Azure
Visualize and map Azure cloud resources, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
- Release Notes
Installation
To install this integration, you will need to configure settings both within Azure and on JupiterOne. Before enabling in JupiterOne, ensure that you have completed the setup within your Azure.
Azure configuration
To set up this integration, you will need to authorize access by creating a Service Principal (App Registration) in Azure and provide the credentials to JupiterOne.
The integration is triggered by an event containing the information for a specific integration instance. Users configure the integration by providing API credentials obtained through the Azure portal.
Microsoft Entra ID is authenticated and accessed through the Microsoft Graph API. Azure Resource Manager is authenticated and accessed through Resource Manager APIs.
Creating the App Registration in Azure
The first step will be to create your App registration in Azure. From your Azure portal, navigate to Microsoft Entra ID > Manage > App registrations and continue through the following steps:
- Create a new App registration, using the Name
JupiterOne, selecting Accounts in this organizational directory only, with no "Redirect URI". - With the app created, navigate to the new app's Overview page.
- Copy both the Application (client) ID and the Directory (tenant) ID.
- Navigate to the Certificates & secrets section.
- Create a new client secret.
- Save and copy the generated secret Value (not the Secret ID).
With the App created, and the values saved, you will next need to configure the API permissions within Microsoft Entra ID.
API Permissions
To grant permissions for reading the Microsoft Graph information:
- Navigate to API permissions, select Microsoft Graph > Application Permissions
- Grant the following permission to the application:
Directory.Read.AllPolicy.Read.AllAuditLog.Read.AllDevice.Read.AllEntitlementManagement.Read.AllPolicy.Read.ConditionalAccess
- Grant admin consent for this directory for the permissions above.
IAM Roles (Azure Management Groups / Subscriptions)
The next step within Azure is granting the JupiterOne Reader RBAC subscription role to read Azure Resource Manager information.
To grant the role:
- Navigate to the correct scope for your integration.
- RECOMMENDED If configuring all subscription for a tenant: Navigate to Management Groups > the Tenant Root Group.
If it is not possible to select the Tenant Root Group first navigate to Microsoft Entra ID > Manage > Properties and select Yes on Access management for Azure resources. See this elevating access article for more information.
If using this feature, in JupiterOne on your integration instance, enable the following flags:
- Ingest Microsoft Entra ID
- Configure Subscription Instances
- Auto-Delete Removed Subscriptions
If configuring a single Azure Subscription: Navigate to Subscriptions and choose the subscription from which you want to ingest resources. Please fill the Subscription ID field in your integration instance. In Azure, to get the Subscription ID navigate to Subscriptions and Copy the ID of the one to be ingested.
- Auto-Delete Removed Subscriptions
- Create the custom role "JupiterOne Reader"
- Navigate to Access control (IAM) > Add > Add custom role.
- Input
JupiterOne Readerfor the Name. - Navigate to the JSON tab, select Edit, and input the following actions:
Actions to be added
"Microsoft.Advisor/recommendations/read", "Microsoft.ApiManagement/service/apis/read", "Microsoft.ApiManagement/service/read", "Microsoft.Authorization/classicAdministrators/read", "Microsoft.Authorization/locks/read", "Microsoft.Authorization/policyAssignments/read", "Microsoft.Authorization/policyDefinitions/read", "Microsoft.Authorization/policySetDefinitions/read", "Microsoft.Authorization/roleAssignments/read", "Microsoft.Authorization/roleDefinitions/read", "Microsoft.Automation/automationAccounts/read", "Microsoft.Batch/batchAccounts/applications/read", "Microsoft.Batch/batchAccounts/certificates/read", "Microsoft.Batch/batchAccounts/pools/read", "Microsoft.Batch/batchAccounts/read", "Microsoft.BotService/botServices/read", "Microsoft.BotService/botServices/channels/read", "Microsoft.Cache/redis/firewallRules/read", "Microsoft.Cache/redis/linkedServers/read", "Microsoft.Cache/redis/read", "Microsoft.Cdn/profiles/endpoints/read", "Microsoft.Cdn/profiles/read", "Microsoft.CognitiveServices/accounts/read", "Microsoft.Compute/disks/read", "Microsoft.Compute/galleries/images/read", "Microsoft.Compute/galleries/images/versions/read", "Microsoft.Compute/galleries/read", "Microsoft.Compute/images/read", "Microsoft.Compute/virtualMachines/extensions/read", "Microsoft.Compute/virtualMachines/read", "Microsoft.Compute/virtualMachineScaleSets/read", "Microsoft.Consumption/usageDetails/read", "Microsoft.ContainerInstance/containerGroups/read", "Microsoft.ContainerRegistry/registries/read", "Microsoft.ContainerRegistry/registries/webhooks/read", "Microsoft.ContainerService/managedClusters/maintenanceConfigurations/read", "Microsoft.ContainerService/managedClusters/read", "Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/read", "Microsoft.DBforMariaDB/servers/databases/read", "Microsoft.DBforMariaDB/servers/read", "Microsoft.DBforMySQL/flexibleServers/databases/read", "Microsoft.DBforMySQL/flexibleServers/firewallRules/read", "Microsoft.DBforMySQL/flexibleServers/read", "Microsoft.DBforMySQL/servers/databases/read", "Microsoft.DBforMySQL/servers/firewallRules/read", "Microsoft.DBforMySQL/servers/read", "Microsoft.Databricks/workspaces/read", "Microsoft.DataProtection/backupVaults/read", "Microsoft.DBforPostgreSQL/flexibleServers/databases/read", "Microsoft.DBforPostgreSQL/flexibleServers/firewallRules/read", "Microsoft.DBforPostgreSQL/flexibleServers/read", "Microsoft.DBforPostgreSQL/servers/databases/read", "Microsoft.DBforPostgreSQL/servers/firewallRules/read", "Microsoft.DBforPostgreSQL/servers/read", "Microsoft.Devices/iotHubs/Read", "Microsoft.DocumentDB/databaseAccounts/read", "Microsoft.DocumentDB/databaseAccounts/sqlDatabases/read", "Microsoft.Easm/workspaces/read", "Microsoft.EventGrid/domains/read", "Microsoft.EventGrid/domains/topics/eventSubscriptions/read", "Microsoft.EventGrid/domains/topics/read", "Microsoft.EventGrid/topics/eventSubscriptions/read", "Microsoft.EventGrid/topics/read", "Microsoft.EventHub/clusters/read", "Microsoft.EventHub/namespaces/eventHubs/consumergroups/read", "Microsoft.EventHub/namespaces/eventhubs/read", "Microsoft.EventHub/namespaces/read", "Microsoft.Insights/ActivityLogAlerts/Read", "Microsoft.Insights/DiagnosticSettings/Read", "Microsoft.Insights/LogProfiles/Read", "Microsoft.KeyVault/managedHSMs/read", "Microsoft.KeyVault/vaults/keys/read", "Microsoft.KeyVault/vaults/read", "Microsoft.KeyVault/vaults/secrets/read", "Microsoft.MachineLearningServices/workspaces/read", "Microsoft.MachineLearningServices/workspaces/computes/read", "Microsoft.Management/managementGroups/read", "Microsoft.Network/applicationGateways/read", "Microsoft.Network/applicationSecurityGroups/read", "Microsoft.Network/azurefirewalls/read", "Microsoft.Network/bastionHosts/read", "Microsoft.Network/bgpServiceCommunities/read", "Microsoft.Network/ddosProtectionPlans/read", "Microsoft.Network/dnszones/read", "Microsoft.Network/dnszones/recordsets/read", "Microsoft.Network/expressRouteCircuits/peerings/connections/read", "Microsoft.Network/expressRouteCircuits/peerings/peerConnections/read", "Microsoft.Network/expressRouteCircuits/read", "Microsoft.Network/firewallPolicies/Read", "Microsoft.Network/firewallPolicies/ruleCollectionGroups/Read", "Microsoft.Network/frontDoors/read", "Microsoft.Network/loadBalancers/read", "Microsoft.Network/natGateways/read", "Microsoft.Network/networkInterfaces/read", "Microsoft.Network/networkSecurityGroups/read", "Microsoft.Network/networkWatchers/flowLogs/read", "Microsoft.Network/networkWatchers/read", "Microsoft.Network/privateDnsZones/read", "Microsoft.Network/privateDnsZones/recordsets/read", "Microsoft.Network/privateEndpoints/read", "Microsoft.Network/publicIPAddresses/read", "Microsoft.Network/virtualNetworks/read", "Microsoft.PolicyInsights/policyStates/queryResults/read", "Microsoft.RecoveryServices/vaults/read", "Microsoft.Resources/subscriptions/locations/read", "Microsoft.Resources/subscriptions/read", "Microsoft.Resources/subscriptions/resourceGroups/read", "Microsoft.Security/alerts/read", "Microsoft.Security/assessments/read", "Microsoft.Security/autoProvisioningSettings/read", "Microsoft.Security/iotSecuritySolutions/read", "Microsoft.Security/pricings/read", "Microsoft.Security/securityContacts/read", "Microsoft.Security/settings/read", "Microsoft.ServiceBus/namespaces/queues/read", "Microsoft.ServiceBus/namespaces/read", "Microsoft.ServiceBus/namespaces/topics/read", "Microsoft.ServiceBus/namespaces/topics/subscriptions/read", "Microsoft.Sql/managedInstances/administrators/read", "Microsoft.Sql/managedInstances/databases/read", "Microsoft.Sql/managedInstances/read", "Microsoft.Sql/servers/administrators/read", "Microsoft.Sql/servers/databases/read", "Microsoft.Sql/servers/firewallRules/read", "Microsoft.Sql/servers/read", "Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action", "Microsoft.Storage/storageAccounts/blobServices/containers/read", "Microsoft.Storage/storageAccounts/blobServices/read", "Microsoft.Storage/storageAccounts/fileServices/read", "Microsoft.Storage/storageAccounts/fileServices/shares/read", "Microsoft.Storage/storageAccounts/listKeys/action", "Microsoft.Storage/storageAccounts/queueServices/read", "Microsoft.Storage/storageAccounts/read", "Microsoft.Storage/storageAccounts/tableServices/read", "Microsoft.Storage/storageAccounts/tableServices/tables/read", "Microsoft.Subscription/policies/read", "Microsoft.Synapse/workspaces/keys/read", "Microsoft.Synapse/workspaces/read", "Microsoft.Synapse/workspaces/sqlPools/dataMaskingPolicies/read", "Microsoft.Synapse/workspaces/sqlPools/dataMaskingPolicies/rules/read", "Microsoft.Synapse/workspaces/sqlPools/read", "Microsoft.Web/serverfarms/Read", "Microsoft.Web/sites/config/list/action", "Microsoft.Web/sites/config/Read", "Microsoft.Web/sites/functions/read", "Microsoft.Web/sites/Read",
Data Actions to be added
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read"
-
Click Save > Review + Create > Create.
-
Assign Roles to the "JupiterOne" App:
- Navigate to Access control (IAM) > Add > Add role assignment
- Assign the
JupiterOne Readerrole to the JupiterOne member. - Navigate to the Member tab. Click on + Select Members, search for the JupiterOne App, click it, and then press Select.
- Navigate to the Review + assign tab and click Review + assign.
Key Vaults
Listing key vault keys and secrets (the rm-keyvault-keys and rm-keyvault-secrets steps) requires granting the JupiterOne security principal access to each key vault's data plane. Azure supports two authorization models, and which one you use depends on how each vault is configured.
Microsoft now recommends Azure role-based access control (RBAC), and many recently created key vaults use it by default. Check the Permission model field under Settings > Access configuration on the vault before choosing an option below.
