Skip to main content

Overview

The Azure integration enables ThreatAware to collect read-only data from your Azure subscriptions, providing visibility into cloud infrastructure, resources, and security configurations.
Connection Method: OAuth with IAM Role Assignment Setup Time: 20 minutes Access Required: Azure Subscription Administrator account

Data collected

The Azure integration provides:
  • Azure resource inventory
  • Virtual machine and instance details
  • Network and security configurations
  • Subscription and resource group information

Use cases

Cloud Resource Monitoring

Track Azure resources and infrastructure across subscriptions

VM Inventory Management

Monitor virtual machines and compute resources

Security Configuration Validation

Verify Azure security controls and network configurations

Compliance Verification

Validate cloud infrastructure meets organisational standards

Setup instructions

1

Log in to ThreatAware

Access the ThreatAware dashboard and navigate to Settings → Integrations.
2

Locate Azure Integration

Use the search bar to find Azure in the integrations list.
3

Start Authorization

Click Connect and a dialog will appear. Click the Authorize button to begin the OAuth flow.
4

Sign In with Azure Account

You will be redirected to Azure:
  • Sign in with your Subscription Administrator account
  • Review the help article on finding your Subscription Administrator if needed
  • Review and accept the required permissions
  • Click Accept to proceed
The account you use must have subscription-level admin permissions.
5

Verify Authorization Success

After authorising, you’ll be redirected to a ThreatAware confirmation page:
  • If successful: You may close the page and continue
  • If unsuccessful: Return and retry authorization with correct permissions
6

Select Subscriptions

If you manage multiple Azure Subscriptions:
  • Log in to your Azure Portal
  • Navigate to Subscriptions
  • Select all subscriptions you want to monitor
  • Document their IDs for reference in ThreatAware
7

Configure IAM Role Assignment

For each Azure Subscription you want to monitor:
  • Log in to Azure Portal
  • Navigate to the Subscription
  • Go to Access Control (IAM)
  • Click the Role Assignments tab
  • Click Add and select Add role assignment
8

Assign Reader Role to ThreatAware

In the role assignment dialog:
  • Choose the role Reader
  • Set Assign access to: User, Group, or service principal
  • In the Select field, search for ThreatAware Azure Connector
  • Click to select ThreatAware Azure Connector
  • Click Save to complete the assignment
The Reader role provides read-only access to all resources in the subscription. This is the minimum required for ThreatAware monitoring.
9

Repeat for Multiple Subscriptions

If monitoring multiple subscriptions:
  • Repeat steps 6-7 for each subscription
  • Assign the Reader role to ThreatAware Azure Connector in each subscription
  • Verify all assignments are complete in the Azure Portal
10

Verify Connection

After completing all steps:
  • Return to ThreatAware and verify the Integration Status shows as Active
  • Wait for initial data synchronization
  • Verify Azure resources appear in ThreatAware

Required permissions

Required: Azure Subscription Administrator account for initial authorizationThis account needs:
  • Ability to grant consent to applications
  • Permission to manage IAM role assignments
  • Access to all subscriptions being monitored
Assigned to: ThreatAware Azure Connector (service principal)This role provides:
  • Read access to all resources
  • View resource properties and configurations
  • Access to resource groups and subscriptions
  • No ability to modify or delete resources

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm the Azure integration shows Active status
  2. Verify Data Collection
    • Wait for initial data synchronization (typically 1 hour)
    • Log in to Azure Portal to view your resources
    • Verify the same resources appear in ThreatAware
  3. Test Multi-Subscription Setup
    • Verify resources from all subscriptions appear in ThreatAware
    • Check that resource details are complete and accurate

Troubleshooting

Symptoms: Authorization redirects back with an errorSolutions:
  • Verify you are using a Subscription Administrator account
  • Ensure the account has permission to grant consent to applications
  • Check that your Azure tenant is properly configured
  • Try using InPrivate/Incognito browser mode to avoid cached credentials
  • Contact your Azure administrator for assistance
Symptoms: Integration connects but shows permission or access errorsSolutions:
  • Verify the ThreatAware Azure Connector role assignment is in place
  • Confirm the Reader role is assigned (not Owner or other roles)
  • Check that the role is assigned at the subscription level
  • Verify the assignment was saved successfully in the Azure Portal
  • Wait 5-10 minutes for permission changes to propagate
Symptoms: Integration shows active but Azure resources don’t appearSolutions:
  • Verify the Reader role is assigned for the subscription containing resources
  • Ensure you’ve completed step 7 (IAM role assignment) for all subscriptions
  • Wait up to 1 hour for initial data synchronization
  • Check if resources exist in the selected subscription
  • Contact Azure support to verify role assignments
Symptoms: Only one subscription appears or some subscriptions are missingSolutions:
  • Verify the Reader role is assigned in each subscription
  • Confirm all role assignments were saved successfully
  • Check that you have access to all subscriptions in Azure Portal
  • Review the subscription IDs in Azure Portal match your configuration

Additional resources

Azure Subscriptions Documentation

Microsoft documentation on subscription administration

Azure IAM Documentation

Azure role-based access control (RBAC) documentation

Azure Portal

Access your Azure Portal for resource and permission management

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Subscription Management
  • Document all subscriptions you are monitoring with ThreatAware
  • Verify Reader role assignments after any account changes
  • Monitor integration status regularly
  • Keep track of which Azure administrator performed the setup
Security Considerations
  • The Reader role provides read-only access (no data modification risk)
  • Review Azure access logs periodically for ThreatAware API activity
  • Ensure only authorised administrators manage role assignments
  • Monitor for unexpected Azure resource changes
  • Keep IAM role assignments updated when subscriptions change