[ Applies to ] StorageGuard 9.x and later / Microsoft Azure subscriptions / Microsoft Entra ID
StorageGuard collects configuration data from a Microsoft Azure environment by using the Azure Java SDK to run read-only management API calls. It authenticates as a service principal (an app registration) with the Reader role. This article describes the requirements and how to create the service principal.
In this article
Requirements
| Requirement | Details |
|---|---|
| Subscription ID | The ID of the target Azure subscription. |
| Credentials | Service principal credentials: Client ID, Tenant ID, and Client Secret. |
| Role and permissions | The service principal needs the Reader role on each subscription or resource group you want to scan. |
| Network access | Connectivity from the StorageGuard server to Azure. |
Note: StorageGuard collects data from every subscription that the app registration has permission to access, not only the target subscription.
Create the service principal
The following procedures are a suggested way to create a service principal with read-only access. Do them in order, in the Azure portal.
1. Register an application
- Sign in to the Azure portal.
- Go to Microsoft Entra ID (formerly Azure Active Directory).
- Under Manage, select App registrations, and then click New registration.
- Enter a name for the application, for example StorageGuardReader.
- Choose the supported account type that fits your organization.
- Click Register.
- On the application's Overview page, copy the Application (client) ID and Directory (tenant) ID. These are the Client ID and Tenant ID StorageGuard needs.
2. Create a client secret
- In the application, go to Certificates & secrets.
- Click New client secret.
- Enter a description, and set an expiration period.
- Click Add, and copy the secret Value.
Note: Azure shows the client secret value only right after you create it. Store it securely. When the secret expires, create a new one and update the credentials in StorageGuard.
3. Assign the Reader role
- Go to the subscription or resource group you want to scan.
- Click Access control (IAM).
- Click Add > Add role assignment.
- Select the Reader role.
- In Assign access to, choose User, group, or service principal.
- Search for the application you registered, and select it.
- Click Save.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.