Option A: Azure RBAC (default for new vaults)
When a vault's Permission model is Azure role-based access control, assign the built-in Key Vault Reader role to the JupiterOne app:
- Navigate to the key vault in the Azure portal.
- Click Access control (IAM) > Add > Add role assignment.
- On the Role tab, search for and select Key Vault Reader.
- On the Members tab, click + Select members, search for the JupiterOne app registration, select it, and click Select.
- Navigate to the Review + assign tab and click Review + assign.
You can scope the role assignment to the resource group or subscription that contains your key vaults to cover all of them at once, instead of repeating this for each vault.
Learn more on Azure about the RBAC guide for Key Vault
Option B: Vault access policy (legacy model)
When a vault's Permission model is Vault access policy, grant JupiterOne permissions for the vault keys and secrets (rm-keyvault-keys and rm-keyvault-secrets).
You are required to grant the permissions to the JupiterOne security principal for each key vault in your account. Learn more on Azure for assigning a key vault access policy
To grant the permissions:
- Navigate to Key Vaults and select the one you wish to ingest.
- Click Access policies, then + Create
- On the Permissions tab, under Key permissions and Secret Permissions, select the permissions.
- Key Permissions
- Key Management Operations
- List
- Key Management Operations
- Secret Permissions
- Key Management Operations
- List
- Key Management Operations
- On the Principal tab, assign them to the JupiterOne App.
- Navigate to the Review + Create tab and click Create.
That concludes the setup from within Azure. The last thing to do is initiate the integration from within JupiterOne!
Data Volume Configuration
Control how much data is ingested from Azure to manage storage and processing.
Ingestion Windows (Time Ranges)
| Field | Description | Default | Options |
|---|---|---|---|
| Active Device Window | Maximum number of days in the past a device can be active to be eligible for ingestion. Devices with activity older than this threshold will be excluded. | 30 | 30, 90, 365 days, No limit |
How it affects data volume: A longer active device window increases the number of device entities ingested. Setting "No limit" ingests all devices regardless of last activity date.
Data Filtering Options
| Field | Description | Default |
|---|---|---|
| Included Defender for cloud Alert Severities | Select which Defender for Cloud alert severity levels to ingest. | High, Medium |
| Container Registry Exclude List | Comma-separated list of container registry names to exclude from repository ingestion. Registries listed here are skipped when the Container registry repositories ingestion source is enabled. | (none — all registries included) |
How it affects data volume: Severity filtering reduces Defender alert entities by excluding lower-severity alerts. The Container Registry Exclude List reduces repository ingestion for specific registries.
Advanced Configuration
| Field | Description | Default |
|---|---|---|
| Advisor Recommendation Extended Properties to Promote | A list of Azure Advisor recommendation property names to surface as top-level properties on ingested recommendation entities. Each key is automatically converted to camelCase. Example: assessmentKey, score, snake_case_key. | (none) |
Configuration in JupiterOne
To add the Azure integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Azure. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the Azure account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
Your Azure Directory (tenant) ID of the Entra ID to target the Azure API requests.
-
The Application (client) ID created for JupiterOne and used to authenticate with Azure.
-
Enable Ingest Microsoft Entra ID to ingest Directory information.
noteThe Ingest Microsoft Entra ID flag enables the ingestion of
azure_user,azure_user_group, andazure_service_principalentities.This should only be enabled for one integration instance per directory.
-
Configure the Subscription Instances for your integration:
- RECOMMENDED If configuring all subscriptions for a tenant: Select the option Configure Subscription Instances to automatically provision new JupiterOne integration instances for each Azure Subscription in this tenant that does not have a "JupiterOne" tag set to
SKIP. It is recommended that you use this feature when Ingest Microsoft Entra ID selected. - If configuring a single Azure Subscription: Enter the Subscription ID for the subscription you wish to ingest data from. In Azure, to get the Subscription ID, navigate to Subscriptions and copy the desired Subscription ID.
With Configure Subscription Instances enabled, the following additional options are available:
- Auto-delete Removed Subscriptions — when enabled, automatically deletes JupiterOne integration instances for subscriptions that have been deleted or removed from Azure. Disabled by default.
- Ingest disabled subscriptions — when enabled, ingests subscriptions that are in a
disabledstate. Disabled by default. - Auto-delete Child Integrations — when enabled, automatically deletes child integration instances when the parent integration for this directory is deleted. Enabled by default.
- RECOMMENDED If configuring all subscriptions for a tenant: Select the option Configure Subscription Instances to automatically provision new JupiterOne integration instances for each Azure Subscription in this tenant that does not have a "JupiterOne" tag set to
Once all values have been provided, click Create to finalize the integration.
Troubleshooting authentication
If the Azure integration job does not complete, and you encounter a message such as:
[validation_failure] Error occurred while validating integration configuration
in your job log, check the following common configuration errors:
-
Verify the Application (client) ID and Application (client) Secret: Make sure that you've verified the proper value for client ID and client secret. The client secret has both a Value property and a Secret ID property. The Secret ID is unused: make sure you haven't accidentally used the Secret ID as the Client ID.
-
Verify that you've enabled the proper API permissions: Make sure the required API permissions (described above) are enabled for the application.
-
Verify that the API permissions have been granted as "Application" and not "Delegated": The integration requires API Permissions of type Application. Permissions of type Delegated will cause issues in your integration.
-
Verify that your permissions have been "Grant(ed) admin consent for Directory": If you have added API Permissions to the application, but have not granted Admin Consent, the permissions are not yet active.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Permissions
IAM permissions that must be granted to the integration principal for data ingestion.
Show Permissions (231)
AccessReview.Read.AllAccessReview.ReadWrite.AllAccessReview.ReadWrite.MembershipMicrosoft.Advisor/recommendations/readMicrosoft.ApiManagement/service/apis/readMicrosoft.ApiManagement/service/backends/readMicrosoft.ApiManagement/service/namedValues/readMicrosoft.ApiManagement/service/portalconfigs/readMicrosoft.ApiManagement/service/portalsettings/readMicrosoft.ApiManagement/service/products/readMicrosoft.ApiManagement/service/products/subscriptions/readMicrosoft.ApiManagement/service/readMicrosoft.ApiManagement/service/subscriptions/readMicrosoft.ApiManagement/service/tenant/readMicrosoft.App/agents/readMicrosoft.AppConfiguration/configurationStores/readMicrosoft.Authorization/classicAdministrators/readMicrosoft.Authorization/locks/readMicrosoft.Authorization/policyAssignments/readMicrosoft.Authorization/policyDefinitions/readMicrosoft.Authorization/policySetDefinitions/readMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/readMicrosoft.Automation/automationAccounts/readMicrosoft.AzureArcData/sqlServerInstances/databases/readMicrosoft.AzureArcData/sqlServerInstances/readMicrosoft.Batch/batchAccounts/applications/readMicrosoft.Batch/batchAccounts/certificates/readMicrosoft.Batch/batchAccounts/pools/readMicrosoft.Batch/batchAccounts/readMicrosoft.BotService/botServices/channels/readMicrosoft.BotService/botServices/readMicrosoft.Cache/redis/firewallRules/readMicrosoft.Cache/redis/linkedServers/readMicrosoft.Cache/redis/readMicrosoft.Cache/redisEnterprise/databases/readMicrosoft.Cache/redisEnterprise/readMicrosoft.Cdn/profiles/afdEndpoints/readMicrosoft.Cdn/profiles/afdEndpoints/routes/readMicrosoft.Cdn/profiles/customDomains/readMicrosoft.Cdn/profiles/endpoints/readMicrosoft.Cdn/profiles/originGroups/origins/readMicrosoft.Cdn/profiles/originGroups/readMicrosoft.Cdn/profiles/readMicrosoft.Chaos/experiments/readMicrosoft.Chaos/targets/capabilities/readMicrosoft.Chaos/targets/readMicrosoft.CognitiveServices/accounts/readMicrosoft.Compute/disks/readMicrosoft.Compute/galleries/images/readMicrosoft.Compute/galleries/images/versions/readMicrosoft.Compute/galleries/readMicrosoft.Compute/images/readMicrosoft.Compute/virtualMachineScaleSets/readMicrosoft.Compute/virtualMachines/extensions/readMicrosoft.Compute/virtualMachines/readMicrosoft.Consumption/usageDetails/readMicrosoft.ContainerInstance/containerGroups/readMicrosoft.ContainerRegistry/registries/pull/readMicrosoft.ContainerRegistry/registries/readMicrosoft.ContainerRegistry/registries/webhooks/readMicrosoft.ContainerService/fleets/members/readMicrosoft.ContainerService/fleets/readMicrosoft.ContainerService/managedClusters/maintenanceConfigurations/readMicrosoft.ContainerService/managedClusters/readMicrosoft.ContainerService/managedClusters/trustedAccessRoleBindings/readMicrosoft.DBforMariaDB/servers/databases/readMicrosoft.DBforMariaDB/servers/readMicrosoft.DBforMySQL/flexibleServers/databases/readMicrosoft.DBforMySQL/flexibleServers/firewallRules/readMicrosoft.DBforMySQL/flexibleServers/readMicrosoft.DBforMySQL/servers/databases/readMicrosoft.DBforMySQL/servers/firewallRules/readMicrosoft.DBforMySQL/servers/readMicrosoft.DBforPostgreSQL/flexibleServers/administrators/readMicrosoft.DBforPostgreSQL/flexibleServers/advancedThreatProtectionSettings/readMicrosoft.DBforPostgreSQL/flexibleServers/configurations/readMicrosoft.DBforPostgreSQL/flexibleServers/databases/readMicrosoft.DBforPostgreSQL/flexibleServers/firewallRules/readMicrosoft.DBforPostgreSQL/flexibleServers/privateEndpointConnections/readMicrosoft.DBforPostgreSQL/flexibleServers/readMicrosoft.DBforPostgreSQL/servers/databases/readMicrosoft.DBforPostgreSQL/servers/firewallRules/readMicrosoft.DBforPostgreSQL/servers/readMicrosoft.DataFactory/factories/integrationRuntimes/readMicrosoft.DataFactory/factories/linkedservices/readMicrosoft.DataFactory/factories/managedVirtualNetworks/managedPrivateEndpoints/readMicrosoft.DataFactory/factories/managedVirtualNetworks/readMicrosoft.DataFactory/factories/privateEndpointConnections/readMicrosoft.DataFactory/factories/readMicrosoft.DataMigration/services/projects/readMicrosoft.DataMigration/services/readMicrosoft.DataMigration/services/serviceTasks/readMicrosoft.DataProtection/backupVaults/readMicrosoft.DataShare/accounts/readMicrosoft.Databricks/workspaces/readMicrosoft.DesktopVirtualization/applicationGroups/desktops/readMicrosoft.DesktopVirtualization/applicationGroups/readMicrosoft.DesktopVirtualization/hostPools/readMicrosoft.DesktopVirtualization/workspaces/readMicrosoft.Devices/iotHubs/ReadMicrosoft.DocumentDB/databaseAccounts/readMicrosoft.DocumentDB/databaseAccounts/sqlDatabases/readMicrosoft.Easm/workspaces/readMicrosoft.EventGrid/domains/readMicrosoft.EventGrid/domains/topics/eventSubscriptions/readMicrosoft.EventGrid/domains/topics/readMicrosoft.EventGrid/topics/eventSubscriptions/readMicrosoft.EventGrid/topics/readMicrosoft.EventHub/clusters/readMicrosoft.EventHub/namespaces/eventHubs/consumergroups/readMicrosoft.EventHub/namespaces/eventhubs/readMicrosoft.EventHub/namespaces/readMicrosoft.Fabric/capacities/readMicrosoft.HybridCompute/machines/extensions/readMicrosoft.HybridCompute/machines/readMicrosoft.Insights/ActivityLogAlerts/ReadMicrosoft.Insights/DiagnosticSettings/ReadMicrosoft.Insights/LogProfiles/ReadMicrosoft.Insights/components/readMicrosoft.Insights/eventtypes/values/ReadMicrosoft.KeyVault/managedHSMs/readMicrosoft.KeyVault/vaults/keys/readMicrosoft.KeyVault/vaults/readMicrosoft.KeyVault/vaults/secrets/readMicrosoft.KeyVault/vaults/secrets/readMetadata/actionMicrosoft.MachineLearningServices/workspaces/computes/readMicrosoft.MachineLearningServices/workspaces/onlineEndpoints/readMicrosoft.MachineLearningServices/workspaces/readMicrosoft.ManagedIdentity/userAssignedIdentities/readMicrosoft.ManagedServices/registrationAssignments/readMicrosoft.ManagedServices/registrationDefinitions/readMicrosoft.Management/managementGroups/readMicrosoft.Network/applicationGateways/readMicrosoft.Network/applicationSecurityGroups/readMicrosoft.Network/azurefirewalls/readMicrosoft.Network/bastionHosts/readMicrosoft.Network/bgpServiceCommunities/readMicrosoft.Network/ddosProtectionPlans/readMicrosoft.Network/dnszones/readMicrosoft.Network/dnszones/recordsets/readMicrosoft.Network/expressRouteCircuits/peerings/connections/readMicrosoft.Network/expressRouteCircuits/peerings/peerConnections/readMicrosoft.Network/expressRouteCircuits/readMicrosoft.Network/firewallPolicies/ReadMicrosoft.Network/firewallPolicies/ruleCollectionGroups/ReadMicrosoft.Network/frontDoors/readMicrosoft.Network/loadBalancers/readMicrosoft.Network/natGateways/readMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkSecurityGroups/readMicrosoft.Network/networkSecurityGroups/securityRules/readMicrosoft.Network/networkWatchers/flowLogs/readMicrosoft.Network/networkWatchers/readMicrosoft.Network/privateDnsZones/readMicrosoft.Network/privateDnsZones/recordsets/readMicrosoft.Network/privateDnsZones/virtualNetworkLinks/readMicrosoft.Network/privateEndpoints/readMicrosoft.Network/publicIPAddresses/readMicrosoft.Network/routeTables/readMicrosoft.Network/trafficmanagerprofiles/readMicrosoft.Network/virtualHubs/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualWans/readMicrosoft.Network/vpnGateways/readMicrosoft.Network/vpnGateways/vpnConnections/vpnLinkConnections/readMicrosoft.OperationalInsights/workspaces/readMicrosoft.PolicyInsights/policyStates/queryResults/readMicrosoft.PowerBI/privateLinkServicesForPowerBI/readMicrosoft.RecoveryServices/Vaults/backupProtectedItems/readMicrosoft.RecoveryServices/vaults/readMicrosoft.Resources/deployments/readMicrosoft.Resources/subscriptions/locations/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.ScVmm/virtualMachineInstances/readMicrosoft.Search/searchServices/listAdminKeys/actionMicrosoft.Search/searchServices/readMicrosoft.Security/alerts/readMicrosoft.Security/assessments/readMicrosoft.Security/autoProvisioningSettings/readMicrosoft.Security/iotSecuritySolutions/readMicrosoft.Security/pricings/readMicrosoft.Security/securityContacts/readMicrosoft.Security/settings/readMicrosoft.ServiceBus/namespaces/queues/readMicrosoft.ServiceBus/namespaces/readMicrosoft.ServiceBus/namespaces/topics/readMicrosoft.ServiceBus/namespaces/topics/subscriptions/readMicrosoft.Sql/managedInstances/administrators/readMicrosoft.Sql/managedInstances/databases/readMicrosoft.Sql/managedInstances/readMicrosoft.Sql/servers/administrators/readMicrosoft.Sql/servers/databases/readMicrosoft.Sql/servers/firewallRules/readMicrosoft.Sql/servers/readMicrosoft.SqlVirtualMachine/sqlVirtualMachines/readMicrosoft.Storage/storageAccounts/blobServices/containers/readMicrosoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/actionMicrosoft.Storage/storageAccounts/blobServices/readMicrosoft.Storage/storageAccounts/fileServices/readMicrosoft.Storage/storageAccounts/fileServices/shares/readMicrosoft.Storage/storageAccounts/listKeys/actionMicrosoft.Storage/storageAccounts/queueServices/readMicrosoft.Storage/storageAccounts/readMicrosoft.Storage/storageAccounts/tableServices/readMicrosoft.Storage/storageAccounts/tableServices/tables/readMicrosoft.StreamAnalytics/clusters/privateEndpoints/readMicrosoft.StreamAnalytics/clusters/readMicrosoft.StreamAnalytics/streamingjobs/readMicrosoft.Subscription/policies/readMicrosoft.Synapse/workspaces/keys/readMicrosoft.Synapse/workspaces/readMicrosoft.Synapse/workspaces/sqlPools/dataMaskingPolicies/readMicrosoft.Synapse/workspaces/sqlPools/dataMaskingPolicies/rules/readMicrosoft.Synapse/workspaces/sqlPools/readMicrosoft.Web/serverfarms/ReadMicrosoft.Web/sites/ReadMicrosoft.Web/sites/config/ReadMicrosoft.Web/sites/config/list/actionMicrosoft.Web/sites/functions/readMicrosoft.Web/staticSites/ReadMicrosoft.Web/staticSites/basicAuth/readMicrosoft.Web/staticSites/builds/ReadMicrosoft.Web/staticSites/customDomains/ReadMicrosoft.Web/staticSites/listAppSettings/actionOracle.Database/cloudExadataInfrastructures/dbServers/readOracle.Database/cloudExadataInfrastructures/readOracle.Database/cloudVmClusters/dbNodes/readOracle.Database/dbSystems/readOracle.Database/exadbVmClusters/read
OAuth Scopes
OAuth scopes that must be granted to the application or service principal.
Show OAuth Scopes (8)
Application.Read.AllAuditLog.Read.AllDevice.Read.AllDirectory.Read.AllDomain.Read.AllEntitlementManagement.Read.AllPolicy.Read.AllPolicy.Read.ConditionalAccess
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (8)
- https://learn.microsoft.com/en-us/azure/key-vault/general/assign-access-policy
- https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide
- https://learn.microsoft.com/en-us/azure/virtual-machines/overview
- https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-network-interface
- https://learn.microsoft.com/en-us/graph/api/conditionalaccesstemplate-get
- https://learn.microsoft.com/en-us/graph/api/resources/authenticationcontextclassreference
- https://learn.microsoft.com/en-us/graph/api/resources/conditionalaccesspolicy
- https://learn.microsoft.com/en-us/graph/api/resources/namedlocation
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (334)
| Step | Permissions | OAuth Scopes |
|---|---|---|
| Access Package Assignment Contains Access Package Assignment Policy | - | - |
| Access Package HAS Access Package Assignment | - | - |
| Access Reviews | AccessReview.Read.All, AccessReview.ReadWrite.All, AccessReview.ReadWrite.Membership | - |
| AI Search Service Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| AI Search Services | Microsoft.Search/searchServices/read, Microsoft.Search/searchServices/listAdminKeys/action, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| API Management APIs | Microsoft.ApiManagement/service/apis/read | - |
| API Management Backends | Microsoft.ApiManagement/service/backends/read | - |
| API Management Named Values | Microsoft.ApiManagement/service/namedValues/read | - |
| API Management Portal Config | Microsoft.ApiManagement/service/portalconfigs/read | - |
| API Management Product Subscription Relationships | Microsoft.ApiManagement/service/products/subscriptions/read | - |
| API Management Products | Microsoft.ApiManagement/service/products/read | - |
| API Management Services | Microsoft.ApiManagement/service/read, Microsoft.ApiManagement/service/portalsettings/read | - |
| API Management Services Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| API Management Subscriptions | Microsoft.ApiManagement/service/subscriptions/read | - |
| API Management Tenant Access | Microsoft.ApiManagement/service/tenant/read | - |
| App Configuration Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| App Configuration Stores | Microsoft.AppConfiguration/configurationStores/read | - |
| App Service Apps | Microsoft.Web/sites/Read, Microsoft.Web/sites/config/Read, Microsoft.Web/sites/config/list/action | - |
| App Service Functions | Microsoft.Web/sites/functions/read | - |
| App Service Plans | Microsoft.Web/serverfarms/Read | - |
| Application Insights Components | Microsoft.Insights/components/read | - |
| Application Insights Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Application Security Group | Microsoft.Network/applicationSecurityGroups/read | - |
| ARM Deployments | Microsoft.Resources/deployments/read | - |
| Automation Account -> Private Endpoint Relationships | Microsoft.Automation/automationAccounts/read | - |
| Automation Accounts | Microsoft.Automation/automationAccounts/read | - |
| Automation Accounts Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Azure Access Package Has Application | - | - |
| Azure Application Gateway | Microsoft.Network/applicationGateways/read | - |
| Azure Arc Machine Extensions | Microsoft.HybridCompute/machines/extensions/read | - |
| Azure Arc Machines | Microsoft.HybridCompute/machines/read | - |
| Azure Arc SCVMM Virtual Machine Instances | Microsoft.ScVmm/virtualMachineInstances/read | - |
| Azure Arc SQL Server Databases | Microsoft.AzureArcData/sqlServerInstances/databases/read | - |
| Azure Arc SQL Server Instances | Microsoft.AzureArcData/sqlServerInstances/read | - |
| Azure Bgp Service Communities | Microsoft.Network/bgpServiceCommunities/read | - |
| Azure Consumer Group | Microsoft.EventHub/namespaces/eventHubs/consumergroups/read | - |
| Azure Content Safety Accounts | Microsoft.CognitiveServices/accounts/read, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Azure Event Hub | Microsoft.EventHub/namespaces/eventhubs/read | - |
| Azure Group assigned to Access Package | - | - |
| Azure Language Accounts | Microsoft.CognitiveServices/accounts/read, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Azure OpenAI Accounts | Microsoft.CognitiveServices/accounts/read, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Azure Peer Express Route Connection | Microsoft.Network/expressRouteCircuits/peerings/peerConnections/read | - |
| Azure Speech Accounts | Microsoft.CognitiveServices/accounts/read, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Azure user assigned to Access Package | - | - |
| Azure user Created Entitlement Management Access Package Request | - | - |
| Bastion Hosts | Microsoft.Network/bastionHosts/read | - |
| Batch Accounts | Microsoft.Batch/batchAccounts/read | - |
