Onboard Azure Subscriptions

This topic describes how to onboard Azure subscriptions to ACE.

Note: Seamless Azure Subscription Onboarding:

  • An early availability feature in ASMS A33.10 is the ability to onboard Azure Subscriptions to both ACE and ASMS simultaneously. This capability streamlines your onboarding process. Once accounts are added to ACE, they are automatically onboarded to ASMS. For more details, refer to our ASMS tech docs Simultaneously onboard Azure subscriptions into ACE and ASMS.

You can choose four onboarding methods to add new Azure subscriptions, management groups, and tenant root groups. The first involves using scripts, while the others do not. The onboarding method you select also determines whether changes made to account resources after onboarding are automatically synced from Azure to your environment.

Note: Depending on which onboarding method you choose, changes to onboarded account resources may be automatically synced every hour.

Onboarding Methods Azure subscriptions, management groups, and tenant root groups

*Automatically syncs changes to subscriptions, management groups, and tenant root groups from Azure to ACE after onboarding.
Onboarding Method Description Automatic sync*
With script (via wizard) Uses scripts to onboard Azure resources Yes
No script Onboard Azure resources without using scripts Yes
API (single account) Onboard a single subscription via API No
Terraform Leverage Terraform, the infrastructure-as-code solution, for onboarding your Azure subscriptions into ACE. Yes

Note: Any changes to Azure subscriptions, managed groups, or tenant root groups after onboarding will automatically sync with ACE once every hour.

Note: For more information about the Azure onboarding script, see Inside the Azure Onboarding Script.

Before you start

Onboarding Azure Subscription

Onboard Azure resources using your preferred method:

Do the following:

Enable Azure resource logs for traffic analysis

For each Azure device where resource logs are enabled in your connected subscription, ACE automatically collects resource logs.

The resource logs provide all the details needed to display rule usage data on the risk trigger and network policy pages. On the Network policy pages, ACE users can clean up old or unused NSG / Azure Native Firewall policy rules, supported by the display of this data. For more details, see Last used and Clean Up Policies.

Offboard Azure subscriptions from ACE

You can offboard Azure subscriptions from ACE with the following methods:

 

â See also: