Configuring Azure Cloud Environment Scanning
Overview Direct link to this section
This document describes how to configure scanning for your Microsoft Azure cloud environment configurations. Cloud scans are part of your Cloud Security Posture Management (CSPM). As part of this configuration, you must provide the following information for your Azure environment to Arctic Wolf using the Arctic Wolf Portal:
- Directory ID
- Application ID
- Subscription ID
- Secret key
Note: You must be an Arctic Wolf® Managed Risk customer to configure cloud scanning.
Register the application Direct link to this section
-
Sign in to the Microsoft Azure Portal.
-
Open the navigation menu, and then select Azure Active Directory.
-
Select App registrations from the navigation pane.
-
Select New registration to open the Register an application page.
-
Enter a memorable name for the application in the Name text box.
-
In the Supported Account types section, confirm that Accounts in this organizational directory only (<Organization-Name> only - Single Tenant) is selected.
Note: Leave all other fields as their defaults.
-
Click Register. This opens the page for the newly registered application.
-
Record the Application (client) ID and Directory (tenant) ID values to provide to Arctic Wolf as part of Provide credentials to Arctic Wolf.
-
In the navigation pane, under Manage, select Certificates & secrets.
-
In the Client secrets section, select + New client secret, and then create the secret:
-
Enter a meaningful description for the client secret.
-
Select your desired option for the Expires field.
Tip: You must submit updated credentials to Arctic Wolf before the credentials expire.
-
Click Add.
-
-
Verify that your new client secret appears in the Client secrets section, and then copy the Value field to a secure location. You must provide this value to Arctic Wolf as part of Provide credentials to Arctic Wolf.

Note: Ensure that you copy the Value field before exiting the page, as this value is only viewable immediately after creation. Do not copy the Secret ID field.
Retrieve the subscription ID Direct link to this section
-
From the navigation menu, select Subscriptions, and then select the subscription that you want Arctic Wolf to scan.
-
Record the Subscription ID to provide to Arctic Wolf as part of Provide credentials to Arctic Wolf.
Add role assignments Direct link to this section
-
From the All Services menu, select «Subscriptions.
-
Select the subscriptions that you want to integrate with Arctic Wolf.
-
Select Access control (IAM). and then select the Role assignments tab.
-
Click Add, and then select Add role assignment.
-
In the Role list, enter
Security Reader
, and then select that option. -
In the Select list, add the application that you created in Register the application.
Note: Leave the Assign access to list with the default value.
-
Click Save.
-
Repeat steps 5-7 for the Log Analytics Reader role.
-
Verify that the Role assignments tab lists the two roles that you created.
Provide credentials to Arctic Wolf Direct link to this section
-
Sign in to the Arctic Wolf Portal.
-
Select Connected Accounts in the banner menu to open the Connected Accounts page.
-
Select +Add Account to open the Add Account form.
-
Select Cloud Security Posture Management as the Account Type.
-
Select Azure, and then fill in the form:
- Account Name — Enter an account name of your choosing.
- Directory ID — Enter the Directory (tenant) ID value from Register the application.
- Application ID — Enter the Application (client) ID value from Register the application.
- Subscription ID — Enter the Subscription ID value from Retrieve the subscription ID.
- Secret Key — Enter the Client Secret value from step 11 of Register the application.
-
Select Submit to CST.
-
When prompted with the confirmation message, review your submission, and then select Done. You are returned to the Connected Accounts page.
-
Verify that the newly-submitted credential entry appears in the cloud services list with the status Connection Pending.
After your Concierge Security® Team adds this account to your scan configuration, the status of your credentials changes to Connected.