| Batch Accounts Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Batch Applications | Microsoft.Batch/batchAccounts/applications/read | - |
| Batch Certificates | Microsoft.Batch/batchAccounts/certificates/read | - |
| Batch Pools | Microsoft.Batch/batchAccounts/pools/read | - |
| Bot Service Bot -> Private Endpoint Relationships | Microsoft.BotService/botServices/read | - |
| Bot Service Bots | Microsoft.BotService/botServices/read | - |
| Bot Service Channels | Microsoft.BotService/botServices/channels/read | - |
| Bot Service Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Build Azure Application Ownership Relationships | - | Application.Read.All |
| Build Ddos Protection Plan Public Ip Relationship | - | - |
| Build Ddos Protection Plan Vnet Relationship | - | - |
| Build Fabric Capacity–Workspace Relationship | - | - |
| Build Fabric Report-Semantic Model Relationships | - | - |
| Build Fabric Semantic Model-Data Source Relationships | - | - |
| Build Key Vault Service Synapse Keys Relationship | - | - |
| Build Power BI Private Link Service–Private Endpoint Relationship | - | - |
| Build Resource Group Ddos Protection Plan Relationship | - | - |
| Build Synapse Service and key Relationship | - | - |
| Build Synapse Service and SQL Pool Relationship | - | - |
| Build Synapse Service and Workspace Relationship | - | - |
| Build Synapse SQL Pool Data Masking Policy Relationship | - | - |
| Build Synapse Sql Pool Data Masking Rule Relationship | - | - |
| Build Synapse Workspace and Keys Relationship | - | - |
| Build Synapse Workspace and SQL Pool Relationship | - | - |
| CDN Endpoints | Microsoft.Cdn/profiles/endpoints/read | - |
| CDN Endpoints Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| CDN Profiles | Microsoft.Cdn/profiles/read | - |
| CDN Profiles Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Chaos Studio Capabilities | Microsoft.Chaos/targets/capabilities/read | - |
| Chaos Studio Experiment Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Chaos Studio Experiments | Microsoft.Chaos/experiments/read | - |
| Chaos Studio Targets | Microsoft.Chaos/targets/read | - |
| Classic Administrators | Microsoft.Authorization/classicAdministrators/read | - |
| Cognitive Services Accounts | Microsoft.CognitiveServices/accounts/read, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Compute Network Relationships | - | - |
| Conditional Access Has Conditional Access Auth Context Relationships | - | - |
| Conditional Access Has Conditional Access Policy Relationships | - | - |
| Conditional Access Has Conditional Access Template Relationships | - | - |
| Conditional Access Policy Assigned AD Groups Relationships | - | - |
| Conditional Access Policy Assigned AD Users Relationships | - | - |
| Conditional Access Policy Contains Named Location Relationships | - | - |
| Container Groups | Microsoft.ContainerInstance/containerGroups/read | - |
| Container Registries | Microsoft.ContainerRegistry/registries/read | - |
| Container Registries Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Container Registry Repositories | Microsoft.ContainerRegistry/registries/pull/read | - |
| Container Registry Webhooks | Microsoft.ContainerRegistry/registries/webhooks/read | - |
| CosmosDB SQL Databases | Microsoft.DocumentDB/databaseAccounts/read, Microsoft.DocumentDB/databaseAccounts/sqlDatabases/read | - |
| Data Factory -> Private Endpoint Relationships | Microsoft.DataFactory/factories/privateEndpointConnections/read | - |
| Data Factory Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Data Factory Instances | Microsoft.DataFactory/factories/read | - |
| Data Factory Integration Runtimes | Microsoft.DataFactory/factories/integrationRuntimes/read | - |
| Data Factory Linked Services | Microsoft.DataFactory/factories/linkedservices/read | - |
| Data Factory Managed Private Endpoints | Microsoft.DataFactory/factories/managedVirtualNetworks/managedPrivateEndpoints/read | - |
| Data Factory Managed Virtual Networks | Microsoft.DataFactory/factories/managedVirtualNetworks/read | - |
| Data Migration Projects | Microsoft.DataMigration/services/projects/read | - |
| Data Migration Service Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Data Migration Services | Microsoft.DataMigration/services/read | - |
| Data Migration Tasks | Microsoft.DataMigration/services/serviceTasks/read | - |
| Data Protection Backup Vaults | Microsoft.DataProtection/backupVaults/read | - |
| Data Protection Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Data Share Accounts | Microsoft.DataShare/accounts/read | - |
| Data Share Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Databricks Workspaces | Microsoft.Databricks/workspaces/read | - |
| Defender Alerts | Microsoft.Security/alerts/read | - |
| Defender EASM Workspaces | Microsoft.Easm/workspaces/read | - |
| Desktop Virtualization Application Groups | Microsoft.DesktopVirtualization/applicationGroups/read | - |
| Desktop Virtualization Desktops | Microsoft.DesktopVirtualization/applicationGroups/desktops/read | - |
| Desktop Virtualization Host Pool Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Desktop Virtualization Host Pools | Microsoft.DesktopVirtualization/hostPools/read | - |
| Desktop Virtualization Workspace Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Desktop Virtualization Workspaces | Microsoft.DesktopVirtualization/workspaces/read | - |
| DNS Record Sets | Microsoft.Network/dnszones/recordsets/read | - |
| DNS Zones | Microsoft.Network/dnszones/read | - |
| Document Intelligence Accounts | Microsoft.CognitiveServices/accounts/read, Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Document Intelligence Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Entitlement Management Access Package Approver IS Azure User | - | - |
| Entitlement Management Access Package Assignment Approver | - | EntitlementManagement.Read.All |
| Entitlement Management Resource Application Assigned To Access Catalog | - | - |
| Entra ID Authentication Methods Policy | - | Policy.Read.All |
| Entra ID Authentication Strength Policy | - | Policy.Read.All |
| Entra ID Authorization Policy | - | Policy.Read.All |
| Entra ID Device Registration Policy | - | Policy.Read.All |
| Entra ID Group Members | - | Directory.Read.All |
| Entra ID Groups | - | Directory.Read.All |
| Entra ID OAuth2 Permission Grants | - | Directory.Read.All |
| Entra ID Role Definitions | - | Directory.Read.All |
| Entra ID Service Principal Access | - | Directory.Read.All |
| Entra ID Service Principals | - | Directory.Read.All |
| Entra ID Users | - | Directory.Read.All |
| Event Grid Domain Topic Subscriptions | Microsoft.EventGrid/domains/topics/eventSubscriptions/read | - |
| Event Grid Domain Topics | Microsoft.EventGrid/domains/topics/read | - |
| Event Grid Domains | Microsoft.EventGrid/domains/read | - |
| Event Grid Domains Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Event Grid Topic Subscriptions | Microsoft.EventGrid/topics/eventSubscriptions/read | - |
| Event Grid Topics | Microsoft.EventGrid/topics/read, Microsoft.Insights/DiagnosticSettings/Read | - |
| Event Grid Topics Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Event Hub Cluster | Microsoft.EventHub/clusters/read | - |
| Event Hub Namespace | Microsoft.EventHub/namespaces/read | - |
| Express Route Circuit | Microsoft.Network/expressRouteCircuits/read | - |
| Express Route Circuit Connection | Microsoft.Network/expressRouteCircuits/peerings/connections/read | - |
| Fetch application credentials | - | - |
| Fetch Container Maintenance Configurations | Microsoft.ContainerService/managedClusters/maintenanceConfigurations/read | - |
| Fetch Container Services Clusters | Microsoft.ContainerService/managedClusters/read | - |
| Fetch Ddos Protection Plan | Microsoft.Network/ddosProtectionPlans/read | - |
| Fetch Fabric Capacities | Microsoft.Fabric/capacities/read | - |
| Fetch Fabric Capacity Tenant Setting Overrides | - | - |
| Fetch Fabric Domain Tenant Setting Overrides | - | - |
| Fetch Fabric Domains | - | - |
| Fetch Fabric Tenant Settings | - | - |
| Fetch Fabric Workspace Artifacts | - | - |
| Fetch Fabric Workspace Tenant Setting Overrides | - | - |
| Fetch Fabric Workspaces | - | - |
| Fetch Front Door AFD Custom Domains | Microsoft.Cdn/profiles/customDomains/read | - |
| Fetch Front Door AFD Endpoints | Microsoft.Cdn/profiles/afdEndpoints/read | - |
| Fetch Front Door AFD Origin Groups | Microsoft.Cdn/profiles/originGroups/read | - |
| Fetch Front Door AFD Origins | Microsoft.Cdn/profiles/originGroups/origins/read | - |
| Fetch Front Door AFD Profiles | Microsoft.Cdn/profiles/read | - |
| Fetch Front Door AFD Routes | Microsoft.Cdn/profiles/afdEndpoints/routes/read | - |
| Fetch FrontDoors | Microsoft.Network/frontDoors/read | - |
| Fetch Power BI Private Link Services | Microsoft.PowerBI/privateLinkServicesForPowerBI/read | - |
| Fetch Synapse Data Masking Policy | Microsoft.Synapse/workspaces/sqlPools/dataMaskingPolicies/read | - |
| Fetch Synapse Data Masking Rule | Microsoft.Synapse/workspaces/sqlPools/dataMaskingPolicies/rules/read | - |
| Fetch Synapse Keys | Microsoft.Synapse/workspaces/keys/read | - |
| Fetch Traffic Manager Profiles | Microsoft.Network/trafficmanagerprofiles/read | - |
| Fetch Trusted Access Roles | Microsoft.ContainerService/managedClusters/trustedAccessRoleBindings/read | - |
| Fetch Virtual Hubs | Microsoft.Network/virtualHubs/read | - |
| Fetch Virtual WANs | Microsoft.Network/virtualWans/read | - |
| Fetch VPN Connections | Microsoft.Network/vpnGateways/read | - |
| Fetch VPN Gateways | Microsoft.Network/vpnGateways/read | - |
| Fetch VPN Link Connections | Microsoft.Network/vpnGateways/vpnConnections/vpnLinkConnections/read | - |
| Front Door AFD Profile Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Galleries | Microsoft.Compute/galleries/read | - |
| Gallery Shared Image Versions | Microsoft.Compute/galleries/images/versions/read | - |
| Gallery Shared Images | Microsoft.Compute/galleries/images/read | - |
| Group Setting Templates | - | Directory.Read.All |
| Group Settings | - | Directory.Read.All |
| IoT Hub Security Solution Relationships | - | - |
| IoT Hubs | Microsoft.Devices/iotHubs/Read | - |
| IoT Security Solutions | Microsoft.Security/iotSecuritySolutions/read | - |
| Key Vault Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Key Vault Keys | Microsoft.KeyVault/vaults/keys/read | - |
| Key Vault Secrets | Microsoft.KeyVault/vaults/secrets/readMetadata/action, Microsoft.KeyVault/vaults/secrets/read | - |
| Key Vaults | Microsoft.KeyVault/vaults/read | - |
| Kubernetes Fleet Managers | Microsoft.ContainerService/fleets/read | - |
| Kubernetes Fleet Members | Microsoft.ContainerService/fleets/members/read | - |
| Load Balancer Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Load Balancers | Microsoft.Network/loadBalancers/read | - |
| Load Balancers NIC Relationships | - | - |
| Log Analytics Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Log Analytics Workspaces | Microsoft.OperationalInsights/workspaces/read | - |
| Machine Learning Compute | Microsoft.MachineLearningServices/workspaces/computes/read | - |
