Onboard Azure Subscriptions to Cloud Network Security

This topic describes how to onboard Azure subscriptions toACE Cloud Network Security.

Note: Seamless Azure Subscription Onboarding: An early availability feature in ASMS A33.10 is the ability to onboard Azure Subscriptions to both ACE and ASMS simultaneously. This capability streamlines your onboarding process. Once accounts are added to ACE, they are automatically onboarded to ASMS. For more details, refer to our ASMS tech docs Simultaneously onboard Azure subscriptions into ACE and ASMS.

For details about permissions required, see Permissions Required for Azure Subscriptions.

You can choose from the following four onboarding methods to add new Azure subscriptions, management groups, and tenant root groups:

  • With script - Uses scripts to onboard Azure resources. Changes to subscriptions, management groups, and tenant root groups after onboarding are automatically synced.

  • No script - Onboard Azure resources without using scripts. Changes to subscriptions, management groups, and tenant root groups after onboarding are automatically synced.

  • API (single account) - Onboard a single subscription. Changes to the subscription after onboarding are not synced.

  • Terraform - Leverage Terraform, the infrastructure-as-code solution, for onboarding your Azure subscriptions into ACE. Changes to subscriptions, management groups, and tenant root groups after onboarding are automatically synced.

Note: Any changes to Azure subscriptions, managed groups, or tenant root groups after onboarding will automatically sync with ACE once every hour.

Note: For more information about the Azure onboarding script, see Inside the Azure Onboarding Script.

Before you start

Required permissions

To onboard multiple subscriptions in your Azure account, make sure you have the following permissions:

Access the Onboarding wizard

Do the following:

  1. In the ACE Settings area, click ONBOARDING.

    On the Onboarding Managment page that opens, click +Onboard.

  2. If you are onboarding your first account, click the New Cloud Account button on the welcome page.

  3. Otherwise, click the Microsoft Azure button and click Next.

    The Azure Onboarding wizard appears.

  4. Select your preferred method to onboard using the Select Onboarding Method dropdown.

    *Automatically syncs changes to subscriptions, management groups, and tenant root groups from Azure to ACE after onboarding.
    Onboarding Method Description Automatic sync*
    With script Uses scripts to onboard Azure resources Yes
    No script Onboard Azure resources without using scripts Yes
    API (single account) Onboard a single subscription via API No
    Terraform Onboard Azure resources using Terraform Yes
  5. Onboard Azure resources using your preferred method:

Enable Azure resource logs for traffic analysis

For each Azure device where resource logs are enabled in your connected subscription, ACE automatically collects resource logs.

The resource logs provide all the details needed to display rule usage data on the risk trigger and network policy pages. On the Network policy pages, ACE users can clean up old or unused NSG / Azure Native Firewall policy rules, supported by the display of this data. For more details, see Last used and Clean Up Policies.

Offboard Azure subscriptions from ACE

You can offboard Azure subscriptions from ACE with the following methods: