Overview
The Azure integration enables ThreatAware to collect read-only data from your Azure subscriptions, providing visibility into cloud infrastructure, resources, and security configurations.Connection Method: OAuth with IAM Role Assignment
Setup Time: 20 minutes
Access Required: Azure Subscription Administrator account
Data collected
The Azure integration provides:- Azure resource inventory
- Virtual machine and instance details
- Network and security configurations
- Subscription and resource group information
Use cases
Cloud Resource Monitoring
Track Azure resources and infrastructure across subscriptions
VM Inventory Management
Monitor virtual machines and compute resources
Security Configuration Validation
Verify Azure security controls and network configurations
Compliance Verification
Validate cloud infrastructure meets organisational standards
Setup instructions
1
Log in to ThreatAware
Access the ThreatAware dashboard and navigate to Settings → Integrations.
2
Locate Azure Integration
Use the search bar to find Azure in the integrations list.
3
Start Authorization
Click Connect and a dialog will appear. Click the Authorize button to begin the OAuth flow.
4
Sign In with Azure Account
You will be redirected to Azure:
- Sign in with your Subscription Administrator account
- Review the help article on finding your Subscription Administrator if needed
- Review and accept the required permissions
- Click Accept to proceed
5
Verify Authorization Success
After authorising, you’ll be redirected to a ThreatAware confirmation page:
- If successful: You may close the page and continue
- If unsuccessful: Return and retry authorization with correct permissions
6
Select Subscriptions
If you manage multiple Azure Subscriptions:
- Log in to your Azure Portal
- Navigate to Subscriptions
- Select all subscriptions you want to monitor
- Document their IDs for reference in ThreatAware
7
Configure IAM Role Assignment
For each Azure Subscription you want to monitor:
- Log in to Azure Portal
- Navigate to the Subscription
- Go to Access Control (IAM)
- Click the Role Assignments tab
- Click Add and select Add role assignment
8
Assign Reader Role to ThreatAware
In the role assignment dialog:
- Choose the role Reader
- Set Assign access to: User, Group, or service principal
- In the Select field, search for ThreatAware Azure Connector
- Click to select ThreatAware Azure Connector
- Click Save to complete the assignment
The Reader role provides read-only access to all resources in the subscription. This is the minimum required for ThreatAware monitoring.
9
Repeat for Multiple Subscriptions
If monitoring multiple subscriptions:
- Repeat steps 6-7 for each subscription
- Assign the Reader role to ThreatAware Azure Connector in each subscription
- Verify all assignments are complete in the Azure Portal
10
Verify Connection
After completing all steps:
- Return to ThreatAware and verify the Integration Status shows as Active
- Wait for initial data synchronization
- Verify Azure resources appear in ThreatAware
Required permissions
Subscription Administrator
Subscription Administrator
Required: Azure Subscription Administrator account for initial authorizationThis account needs:
- Ability to grant consent to applications
- Permission to manage IAM role assignments
- Access to all subscriptions being monitored
Reader Role
Reader Role
Assigned to: ThreatAware Azure Connector (service principal)This role provides:
- Read access to all resources
- View resource properties and configurations
- Access to resource groups and subscriptions
- No ability to modify or delete resources
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings → Integrations in ThreatAware
- Confirm the Azure integration shows Active status
-
Verify Data Collection
- Wait for initial data synchronization (typically 1 hour)
- Log in to Azure Portal to view your resources
- Verify the same resources appear in ThreatAware
-
Test Multi-Subscription Setup
- Verify resources from all subscriptions appear in ThreatAware
- Check that resource details are complete and accurate
Troubleshooting
Permission Denied Errors
Permission Denied Errors
Symptoms: Integration connects but shows permission or access errorsSolutions:
- Verify the ThreatAware Azure Connector role assignment is in place
- Confirm the Reader role is assigned (not Owner or other roles)
- Check that the role is assigned at the subscription level
- Verify the assignment was saved successfully in the Azure Portal
- Wait 5-10 minutes for permission changes to propagate
Missing Resources
Missing Resources
Symptoms: Integration shows active but Azure resources don’t appearSolutions:
- Verify the Reader role is assigned for the subscription containing resources
- Ensure you’ve completed step 7 (IAM role assignment) for all subscriptions
- Wait up to 1 hour for initial data synchronization
- Check if resources exist in the selected subscription
- Contact Azure support to verify role assignments
Multi-Subscription Issues
Multi-Subscription Issues
Symptoms: Only one subscription appears or some subscriptions are missingSolutions:
- Verify the Reader role is assigned in each subscription
- Confirm all role assignments were saved successfully
- Check that you have access to all subscriptions in Azure Portal
- Review the subscription IDs in Azure Portal match your configuration
Additional resources
Azure Subscriptions Documentation
Microsoft documentation on subscription administration
Azure IAM Documentation
Azure role-based access control (RBAC) documentation
Azure Portal
Access your Azure Portal for resource and permission management
ThreatAware Support
Contact ThreatAware support for integration assistance