| Machine Learning Online Endpoints | Microsoft.MachineLearningServices/workspaces/onlineEndpoints/read | - |
| Machine Learning Workspace -> Private Endpoint Relationships | Microsoft.MachineLearningServices/workspaces/read | - |
| Machine Learning Workspace Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Machine Learning Workspaces | Microsoft.MachineLearningServices/workspaces/read | - |
| Managed HSMs | Microsoft.KeyVault/managedHSMs/read | - |
| Managed Identities (User-Assigned) | Microsoft.ManagedIdentity/userAssignedIdentities/read | - |
| Managed Services Registration Assignments | Microsoft.ManagedServices/registrationAssignments/read | - |
| Managed Services Registration Definitions | Microsoft.ManagedServices/registrationDefinitions/read | - |
| Management Groups | Microsoft.Management/managementGroups/read | - |
| MariaDB Databases | Microsoft.DBforMariaDB/servers/databases/read, Microsoft.DBforMariaDB/servers/read | - |
| MariaDB Databases Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Monitor Activity Log Alerts | Microsoft.Insights/ActivityLogAlerts/Read | - |
| Monitor Activity Log Events | Microsoft.Insights/eventtypes/values/Read | - |
| Monitor Log Profiles | Microsoft.Insights/LogProfiles/Read | - |
| MySQL Databases | Microsoft.DBforMySQL/servers/read, Microsoft.DBforMySQL/servers/databases/read | - |
| MySQL Databases Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| MySQL Flexible Databases | Microsoft.DBforMySQL/flexibleServers/databases/read | - |
| MySQL Flexible Server Firewall Rules | Microsoft.DBforMySQL/flexibleServers/firewallRules/read | - |
| MySQL Flexible Servers | Microsoft.DBforMySQL/flexibleServers/read | - |
| MySQL Server Firewall Rules | Microsoft.DBforMySQL/servers/firewallRules/read | - |
| Network Application Gateway Ip Relationships | - | - |
| Network Azure Firewalls | Microsoft.Network/azurefirewalls/read | - |
| Network Azure Firewalls Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Network Firewall IP Relationships | - | - |
| Network Firewall Policies | Microsoft.Network/firewallPolicies/Read | - |
| Network Firewall Rules Relationships | Microsoft.Network/firewallPolicies/ruleCollectionGroups/Read | - |
| Network Interfaces | Microsoft.Network/networkInterfaces/read | - |
| Network Load Balancers IP Relationships | - | - |
| Network NAT Gateways | Microsoft.Network/natGateways/read | - |
| Network NAT Gateways IP Relationships | - | - |
| Network Security Group Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Network Security Group NIC Relationships | - | - |
| Network Security Groups | Microsoft.Network/networkSecurityGroups/read | - |
| Network Security Rules | Microsoft.Network/networkSecurityGroups/securityRules/read | - |
| Network Securtiy Group Flow Logs | Microsoft.Network/networkWatchers/flowLogs/read | - |
| Network Watchers | Microsoft.Network/networkWatchers/read | - |
| Oracle DB Nodes | Oracle.Database/cloudVmClusters/dbNodes/read | - |
| Oracle DB Servers | Oracle.Database/cloudExadataInfrastructures/dbServers/read | - |
| Oracle DB Systems | Oracle.Database/dbSystems/read | - |
| Oracle Exadata Infrastructures | Oracle.Database/cloudExadataInfrastructures/read | - |
| Oracle ExaDB VM Clusters | Oracle.Database/exadbVmClusters/read | - |
| Policy Assignments | Microsoft.Authorization/policyAssignments/read | - |
| Policy Definitions | Microsoft.Authorization/policyDefinitions/read, Microsoft.Authorization/policySetDefinitions/read | - |
| Policy States | Microsoft.PolicyInsights/policyStates/queryResults/read | - |
| PostgreSQL Databases | Microsoft.DBforPostgreSQL/servers/databases/read | - |
| PostgreSQL Flexible Databases | Microsoft.DBforPostgreSQL/flexibleServers/databases/read | - |
| PostgreSQL Flexible Server Configurations | Microsoft.DBforPostgreSQL/flexibleServers/configurations/read | - |
| PostgreSQL Flexible Server Entra Admins | Microsoft.DBforPostgreSQL/flexibleServers/administrators/read | - |
| PostgreSQL Flexible Server Firewall Rules | Microsoft.DBforPostgreSQL/flexibleServers/firewallRules/read | - |
| PostgreSQL Flexible Server Key Vault Relationships | - | - |
| PostgreSQL Flexible Server Private Endpoint Relationships | Microsoft.DBforPostgreSQL/flexibleServers/privateEndpointConnections/read | - |
| PostgreSQL Flexible Server Replicas | Microsoft.DBforPostgreSQL/flexibleServers/read | - |
| PostgreSQL Flexible Server Subnet Relationships | - | - |
| PostgreSQL Flexible Servers | Microsoft.DBforPostgreSQL/flexibleServers/read, Microsoft.DBforPostgreSQL/flexibleServers/advancedThreatProtectionSettings/read | - |
| PostgreSQL Flexible Servers Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| PostgreSQL Server Firewall Rules | Microsoft.DBforPostgreSQL/servers/firewallRules/read | - |
| PostgreSQL Servers | Microsoft.DBforPostgreSQL/servers/read | - |
| PostgreSQL Servers Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Private DNS Record Sets | Microsoft.Network/privateDnsZones/recordsets/read | - |
| Private DNS Virtual Network Links | Microsoft.Network/privateDnsZones/virtualNetworkLinks/read | - |
| Private DNS Zones | Microsoft.Network/privateDnsZones/read | - |
| Private Endpoints | Microsoft.Network/privateEndpoints/read | - |
| Public IP Addresses | Microsoft.Network/publicIPAddresses/read | - |
| Public IP Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Recommendations | Microsoft.Advisor/recommendations/read | - |
| Recovery Services Backup Protected Items | Microsoft.RecoveryServices/Vaults/backupProtectedItems/read | - |
| Recovery Services Vault -> Private Endpoint Relationships | Microsoft.RecoveryServices/vaults/read | - |
| Recovery Services Vaults | Microsoft.RecoveryServices/vaults/read | - |
| Redis Caches | Microsoft.Cache/redis/read | - |
| Redis Enterprise Cluster Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Redis Enterprise Clusters | Microsoft.Cache/redisEnterprise/read | - |
| Redis Enterprise Database Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Redis Enterprise Databases | Microsoft.Cache/redisEnterprise/databases/read | - |
| Redis Firewall Rules | Microsoft.Cache/redis/firewallRules/read | - |
| Redis Linked Servers | Microsoft.Cache/redis/linkedServers/read | - |
| Resource Groups | Microsoft.Resources/subscriptions/resourceGroups/read | - |
| Resource Locks | Microsoft.Authorization/locks/read | - |
| Role Assignments | Microsoft.Authorization/roleAssignments/read | - |
| Role Definitions | Microsoft.Authorization/roleDefinitions/read | - |
| Route Table Routes | - | - |
| Route Tables | Microsoft.Network/routeTables/read | - |
| Security Assessments | Microsoft.Security/assessments/read | - |
| Security Center Auto-Provisioning Settings | Microsoft.Security/autoProvisioningSettings/read | - |
| Security Center Pricing Configurations | Microsoft.Security/pricings/read | - |
| Security Center Settings | Microsoft.Security/settings/read | - |
| Security Contacts | Microsoft.Security/securityContacts/read | - |
| Service Bus Namespaces | Microsoft.ServiceBus/namespaces/read | - |
| Service Bus Queues | Microsoft.ServiceBus/namespaces/queues/read | - |
| Service Bus Topic Subscriptions | Microsoft.ServiceBus/namespaces/topics/subscriptions/read | - |
| Service Bus Topics | Microsoft.ServiceBus/namespaces/topics/read | - |
| Skipped Subscriptions | Microsoft.Resources/subscriptions/read | - |
| SQL Databases | Microsoft.Sql/servers/databases/read | - |
| SQL Managed Instance Databases | Microsoft.Sql/managedInstances/databases/read | - |
| SQL Managed Instance Entra ID Admins | Microsoft.Sql/managedInstances/administrators/read | - |
| SQL Managed Instance Private Endpoint Relationships | - | - |
| SQL Managed Instances | Microsoft.Sql/managedInstances/read | - |
| SQL Server Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| SQL Server Entra ID Admins | Microsoft.Sql/servers/administrators/read | - |
| SQL Server Firewall Rules | Microsoft.Sql/servers/firewallRules/read | - |
| SQL Servers | Microsoft.Sql/servers/read | - |
| SQL Virtual Machines | Microsoft.SqlVirtualMachine/sqlVirtualMachines/read | - |
| SRE Agent Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| SRE Agents | Microsoft.App/agents/read | - |
| Static Web App Builds | Microsoft.Web/staticSites/builds/Read | - |
| Static Web App Custom Domains | Microsoft.Web/staticSites/customDomains/Read | - |
| Static Web App Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Static Web App Sites | Microsoft.Web/staticSites/Read, Microsoft.Web/staticSites/listAppSettings/action, Microsoft.Web/staticSites/basicAuth/read | - |
| Storage Accounts | Microsoft.Storage/storageAccounts/read, Microsoft.Storage/storageAccounts/blobServices/read, Microsoft.Storage/storageAccounts/queueServices/read, Microsoft.Storage/storageAccounts/tableServices/read, Microsoft.Storage/storageAccounts/fileServices/read | - |
| Storage Accounts Keys | Microsoft.Storage/storageAccounts/listKeys/action | - |
| Storage Blob Services | Microsoft.Storage/storageAccounts/blobServices/read | - |
| Storage Containers | Microsoft.Storage/storageAccounts/blobServices/containers/read, Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action | - |
| Storage File Shares | Microsoft.Storage/storageAccounts/fileServices/shares/read | - |
| Storage Queues | Microsoft.Storage/storageAccounts/queueServices/read | - |
| Storage Tables | Microsoft.Storage/storageAccounts/tableServices/tables/read | - |
| Stream Analytics Clusters | Microsoft.StreamAnalytics/clusters/read | - |
| Stream Analytics Jobs | Microsoft.StreamAnalytics/streamingjobs/read | - |
| Stream Analytics Private Endpoints | Microsoft.StreamAnalytics/clusters/privateEndpoints/read | - |
| Subscription Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Subscription Locations | Microsoft.Resources/subscriptions/locations/read | - |
| Subscription Policies | Microsoft.Subscription/policies/read | - |
| Subscription Usage Details | Microsoft.Consumption/usageDetails/read | - |
| Subscriptions | Microsoft.Resources/subscriptions/read | - |
| Synapse Service | - | - |
| Synapse SQL Pool | Microsoft.Synapse/workspaces/sqlPools/read | - |
| Synapse Workspaces | Microsoft.Synapse/workspaces/read | - |
| Traffic Manager Profile Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Virtual Hub Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Virtual Machine Disk Images | Microsoft.Compute/images/read | - |
| Virtual Machine Disks | Microsoft.Compute/disks/read | - |
| Virtual Machine Extensions | Microsoft.Compute/virtualMachines/extensions/read | - |
| Virtual Machine Scale Sets | Microsoft.Compute/virtualMachineScaleSets/read | - |
| Virtual Machines | Microsoft.Compute/virtualMachines/read, Microsoft.Network/networkInterfaces/read, Microsoft.Network/publicIPAddresses/read | - |
| Virtual Network Diagostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| Virtual Networks | Microsoft.Network/virtualNetworks/read | - |
| Virtual WAN Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
