Microsoft Azure
runZero integrates with Microsoft Azure to give you visibility into your cloud assets. The integration imports data through each applicable API to enrich your asset inventory:
A sync shows you each asset’s OS profile, storage profile, and more. The integration imports assets that are in a running state.
Getting started
runZero supports these Azure resource types:
- Virtual Machines
- Virtual Machine Scale Sets
- Azure SQL
- Azure Cosmos DB
- Load Balancers
- Function Apps
To set up the Azure integration:
- Configure Azure to allow API access through runZero.
- Add an Azure credential to runZero.
- Choose whether to run the integration as a scan probe or connector task.
- Activate the Azure integration to sync your data with runZero.
Requirements
You need access to the Microsoft Azure portal.
Step 1: Configure Azure to allow API access through runZero
- Sign in to the Microsoft Azure portal.
- Go to Azure Active Directory > App registrations and click New registration.
- Provide a name.
- Select the supported account types.
- Optionally add a redirect URI.
- Click Register.
- Once the application is created, you should see the Overview dashboard. Save the following information:
- Application (client) ID
- Directory (tenant) ID
- Give the client access to the subscriptions you want to sync. From the subscription details page, go to Access Control (IAM) and select Add > Add role assignment. Enter the following:
- Role: Reader
- Assign access to: User, group, or service principal
- Under Select, search for the name of the application you created. Click your application to add it to the Selected members list below.
- Click Save.
- Go to Azure Active Directory > App registrations and select the application you created.
- Go to Certificates & secrets and click New client secret.
- Enter a description.
- Select the expiration.
- Click Add to create the client secret. Save the following information:
- Client secret value
Step 2: Add the Azure credential to runZero
The Azure integration accepts either a client secret or a username and password as its credential.
Step 2a: Add an Azure Client Secret credential to runZero
You can use this credential type to sync all resources in a single directory (across multiple subscriptions).
- Go to the Credentials page in runZero and click Add Credential.
- Provide a name for the credential, like
Azure Client Secret. - Choose Azure Client Secret from the list of credential types.
- Provide the following information:
- Azure application (client) ID: The unique ID for the registered application. To find it in the Azure portal, go to Azure Active Directory > App registrations and select the application.
- Azure client secret: To generate a client secret, go to Azure Active Directory > App registrations, select your application, go to Certificates & secrets, and click New client secret.
- Azure directory (tenant) ID: The unique ID for the tenant. To find it in the Azure portal, go to Azure Active Directory > App registrations and select the application.
- Enable the All subscriptions option to sync all resources in your directory. With it enabled, you can list subscription IDs in the Exclude subscription IDs text area to leave specific ones out. With it disabled, you can list specific subscription IDs in the Include subscription IDs text area. To find a subscription ID in the Azure portal, go to Subscriptions and select the subscription. Enter one subscription ID per line in either text area.
- To let other organizations use this credential, select the Make this a global credential option. Otherwise, you can configure access per organization.
- Save the credential.
Step 2b: Add an Azure Username & Password credential to runZero
You can use this credential type to sync all resources across directories. Alternatively, add one Azure Client Secret credential for each Azure directory you want to sync.
- Go to the Credentials page in runZero and click Add Credential.
- Provide a name for the credential, like
Azure User/Pass. - Choose Azure Username & Password from the list of credential types.
- Provide the following information:
- Azure application (client) ID: The unique ID for the registered application. To find it in the Azure portal, go to Azure Active Directory > App registrations and select the application.
- Azure directory (tenant) ID: The unique ID for the tenant. To find it in the Azure portal, go to Azure Active Directory > App registrations and select the application.
- Azure username: The username for your Azure cloud account. It can’t be a federated user account.
- Azure password: The password for your Azure cloud account.
- To let other organizations use this credential, select the Make this a global credential option. Otherwise, you can configure access per organization.
- Save the credential.
Step 3: Choose how to configure the Azure integration
You can run the Azure integration as either a scan probe or a connector task. A scan probe gathers integration data during a scan task. A connector task runs on its own, from the cloud or from one of your Explorers, and performs only the integration sync.
Step 4: Set up and activate the Azure integration to sync data
With your Azure credential saved, set up a connector task or a scan probe to sync your data.
Step 4a: Configure the Azure integration as a connector task
A connection needs a schedule and a site. The schedule sets when the sync runs, and the site is where runZero creates any new Azure-only assets.
- Activate a connection to Azure. You can reach every third-party connection from the integrations page, your inventory, or the tasks page.
- Choose the credential you added earlier. If it isn’t listed, make sure it has access to the organization you’re currently in.
- Enter a name for the task, like
Azure sync. - Schedule the sync to run once or on a recurring schedule. The schedule starts on the date and time you set.
- Under Task configuration, choose the site to add your assets to. runZero stores all newly discovered assets in this site.
- Under Service options, select the services to sync data from. You must choose at least one.
- To leave out assets that runZero has not scanned, switch the Exclude unknown assets toggle to Yes. By default, the integration includes them.
- Activate the connection. The sync runs on the schedule you defined, and the Scheduled tasks page shows when the next sync will occur.
Step 4b: Configure the Azure integration as a scan probe
- Create a new scan task or select a future or recurring scan task from your Tasks page.
- Add or update the scan parameters to fit any additional requirements.
- On the Probes and SNMP tab, choose any additional probes to include, set the Azure toggle to Yes, and change any default options as needed.
- On the Credentials tab, set the Azure toggle to Yes for the credential you want to use.
- Click Initialize scan to save the scan task. It runs immediately or at the scheduled time.
Step 5: View Azure assets
After a successful sync, go to your inventory to view your Azure assets. They show an Azure icon in the Source column.
To filter Azure assets, try these queries:
- View all Azure assets:
source:azure - View all Azure VMs:
has:"@azure.vm.vmID" - View all Azure virtual machine scale set VMs:
has:"@azure.vmss.vmID" - View all Azure load balancers:
has:"@azure.lb.id" - View all AzureSQL instances:
has:"@azure.azsql.id" - View all Azure Cosmos DB instances:
has:"@azure.cosmos.id"" - View all Azure Function Apps:
@azure.functionapp.kind:"functionapp"
Click into an asset to see the attributes the Azure APIs returned. To write your own queries, start with the search query syntax.
Troubleshooting
If the integration isn’t working, start with these checks.
Why is the Microsoft Azure integration unable to connect?
- Check whether the Microsoft Azure integration is returning any data.
- Query the inventory rather than the task details to review all the data available from this integration.
- In some cases, an integration’s configuration limits how much data reaches the runZero console.
- Some integrations require specific actions that are easy to overlook. If you miss a step during setup, the integration may not work correctly. Review this page and follow the steps exactly.
- If the Microsoft Azure integration can’t connect, check the task log for errors. Common errors include:
- 500: server error, unable to connect to the endpoint
- 404: hitting an unknown endpoint on the server
- 403: not authorized, likely a credential issue