel:
ssh -L 18789:localhost:18789 openclaw@<VM_PUBLIC_IP>

# Then open in your browser:
# http://localhost:18789

But Telegram is more practical for daily use. Set it up:

  1. Open Telegram and message @BotFather
  2. Send /newbot, follow the prompts, copy the bot token
  3. On the VM:
openclaw config set channels.telegram.botToken "YOUR_BOT_TOKEN"
openclaw config set channels.telegram.enabled true
openclaw gateway restart
  1. Open Telegram and message your new bot. Approve the pairing when prompted.

Send Your First Message

Open your Telegram bot and type something simple:

Hi, what can you help me with?

If everything is connected, your agent will respond. Congratulations, you have a working AI agent running on Azure.

If it does not respond:

Saving Money

Deallocate When Not Using

When you are not using OpenClaw, deallocate the VM to stop paying for compute. You only pay for disk storage (~$1-4/month).

# Stop and deallocate (stops billing for compute):
az vm deallocate --resource-group rg-openclaw --name vm-openclaw

# Start it back up:
az vm start --resource-group rg-openclaw --name vm-openclaw

# The public IP may change after restart. Check with:
az vm show -d --resource-group rg-openclaw --name vm-openclaw \
  --query publicIps -o tsv

Auto-Shutdown

Set up automatic deallocate so you do not forget:

Go to the Azure portal > your VM > Auto-shutdown > Enable. Set a time like 23:00 your local timezone. The VM will automatically stop every night.

Cost Breakdown

Azure Infrastructure

Estimated monthly costs for a B2s VM in West Europe:

Component Monthly (est.) Notes
VM: Standard_B2s (2 vCPU, 4GB) ~โ‚ฌ25-30 ~โ‚ฌ0.04/hr, less if deallocated nights/weekends
OS Disk (30GB Standard SSD) ~โ‚ฌ3-5 Charged even when deallocated
Public IP (Standard SKU) ~โ‚ฌ3-4 Small charge while allocated
Outbound data transfer ~โ‚ฌ1-3 First 100GB/month is free
Total ~โ‚ฌ32-42 Without Azure Bastion (saves ~$140/month)

LLM API Costs

This depends on your provider and usage. Rough estimates:

Usage Level Monthly (est.) What that looks like
Light ~$5-15 A few questions per day
Medium ~$15-40 Daily active use, longer conversations
Heavy ~$40-100+ Automated tasks running throughout the day

Tip: Monitor your token usage from day one. OpenClaw can burn through tokens fast, especially if you set up automated workflows later. Most LLM providers have usage dashboards and spending alerts.

Total Estimated Monthly Cost

Scenario Monthly Total
Budget (light use, deallocate often) ~โ‚ฌ35-55
Normal (daily use, VM mostly on) ~โ‚ฌ50-80
Heavy (always on, lots of agent work) ~โ‚ฌ80-140+

Essential Commands

openclaw gateway status          # Check if running
openclaw gateway restart         # Restart after config changes
openclaw agents list --bindings  # See all agents and routing
openclaw security audit --deep   # Security check
openclaw dashboard               # Open web UI

# Azure VM management:
az vm deallocate --resource-group rg-openclaw --name vm-openclaw
az vm start --resource-group rg-openclaw --name vm-openclaw

What's Next

You now have a working OpenClaw agent on Azure with a connected LLM and Telegram access. Here are some ideas for what to build next:

Useful Links

Final tip. Start simple. Get your agent responding on Telegram before adding complexity. Once it works, explore the other guides on this site to add more capabilities.

What's Next?

Now that OpenClaw is running on your Azure VM, you're ready to build your first automation. Start with the Morning Briefing guide โ€” it walks you through setting up a personalized daily briefing delivered to Telegram at 8 AM.

Before you connect any paid APIs, make sure to set up proper secret management so your API keys stay safe.