Onboard Azure

Connect Microsoft Azure to ARMO

Overview

ARMO’s Azure CSPM integration enables secure, continuous discovery and assessment of your Azure subscription’s security posture. By establishing a dedicated Azure Active Directory application with scoped, read-only permissions, ARMO can ingest Azure resource configurations, identity and policy data, and compliance state. Once connected, ARMO continuously analyzes these data points to uncover misconfigurations, compliance gaps, and risky exposures — surfacing actionable findings within the ARMO platform to help you reduce cloud risk and improve security posture.


Why Connect My Azure Cloud?

Securing your Azure infrastructure is essential to protecting your workloads, applications, and data. ARMO provides deep visibility into your Azure resources and continuously assesses them for risks and compliance gaps.

By connecting your Azure subscription, ARMO will:

  • Detect high-impact misconfigurations across your Azure environment, including VMs, Storage, and Kubernetes clusters (AKS).
  • Continuously ingest and analyze Azure Activity Logs to power Cloud Detection and Response (CDR), providing visibility into user actions, API calls, and potential threats.
  • Provide actionable insights to harden your Azure workloads without unnecessary alert fatigue.
📘

Cloud Compliance

View all compliance checks performed on your Azure environment under Compliance → Cloud.

📘

Cloud Detection and Response

Monitor detected incidents and suspicious activity under Runtime Incidents. See Cloud Detection & Response on Azure for setup.


What Happens After You Connect?

Once your Azure environment is connected:

  • ARMO automatically scans your subscriptions for misconfigurations, and compliance violations.
  • Daily scans are scheduled automatically.
  • Findings are enriched with context about impacted resources, severity, and remediation steps.

Available Onboarding Methods

Onboarding OptionDescriptionRecommended for
Onboard Azure SubscriptionConnect a single Azure subscription. You register a Microsoft Entra ID application, create a client secret and a custom role, and assign the Reader, Security Reader, and custom roles to the application.Small environments, or teams that manage subscriptions independently.
Onboard Azure Tenant (Multi-Subscription)Connect an entire tenant or a specific management group. ARMO discovers and monitors every subscription beneath it, including subscriptions added later.Organizations that want full coverage across many subscriptions without connecting each one individually.

Prerequisites

Before onboarding, ensure:

  • You have Owner or User Access Administrator on the Azure subscription (or, for a tenant connection, at the management group) to create the custom role and assign roles.
  • You can register an application and grant admin consent for its Microsoft Graph permissions in Microsoft Entra ID.
  • You have access to the Azure Portal and the ARMO Platform with a role (Admin or Manager) that allows connecting new cloud environments.
  • Network connectivity from ARMO to the Azure Management APIs over HTTPS (port 443).

Onboarding Methods

Choose the guide based on your setup:

👉 Onboard an Azure Subscription

👉 Onboard an Azure Tenant (Multi-Subscription)


After Onboarding

Once your Azure environment is connected:

  • ARMO begins automated discovery of Azure resources
  • Connected subscriptions appear under Settings → Accounts → Azure in the ARMO Platform.
  • Compliance findings and misconfiguration results typically populate within 60 minutes.

Did this page help you?