User Guide

How to create an Azure segment

Preview

Create an Azure segment to discover resources in your Azure environment and audit the ones you want to track in Inventory. By default, scans and audits for the segment run on AlloyScan cloud workers, services hosted and managed by AlloyScan. You do not need to install or maintain any local components.

NOTE: With the default cloud worker, Azure credentials are encrypted and stored in the AlloyScan cloud. If you want to keep them within your local network, you can use a local Audit Service instead. This can be a service you already use for other segments.

Prerequisites

  • You are a Site Administrator.
  • You have the tenant ID, client ID, and client secret for an Azure app registration with the permissions listed below.
  • For local execution, an Audit Service is available with access to the provider API. The required cloud modules must be installed on its host, or an administrator must enable Allow module installation on audit service host under Admin Center > Settings > Audit settings > Audit Service.

Azure permissions

Assign the app registration's service principal the built-in Reader role at the scope you want to scan. Reader lets AlloyScan read Azure resource metadata without changing the resources. The same permissions apply to cloud-worker and local execution.

If you use a custom role instead, allow these actions:

Microsoft.Compute/virtualMachines/read
Microsoft.Compute/disks/read
Microsoft.Network/loadBalancers/read
Microsoft.Network/networkSecurityGroups/read
Microsoft.Network/virtualNetworks/read
Microsoft.Network/networkInterfaces/read
Microsoft.Network/publicIPAddresses/read
Microsoft.Network/applicationGateways/read
Microsoft.Resources/subscriptions/read
Microsoft.Resources/subscriptions/resourceGroups/read

Create the segment

  1. Open Network > Segments and select + New segment.
  2. Select Azure and select Next.
  3. Under Execution placement, keep AlloyScan cloud worker, which is selected by default. To run scans and audits in your environment, select Local Audit service and choose an Audit Service.
  4. Review the segment name and change it if needed. Select the Azure resources and scope you want to scan.
  5. Select or add credentials for the provider. Cloud execution uses cloud credentials stored in AlloyScan; local execution uses credentials from the selected Audit Service.
  6. Create a scan schedule, or continue without a schedule. For cloud execution, Cloud start window (minutes) specifies how long after the scheduled time the scan may start.
  7. Review the settings and create the segment.

Use a cloud worker for an existing segment

Open the segment's settings, select AlloyScan cloud worker under Execution placement, select or add compatible cloud credentials, and save. Existing Audit Service credentials are not transferred to cloud storage. You can continue using local execution without changing the segment's credentials.

Verify

  1. Open the segment and select Scan.
  2. Review the scan results and audit the resources you want to inventory.
  3. Open Inventory > Azure and review the audited resources.