| VPN Gateway Diagnostic Settings | Microsoft.Insights/DiagnosticSettings/Read | - |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| [AD] Access Review | azure_access_review | Review |
| [AD] Account | azure_account | Account |
| [AD] Authentication Methods Policy | azure_authentication_methods_policy | AccessPolicy |
| [AD] Authentication Strength Policy | azure_authentication_strength_policy | PasswordPolicy |
| [AD] Authorization Policy | azure_authorization_policy | AccessPolicy |
| [AD] Conditional Access | azure_conditional_access_service | Service |
| [AD] Conditional Access Authorization Context | azure_conditional_access_authorization_context | Resource |
| [AD] Conditional Access Named location | azure_conditional_access_named_location | Network |
| [AD] Conditional Access Policy | azure_conditional_access_policy | AccessPolicy |
| [AD] Conditional Access Template | azure_conditional_access_template | AccessPolicy |
| [AD] Device Registration Policy | azure_device_registration_policy | AccessPolicy |
| [AD] Domain | azure_domain | Service |
| [AD] Group | azure_group | Group |
| [AD] Group Member | azure_group_member | User |
| [AD] Group.Unified Setting | azure_group_unified_setting | Configuration |
| [AD] Group.Unified Setting Template | azure_group_unified_setting_template | Configuration |
| [AD] Group.Unified.Guest Setting | azure_group_unified_guest_setting | Configuration |
| [AD] Group.Unified.Guest Setting Template | azure_group_unified_guest_setting_template | Configuration |
| [AD] Role Definition | azure_ad_role_definition | AccessRole |
| [AD] Service Principal | azure_service_principal | Service, NHI |
| [AD] User | azure_user | User |
| [RM] Access Role | azure_kube_trusted_access_role | AccessRole |
| [RM] Advisor Recommendation | azure_advisor_recommendation | Finding |
| [RM] AI Search Service | azure_search_service | Service |
| [RM] API Management API | azure_api_management_api | ApplicationEndpoint |
| [RM] API Management Backend | azure_api_management_backend | NetworkEndpoint |
| [RM] API Management Named Value | azure_api_management_named_value | Secret |
| [RM] API Management Portal Config | azure_api_management_portal_config | Configuration |
| [RM] API Management Product | azure_api_management_product | Configuration |
| [RM] API Management Service | azure_api_management_service | Gateway |
| [RM] API Management Subscription | azure_api_management_subscription | AccessKey |
| [RM] API Management Tenant Access | azure_api_management_tenant_access | Configuration |
| [RM] App Configuration Store | azure_app_configuration_store | Configuration |
| [RM] App Service Plan | azure_app_service_plan | Configuration |
| [RM] Application Insights | azure_application_insights | Application |
| [RM] Automation Account | azure_automation_account | Service |
| [RM] Azure Arc Machine | azure_arc_machine | Host |
| [RM] Azure Arc Machine Extension | azure_arc_machine_extension | Application |
| [RM] Azure Arc SCVMM Virtual Machine | azure_scvmm_virtual_machine | Host |
| [RM] Azure Arc SQL Server Database | azure_arc_sql_server_database | Database, DataStore |
| [RM] Azure Arc SQL Server Instance | azure_arc_sql_server_instance | Database, DataStore |
| [RM] Azure Bgp Service Communities | azure_bgp_service_communities | Network |
| [RM] Azure Consumer Group | azure_event_hub_consumer_group | Channel |
| [RM] Azure Content Safety Account | azure_content_safety_account | Service |
| [RM] Azure Ddos Protection Plans | azure_ddos_protection_plan | Configuration |
| [RM] Azure Event Hub | azure_event_hub | Service |
| [RM] Azure Express Route | azure_expressroute | Service |
| [RM] Azure Express Route Circuit | azure_expressroute_circuit | Network |
| [RM] Azure Express Route Circuit Connections | azure_expressroute_circuit_connection | Network |
| [RM] Azure Kubernetes Cluster | azure_kubernetes_cluster | Cluster |
| [RM] Azure Language Account | azure_language_account | Service |
| [RM] Azure Managed Disk | azure_managed_disk | DataStore, Disk |
| [RM] Azure OpenAI Account | azure_openai_account | Service |
| [RM] Azure Peer Express Route Circuit Connection | azure_peer_expressroute_circut_connection | Network |
| [RM] Azure Speech Account | azure_speech_account | Service |
| [RM] Backup Protected Item | azure_backup_protected_item | Backup |
| [RM] Bastion Host | azure_bastion_host | Gateway, Host |
| [RM] Batch Account | azure_batch_account | Service |
| [RM] Batch Application | azure_batch_application | Process |
| [RM] Batch Certificate | azure_batch_certificate | Certificate |
| [RM] Batch Pool | azure_batch_pool | Cluster |
| [RM] Bot Service Bot | azure_bot_service_bot | Service |
| [RM] Bot Service Channel | azure_bot_service_channel | Channel |
| [RM] CDN Endpoint | azure_cdn_endpoint | Gateway |
| [RM] CDN Profile | azure_cdn_profile | Service |
| [RM] Chaos Studio Capability | azure_chaos_studio_capability | Configuration |
| [RM] Chaos Studio Experiment | azure_chaos_studio_experiment | Assessment |
| [RM] Chaos Studio Target | azure_chaos_studio_target | Configuration |
| [RM] Classic Admin | azure_classic_admin_group | UserGroup |
| [RM] Cognitive Services Account | azure_cognitive_services_account | Service |
| [RM] Container | azure_container | Container |
| [RM] Container Group | azure_container_group | Group |
| [RM] Container Registry | azure_container_registry | DataStore |
| [RM] Container Registry Webhook | azure_container_registry_webhook | ApplicationEndpoint |
| [RM] Container Volume | azure_container_volume | Disk |
| [RM] Cosmos DB Account | azure_cosmosdb_account | Account, Service |
| [RM] Cosmos DB Database | azure_cosmosdb_sql_database | Database, DataStore |
| [RM] Data Factory | azure_data_factory | Service |
| [RM] Data Factory Integration Runtime | azure_data_factory_integration_runtime | Task |
| [RM] Data Factory Linked Service | azure_data_factory_linked_service | Configuration |
| [RM] Data Factory Managed Private Endpoint | azure_data_factory_managed_private_endpoint | NetworkEndpoint |
| [RM] Data Factory Managed Virtual Network | azure_data_factory_managed_virtual_network | Network |
| [RM] Data Masking Policy | azure_synapse_masking_policy | Policy |
| [RM] Data Masking Rule | azure_synapse_masking_rule | Rule |
| [RM] Data Migration Project | azure_datamigration_project | Project |
| [RM] Data Migration Service | azure_datamigration_service | Service |
| [RM] Data Migration Task | azure_datamigration_task | Task |
| [RM] Data Protection Backup Vault | azure_data_protection_backup_vault | Service |
| [RM] Data Share Account | azure_data_share_account | Account |
| [RM] Databricks Workspace | azure_databricks_workspace | Service |
| [RM] Deployment | azure_rm_deployment | Deployment |
| [RM] Desktop Virtualization Application Group | azure_desktop_virtualization_application_group | Group |
| [RM] Desktop Virtualization Desktop | azure_desktop_virtualization_desktop | Resource |
| [RM] Desktop Virtualization Host Pool | azure_desktop_virtualization_host_pool | Resource |
| [RM] Desktop Virtualization Workspace | azure_desktop_virtualization_workspace | Service |
| [RM] DNS Record Set | azure_dns_record_set | DomainRecord |
| [RM] DNS Zone | azure_dns_zone | DomainZone |
| [RM] Document Intelligence Account | azure_document_intelligence_account | Service |
| [RM] EASM Workspace | azure_easm_workspace | Service |
| [RM] Event Grid Domain | azure_event_grid_domain | Service |
| [RM] Event Grid Domain Topic | azure_event_grid_domain_topic | Queue |
| [RM] Event Grid Topic | azure_event_grid_topic | Queue |
| [RM] Event Grid Topic Subscription | azure_event_grid_topic_subscription | Subscription |
| [RM] Event Hub Cluster | azure_event_hub_cluster | Cluster |
| [RM] Event Hub Keys | azure_event_hub_key | Key |
| [RM] Event Hub Namespace | azure_event_hub_namespace | Group |
| [RM] Fabric Capacity | azure_fabric_capacity | Resource |
| [RM] Fabric Dashboard | azure_fabric_dashboard | Application |
| [RM] Fabric Data Source | azure_fabric_datasource | DataStore |
| [RM] Fabric Dataflow | azure_fabric_dataflow | Workflow |
| [RM] Fabric Datamart | azure_fabric_datamart | DataStore |
| [RM] Fabric Domain | azure_fabric_domain | Group |
| [RM] Fabric Report | azure_fabric_report | Application |
| [RM] Fabric Semantic Model | azure_fabric_semantic_model | Model |
| [RM] Fabric Tenant Setting | azure_fabric_tenant_setting | Configuration |
| [RM] Fabric Tenant Setting Override | azure_fabric_tenant_setting_override | Configuration |
| [RM] Fabric Workspace | azure_fabric_workspace | Group |
| [RM] Firewall Policy | azure_network_firewall_policy | Policy |
| [RM] Front Door AFD Endpoint | azure_frontdoor_afd_endpoint | Gateway |
| [RM] Front Door Custom Domain | azure_frontdoor_custom_domain | Domain |
| [RM] Front Door Origin | azure_frontdoor_origin | Configuration |
| [RM] Front Door Origin Group | azure_frontdoor_origin_group | Configuration |
| [RM] Front Door Profile | azure_frontdoor_profile | Service |
| [RM] Front Door Route | azure_frontdoor_route | Configuration |
| [RM] Function | azure_function | Function |
| [RM] Function App | azure_function_app | Function |
| [RM] Gallery | azure_gallery | Repository |
| [RM] Image | azure_image | Image |
| [RM] IoT Hub | azure_iot_hub | Service |
| [RM] IoT Security Solution | azure_iot_security_solution | Configuration |
| [RM] Key Vault | azure_keyvault_service | Service |
| [RM] Key Vault Key | azure_keyvault_key | Key |
| [RM] Key Vault Secret | azure_keyvault_secret | Secret |
| [RM] Kubernetes Fleet Manager | azure_kubernetes_fleet_manager | Cluster |
| [RM] Kubernetes Fleet Member | azure_kubernetes_fleet_member | Resource |
| [RM] Kubernetes Service | azure_kube_service | Service |
| [RM] Load Balancer | azure_lb | Gateway |
| [RM] Log Analytics | azure_log_analytics_service | Service |
| [RM] Log Analytics Workspace | azure_log_analytics_workspace | DataStore, Logs |
| [RM] Machine Learning Compute | azure_machine_learning_compute | Resource |
| [RM] Machine Learning Online Endpoint | azure_machine_learning_online_endpoint | Service |
| [RM] Machine Learning Workspace | azure_machine_learning_workspace | Service |
| [RM] Managed Cluster | azure_kube_maintenance_configuration | Cluster |
| [RM] Managed HSM | azure_managed_hsm | Vault |
| [RM] Managed Identity | azure_managed_identity | Service, NHI |
| [RM] Managed Services Registration Assignment | azure_managed_services_registration_assignment | Configuration |
| [RM] Managed Services Registration Definition | azure_managed_services_registration_definition | AccessPolicy |
| [RM] Management Group | azure_management_group | Group |
| [RM] MariaDB Database | azure_mariadb_database | Database, DataStore |
| [RM] MariaDB Server | azure_mariadb_server | Database, DataStore, Host |
| [RM] Monitor Activity Log Alert | azure_monitor_activity_log_alert | Rule |
| [RM] Monitor Activity Log Event | azure_activity_log_event | Finding |
| [RM] Monitor Diagnostic Settings Resource | azure_diagnostic_setting | Configuration |
| [RM] Monitor Log Profile | azure_monitor_log_profile | Configuration |
| [RM] MySQL Database | azure_mysql_database | Database, DataStore |
| [RM] MySQL Flexible Database | azure_mysql_flexible_database | Database, DataStore |
| [RM] MySQL Flexible Server | azure_mysql_flexible_server | Database, DataStore, Host |
| [RM] MySQL Flexible Server Firewall Rule | azure_mysql_flexible_server_firewall_rule | Firewall |
| [RM] MySQL Server | azure_mysql_server | Database, DataStore, Host |
| [RM] MySQL Server Firewall Rule | azure_mysql_server_firewall_rule | Firewall |
| [RM] NAT Gateway | azure_nat_gateway | Network |
| [RM] Network Firewall | azure_network_firewall | Firewall |
| [RM] Network Interface | azure_nic | NetworkInterface |
| [RM] Network Watcher | azure_network_watcher | Resource |
| [RM] Oracle Cloud Exadata Infrastructure | azure_oracle_exadata_infrastructure | Cluster |
| [RM] Oracle DB Node | azure_oracle_db_node | Resource |
| [RM] Oracle DB Server | azure_oracle_db_server | Resource |
| [RM] Oracle DB System | azure_oracle_db_system | Database |
| [RM] Oracle Exadb VM Cluster | azure_oracle_exadb_vm_cluster | Cluster |
| [RM] Policy Assignment | azure_policy_assignment | ControlPolicy |
| [RM] Policy Definition | azure_policy_definition | Rule |
| [RM] Policy Set Definition | azure_policy_set_definition | Ruleset |
| [RM] Policy State | azure_policy_state | Review |
| [RM] PostgreSQL Database | azure_postgresql_database | Database, DataStore |
| [RM] PostgreSQL Flexible Database | azure_postgresql_flexible_database | Database, DataStore |
| [RM] PostgreSQL Flexible Server | azure_postgresql_flexible_server | Database, DataStore, Host |
| [RM] PostgreSQL Flexible Server Configuration | azure_postgresql_flexible_server_configuration | Configuration |
| [RM] PostgreSQL Flexible Server Entra Admin | azure_postgresql_flexible_server_entra_admin | AccessRole |
| [RM] PostgreSQL Flexible Server Firewall Rule | azure_postgresql_flexible_server_firewall_rule | Firewall |
| [RM] PostgreSQL Server | azure_postgresql_server | Database, DataStore, Host |
| [RM] PostgreSQL Server Firewall Rule | azure_postgresql_server_firewall_rule | Firewall |
| [RM] Power BI Private Link Service | azure_powerbi_private_link_service | Service |
| [RM] Private DNS Record Set | azure_private_dns_record_set | DomainRecord |
| [RM] Private DNS Zone | azure_private_dns_zone | DomainZone |
| [RM] Private DNS Zone Virtual Network Link | azure_private_dns_zone_virtual_network_link | Configuration |
| [RM] Private Endpoint | azure_private_endpoint | NetworkEndpoint |
| [RM] Public IP Address | azure_public_ip | IpAddress |
| [RM] Recovery Services Vault | azure_recovery_services_vault | Service |
| [RM] Redis Cache | azure_redis_cache | Database, DataStore, Cluster |
| [RM] Redis Enterprise Cluster | azure_redis_enterprise_cluster | Database, Cluster |
| [RM] Redis Enterprise Database | azure_redis_enterprise_database | Database, DataStore |
| [RM] Redis Firewall Rule | azure_firewall_rule | Firewall |
| [RM] Resource Group | azure_resource_group | Group |
| [RM] Resource Lock | azure_resource_lock | Rule |
| [RM] Role Assignment | azure_role_assignment | AccessPolicy |
| [RM] Role Binding | azure_kube_cluster_role_binding | AccessPolicy |
| [RM] Role Definition | azure_role_definition | AccessRole |
| [RM] Route | azure_route | Rule |
| [RM] Route Table | azure_route_table | Configuration |
| [RM] Security Assessment | azure_security_assessment | Assessment |
| [RM] Security Center Auto Provisioning Setting | azure_security_center_auto_provisioning_setting | Configuration |
| [RM] Security Center Setting | azure_security_center_setting | Configuration |
| [RM] Security Center Subscription Pricing | azure_security_center_subscription_pricing | Configuration |
| [RM] Security Contact | azure_security_center_contact | Resource |
| [RM] Security Group | azure_security_group | Firewall |
| [RM] Security Group Flow Logs | azure_security_group_flow_logs | Logs |
| [RM] Security Rule | azure_security_rule | Rule |
| [RM] Service Bus Namespace | azure_service_bus_namespace | Service |
| [RM] Service Bus Queue | azure_service_bus_queue | Queue |
| [RM] Service Bus Subscription | azure_service_bus_subscription | Subscription |
| [RM] Service Bus Topic | azure_service_bus_topic | Queue |
| [RM] Shared Image | azure_shared_image | Image |
| [RM] Shared Image Version | azure_shared_image_version | Image |
| [RM] SQL Database | azure_sql_database | Database, DataStore |
| [RM] SQL Managed Instance | azure_sql_managed_instance | Database |
| [RM] SQL Managed Instance Database | azure_sql_managed_instance_database | Database |
| [RM] SQL Managed Instance Entra ID Admin | azure_sql_managed_instance_active_directory_admin | AccessRole |
| [RM] SQL Pool | azure_synapse_sql_pool | Configuration |
| [RM] SQL Server | azure_sql_server | Database, DataStore, Host |
| [RM] SQL Server Entra ID Admin | azure_sql_server_active_directory_admin | AccessRole |
| [RM] SQL Server Firewall Rule | azure_sql_server_firewall_rule | Firewall |
| [RM] SQL Virtual Machine | azure_sql_vm | Host |
| [RM] SRE Agent | azure_sre_agent | Application |
| [RM] Static Web App | azure_static_site | Application |
| [RM] Static Web App Build | azure_static_site_build | Configuration |
| [RM] Static Web App Custom Domain | azure_static_site_custom_domain | Domain |
| [RM] Storage Account | azure_storage_account | Service |
| [RM] Storage Account Key | azure_storage_account_key | Key |
| [RM] Storage Blob Service | azure_storage_blob_service | Service |
| [RM] Storage Container | azure_storage_container | DataStore |
| [RM] Storage File Share | azure_storage_file_share | DataStore |
| [RM] Storage Queue | azure_storage_queue | Queue |
| [RM] Storage Table | azure_storage_table | DataStore, Database |
| [RM] Stream Analytics Cluster | azure_stream_analytics_cluster | Cluster |
| [RM] Stream Analytics Job | azure_stream_analytics_job | Task |
| [RM] Stream Analytics Private Endpoint | azure_stream_analytics_private_endpoint | NetworkEndpoint |
| [RM] Subnet | azure_subnet | Network |
| [RM] Subscription | azure_subscription | Account |
| [RM] Subscription Policy | azure_subscription_policy | Policy |
| [RM] Synapse Keys | azure_synapse_key | Key |
| [RM] Traffic Manager Endpoint | azure_traffic_manager_endpoint | Configuration |
| [RM] Traffic Manager Profile | azure_traffic_manager_profile | Gateway |
| [RM] Usage Details | azure_usage_details | Site |
| [RM] Virtual Hub | azure_virtual_hub | Network |
| [RM] Virtual Machine | azure_vm | Host |
| [RM] Virtual Machine Extension | azure_vm_extension | Application |
| [RM] Virtual Machine Scale Set | azure_vm_scale_set | Deployment, Group |
| [RM] Virtual Network | azure_vnet | Network |
| [RM] Virtual WAN | azure_virtual_wan | Network |
| [RM] VPN Connection | azure_vpn_connection | Network |
| [RM] VPN Gateway | azure_vpn_gateway | Gateway |
| [RM] VPN Link Connection | azure_vpn_link_connection | Network |
| [RM] Web App | azure_web_app | Application |
| [RM] Workspaces | azure_synapse_workspace | Configuration |
| Access Package Assignment Approvers | azure_access_packages_approver | Review |
| Access Package Assignment Policies | azure_access_packages_policy | AccessPolicy |
| Access Package Assignment Requests | azure_access_packages_request | Requirement |
| Access Package Assignments | azure_access_packages_service_assignment | AccessRole |
| Access Package Catalogs | azure_access_packages_catalog | Resource |
| Access Packages | azure_access_packages_services | Service |
| Application Credentials | azure_application_credential | Secret |
| Applications | azure_application | Application |
| Azure Application Gateway | azure_application_gateway | Network |
| Azure Application Security Groups | azure_application_security_group | Firewall |
| Azure Synapse Analytics | azure_synapse | Service |
| Container Registry Repository | azure_container_registry_repository | Repository |
| Device | azure_device | Device |
| Finding | azure_defender_alert | Finding |
| FrontDoor | azure_frontdoor | Service |
| FrontDoor Backend Pool | azure_frontdoor_backend_pool | Configuration |
| FrontDoor Frontend Endpoint | azure_frontdoor_frontend_endpoint | Gateway |
| FrontDoor Routing Rule | azure_frontdoor_routing_rule | Rule |
| FrontDoor Rules Engine | azure_frontdoor_rules_engine | Ruleset |
| OAuth2 Permission Grant | azure_oauth2_permission_grant | AccessKey, NHI |
| Security Assessment Finding | azure_security_assessment_finding | Vulnerability, Finding |
| Service Principal Key Credential | azure_service_principal_key_credential | Certificate, NHI |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
ANY_RESOURCE | GENERATED | azure_shared_image_version |
ANY_RESOURCE | HAS | azure_security_assessment |
ANY_RESOURCE | HAS | azure_defender_alert |
ANY_RESOURCE | HAS | azure_policy_state |
ANY_SCOPE | HAS | azure_diagnostic_setting |
ANY_SCOPE | HAS | azure_resource_lock |
ANY_SCOPE | HAS | azure_advisor_recommendation |
ANY_SCOPE | HAS | azure_policy_assignment |
azure_access_packages_approver | IS | azure_user |
azure_access_packages_catalog | ASSIGNED | azure_application |
azure_access_packages_service_assignment | CONTAINS | azure_access_packages_policy |
azure_access_packages_services | HAS | azure_application |
azure_access_packages_services | HAS | azure_access_packages_service_assignment |
azure_account | HAS | azure_domain |
azure_account | HAS | azure_user |
azure_account | HAS | azure_group |
azure_account | HAS | azure_oauth2_permission_grant |
azure_account | ENFORCES | azure_authorization_policy |
azure_account | ENFORCES | azure_authentication_methods_policy |
azure_account | HAS | azure_group_unified_setting_template |
azure_account | HAS | azure_group_unified_guest_setting_template |
azure_account | HAS | azure_group_unified_setting |
azure_account | ENFORCES | azure_authentication_strength_policy |
azure_account | ENFORCES | azure_device_registration_policy |
azure_account | HAS | azure_access_review |
azure_account | HAS | azure_keyvault_service |
azure_account | HAS | azure_subscription_policy |
azure_account | HAS | azure_management_group |
azure_api_management_product | HAS | azure_api_management_subscription |
azure_api_management_service | HAS | azure_api_management_api |
azure_api_management_service | HAS | azure_api_management_named_value |
azure_api_management_service | HAS | azure_api_management_product |
azure_api_management_service | HAS | azure_api_management_subscription |
azure_api_management_service | HAS | azure_api_management_portal_config |
azure_api_management_service | HAS | azure_api_management_tenant_access |
azure_api_management_service | HAS | azure_api_management_backend |
azure_app_configuration_store | USES | azure_private_endpoint |
azure_app_configuration_store | USES | azure_managed_identity |
azure_app_configuration_store | ASSIGNED | azure_managed_identity |
azure_application | HAS | azure_application_credential |
azure_application_gateway | HAS | azure_public_ip |
azure_application_insights | USES | azure_private_endpoint |
azure_application_insights | USES | azure_log_analytics_workspace |
azure_application_security_group | PROTECTS | azure_vm |
