Onboard Azure Subscriptions to Cloud Network Security

This topic describes how to onboard Azure subscriptions toACE Cloud Network Security.

For details about permissions required, see Permissions Required for Azure Subscriptions.

You can choose from the following four onboarding methods to add new Azure subscriptions, management groups, and tenant root groups:

  • With script - Uses scripts to onboard Azure resources. Changes to subscriptions, management groups, and tenant root groups after onboarding are automatically synced.

  • No script - Onboard Azure resources without using scripts. Changes to subscriptions, management groups, and tenant root groups after onboarding are automatically synced.

  • API (single account) - Onboard a single subscription. Changes to the subscription after onboarding are not synced.

  • Terraform - Leverage Terraform, the infrastructure-as-code solution, for onboarding your Azure subscriptions into ACE. Changes to subscriptions, management groups, and tenant root groups after onboarding are automatically synced.

Note: Any changes to Azure subscriptions, managed groups, or tenant root groups after onboarding will automatically sync with ACE once every hour.

Note: For more information about the Azure onboarding script, see Cloud Network Security Azure Onboarding Script.

Access the Onboarding wizard

Do the following:

  1. In the ACE Settings area, click ONBOARDING.

    On the Onboarding Managment page that opens, click +Onboard.

  2. If you are onboarding your first account, click the New Cloud Account button on the welcome page.

  3. Otherwise, click the Microsoft Azure button and click Next.

    The Azure Onboarding wizard appears.

  4. Select your preferred method to onboard using the Select Onboarding Method dropdown.

    *Automatically syncs changes to subscriptions, management groups, and tenant root groups from Azure to ACE after onboarding.
    Onboarding Method Description Automatic sync*
    With script Uses scripts to onboard Azure resources Yes
    No script Onboard Azure resources without using scripts Yes
    API (single account) Onboard a single subscription via API No
    Terraform Onboard Azure resources using Terraform Yes
  5. Onboard Azure resources using your preferred method:

Enable Azure flow logs

For each Azure device where flow logs are enabled in your connected subscription, ACE automatically collects flow logs.

The flow logs provide all the details needed to display rule usage data on the risk trigger and network policy pages. On the Network policy pages, ACE users can clean up old or unused NSG / Azure Firewall policy rules, supported by the display of this data. For more details, see Last used and Clean Up Policies.

Offboard Azure subscriptions from ACE

You can offboard Azure subscriptions from ACE with the following methods: