Skip to main content

Overview

The Azure IaaS integration enables ThreatAware to collect and monitor security data from your Azure IaaS environment, providing comprehensive visibility and threat detection capabilities.
Connection Method: API Setup Time: 15 minutes Access Required: Azure IaaS Administrator account

Setup instructions

1

Authorize ThreatAware in Azure

  • Log in to the Azure Portal with a Subscription Administrator account.
  • Follow the prompts to authorise ThreatAware with the necessary permissions.
  • Note: For guidance on locating the Subscription Administrator, refer to Microsoft’s Documentation.
2

Configure Subscription Access

  • Navigate to Subscriptions in the Azure Portal.
  • Select the relevant Subscription you want to integrate with ThreatAware.
  • ![Select Subscription](image link)
3

Assign IAM Roles

  • In the selected subscription, go to Access Control (IAM) > Role assignments.
  • Click Add > Add role assignment.
  • Choose Reader as the role and assign it to ThreatAware Azure Connector.
  • Ensure Assign access to is set to User, Group, or Service Principal.
  • ![Assign IAM Role](image link)
4

Save and Review Configuration

  • After completing the role assignments, verify that all permissions are configured as required.
  • Multiple subscriptions may require repeating the role assignment steps.
5

Complete the Integration in ThreatAware

  • Return to ThreatAware, confirm the integration with Azure, and save the settings.

Required credentials

Unique identifier for each Azure subscription to be monitored.
Confirm that ThreatAware Azure Connector is assigned the Reader role.

Troubleshooting

In ThreatAware, ensure the Integration Status displays as Active.
  • Permission Errors: Verify all required permissions are granted, and the correct roles are assigned.
  • Access Control Issues: Check that the Reader role was applied to ThreatAware Azure Connector for each subscription.

Important notes

  • Ensure the Reader role is assigned to ThreatAware Azure Connector for each subscription to monitor.
  • The ThreatAware integration setup may vary depending on your Azure subscription type and permissions. Review the Azure Access Control Documentation for further details.