azure_arc_machine | USES | azure_arc_machine_extension |
azure_arc_machine | HAS | azure_scvmm_virtual_machine |
azure_arc_machine | HAS | azure_arc_sql_server_instance |
azure_arc_sql_server_instance | HAS | azure_arc_sql_server_database |
azure_authorization_policy | USES | azure_ad_role_definition |
azure_automation_account | HAS | azure_private_endpoint |
azure_automation_account | USES | azure_managed_identity |
azure_automation_account | ASSIGNED | azure_managed_identity |
azure_backup_protected_item | PROTECTS | azure_vm |
azure_backup_protected_item | PROTECTS | azure_storage_file_share |
azure_backup_protected_item | PROTECTS | azure_storage_account |
azure_backup_protected_item | PROTECTS | azure_sql_database |
azure_bastion_host | USES | azure_subnet |
azure_bastion_host | USES | azure_public_ip |
azure_batch_account | HAS | azure_batch_pool |
azure_batch_account | HAS | azure_batch_application |
azure_batch_account | HAS | azure_batch_certificate |
azure_bgp_service_communities | HAS | azure_expressroute |
azure_bot_service_bot | HAS | azure_bot_service_channel |
azure_bot_service_bot | USES | azure_storage_account |
azure_bot_service_bot | HAS | azure_private_endpoint |
azure_bot_service_bot | USES | azure_managed_identity |
azure_bot_service_bot | ASSIGNED | azure_managed_identity |
azure_cdn_profile | HAS | azure_cdn_endpoint |
azure_chaos_studio_experiment | HAS | azure_chaos_studio_target |
azure_chaos_studio_experiment | USES | azure_managed_identity |
azure_chaos_studio_experiment | ASSIGNED | azure_managed_identity |
azure_chaos_studio_target | HAS | azure_chaos_studio_capability |
azure_classic_admin_group | HAS | azure_user |
azure_cognitive_services_account | USES | azure_managed_identity |
azure_cognitive_services_account | ASSIGNED | azure_managed_identity |
azure_conditional_access_policy | CONTAINS | azure_conditional_access_named_location |
azure_conditional_access_policy | ASSIGNED | azure_user |
azure_conditional_access_policy | ASSIGNED | azure_group |
azure_conditional_access_service | HAS | azure_conditional_access_policy |
azure_conditional_access_service | HAS | azure_conditional_access_authorization_context |
azure_conditional_access_service | HAS | azure_conditional_access_template |
azure_container | USES | azure_container_volume |
azure_container_group | HAS | azure_container |
azure_container_group | HAS | azure_container_volume |
azure_container_group | USES | azure_managed_identity |
azure_container_group | ASSIGNED | azure_managed_identity |
azure_container_registry | HAS | azure_container_registry_webhook |
azure_container_registry | HAS | azure_container_registry_repository |
azure_container_registry | USES | azure_managed_identity |
azure_container_registry | ASSIGNED | azure_managed_identity |
azure_container_volume | USES | azure_storage_file_share |
azure_content_safety_account | HAS | azure_private_endpoint |
azure_cosmosdb_account | HAS | azure_cosmosdb_sql_database |
azure_data_factory | HAS | azure_data_factory_integration_runtime |
azure_data_factory | HAS | azure_data_factory_managed_virtual_network |
azure_data_factory | HAS | azure_data_factory_linked_service |
azure_data_factory | USES | azure_private_endpoint |
azure_data_factory | USES | azure_managed_identity |
azure_data_factory | ASSIGNED | azure_managed_identity |
azure_data_factory_integration_runtime | USES | azure_data_factory_managed_virtual_network |
azure_data_factory_linked_service | USES | azure_data_factory_integration_runtime |
azure_data_factory_managed_virtual_network | HAS | azure_data_factory_managed_private_endpoint |
azure_data_protection_backup_vault | USES | azure_managed_identity |
azure_data_protection_backup_vault | ASSIGNED | azure_managed_identity |
azure_data_share_account | USES | azure_managed_identity |
azure_data_share_account | ASSIGNED | azure_managed_identity |
azure_databricks_workspace | HAS | azure_private_endpoint |
azure_databricks_workspace | USES | azure_vnet |
azure_databricks_workspace | USES | azure_machine_learning_workspace |
azure_databricks_workspace | USES | azure_lb |
azure_databricks_workspace | USES | azure_managed_identity |
azure_databricks_workspace | ASSIGNED | azure_managed_identity |
azure_datamigration_service | HAS | azure_datamigration_project |
azure_datamigration_service | HAS | azure_datamigration_task |
azure_ddos_protection_plan | ASSIGNED | azure_public_ip |
azure_ddos_protection_plan | ASSIGNED | azure_vnet |
azure_desktop_virtualization_application_group | HAS | azure_desktop_virtualization_desktop |
azure_desktop_virtualization_host_pool | HAS | azure_desktop_virtualization_application_group |
azure_desktop_virtualization_host_pool | HAS | azure_private_endpoint |
azure_desktop_virtualization_workspace | HAS | azure_desktop_virtualization_application_group |
azure_desktop_virtualization_workspace | HAS | azure_private_endpoint |
azure_device_registration_policy | ALLOWS | azure_user |
azure_device_registration_policy | ALLOWS | azure_group |
azure_diagnostic_setting | USES | azure_storage_account |
azure_diagnostic_setting | USES | azure_log_analytics_workspace |
azure_dns_zone | HAS | azure_dns_record_set |
azure_document_intelligence_account | HAS | azure_private_endpoint |
azure_document_intelligence_account | USES | azure_managed_identity |
azure_document_intelligence_account | ASSIGNED | azure_managed_identity |
azure_event_grid_domain | HAS | azure_event_grid_domain_topic |
azure_event_grid_domain_topic | HAS | azure_event_grid_topic_subscription |
azure_event_grid_topic | HAS | azure_event_grid_topic_subscription |
azure_event_hub | HAS | azure_location |
azure_event_hub_cluster | ASSIGNED | azure_event_hub_namespace |
azure_event_hub_consumer_group | HAS | azure_event_hub |
azure_event_hub_key | USES | azure_keyvault_service |
azure_event_hub_namespace | HAS | azure_event_hub |
azure_event_hub_namespace | HAS | azure_event_hub_key |
azure_event_hub_namespace | USES | azure_managed_identity |
azure_event_hub_namespace | ASSIGNED | azure_managed_identity |
azure_expressroute | HAS | azure_expressroute |
azure_expressroute | HAS | azure_peer_expressroute_circut_connection |
azure_expressroute | HAS | azure_application_gateway |
azure_expressroute | HAS | azure_expressroute_circuit_connection |
azure_expressroute_circuit | HAS | azure_peer_expressroute_circut_connection |
azure_expressroute_circuit | HAS | azure_expressroute_circuit_connection |
azure_fabric_capacity | HAS | azure_fabric_tenant_setting_override |
azure_fabric_capacity | HAS | azure_fabric_workspace |
azure_fabric_domain | HAS | azure_fabric_tenant_setting_override |
azure_fabric_report | USES | azure_fabric_semantic_model |
azure_fabric_semantic_model | USES | azure_fabric_datasource |
azure_fabric_tenant_setting_override | OVERRIDES | azure_fabric_tenant_setting |
azure_fabric_workspace | HAS | azure_fabric_tenant_setting_override |
azure_fabric_workspace | HAS | azure_fabric_report |
azure_fabric_workspace | HAS | azure_fabric_semantic_model |
azure_fabric_workspace | HAS | azure_fabric_dashboard |
azure_fabric_workspace | HAS | azure_fabric_dataflow |
azure_fabric_workspace | HAS | azure_fabric_datamart |
azure_frontdoor | HAS | azure_frontdoor_rules_engine |
azure_frontdoor | HAS | azure_frontdoor_routing_rule |
azure_frontdoor | HAS | azure_frontdoor_backend_pool |
azure_frontdoor | HAS | azure_frontdoor_frontend_endpoint |
azure_frontdoor_afd_endpoint | HAS | azure_frontdoor_route |
azure_frontdoor_origin_group | HAS | azure_frontdoor_origin |
azure_frontdoor_profile | HAS | azure_frontdoor_afd_endpoint |
azure_frontdoor_profile | HAS | azure_frontdoor_origin_group |
azure_frontdoor_profile | HAS | azure_frontdoor_custom_domain |
azure_function_app | USES | azure_app_service_plan |
azure_function_app | HAS | azure_function |
azure_function_app | USES | azure_managed_identity |
azure_function_app | ASSIGNED | azure_managed_identity |
azure_gallery | CONTAINS | azure_shared_image |
azure_group | HAS | azure_user |
azure_group | HAS | azure_group |
azure_group | HAS | azure_group_member |
azure_group | HAS | azure_device |
azure_group | HAS | azure_ad_role_definition |
azure_group | APPROVED | azure_access_packages_policy |
azure_group | ASSIGNED | azure_access_packages_services |
azure_group_unified_guest_setting | MANAGES | azure_group |
azure_group_unified_setting | MANAGES | azure_group |
azure_image | GENERATED | azure_shared_image_version |
azure_iot_hub | HAS | azure_iot_security_solution |
azure_keyvault_service | ALLOWS | ANY_PRINCIPAL |
azure_keyvault_service | CONTAINS | azure_keyvault_key |
azure_keyvault_service | CONTAINS | azure_keyvault_secret |
azure_keyvault_service | USES | azure_private_endpoint |
azure_keyvault_service | HAS | azure_synapse_key |
azure_kube_cluster_role_binding | IS | kube_cluster_role_binding |
azure_kube_service | CONTAINS | azure_kube_trusted_access_role |
azure_kubernetes_cluster | HAS | azure_kube_maintenance_configuration |
azure_kubernetes_cluster | CONTAINS | azure_kube_cluster_role_binding |
azure_kubernetes_cluster | USES | azure_managed_identity |
azure_kubernetes_cluster | ASSIGNED | azure_managed_identity |
azure_kubernetes_fleet_manager | HAS | azure_kubernetes_fleet_member |
azure_kubernetes_fleet_manager | USES | azure_managed_identity |
azure_kubernetes_fleet_manager | ASSIGNED | azure_managed_identity |
azure_kubernetes_fleet_member | USES | azure_kubernetes_cluster |
azure_language_account | HAS | azure_private_endpoint |
azure_lb | CONNECTS | azure_nic |
azure_lb | HAS | azure_public_ip |
azure_log_analytics_service | HAS | azure_log_analytics_workspace |
azure_log_analytics_workspace | USES | azure_private_endpoint |
azure_machine_learning_workspace | USES | azure_storage_account |
azure_machine_learning_workspace | USES | azure_keyvault_service |
azure_machine_learning_workspace | USES | azure_container_registry |
azure_machine_learning_workspace | HAS | azure_private_endpoint |
azure_machine_learning_workspace | HAS | azure_machine_learning_compute |
azure_machine_learning_workspace | HAS | azure_machine_learning_online_endpoint |
azure_machine_learning_workspace | USES | azure_managed_identity |
azure_machine_learning_workspace | ASSIGNED | azure_managed_identity |
azure_managed_hsm | MANAGES | ANY_PRINCIPAL |
azure_managed_hsm | USES | azure_private_endpoint |
azure_managed_services_registration_assignment | USES | azure_managed_services_registration_definition |
azure_management_group | CONTAINS | azure_management_group |
azure_mariadb_server | HAS | azure_mariadb_database |
azure_monitor_activity_log_alert | MONITORS | ANY_SCOPE |
azure_monitor_log_profile | USES | azure_storage_account |
azure_mysql_flexible_server | HAS | azure_mysql_flexible_database |
azure_mysql_flexible_server | HAS | azure_mysql_server_firewall_rule |
azure_mysql_server | HAS | azure_mysql_database |
azure_mysql_server | HAS | azure_mysql_server_firewall_rule |
azure_nat_gateway | HAS | azure_public_ip |
azure_network_firewall | HAS | azure_network_firewall_policy |
azure_network_firewall | HAS | azure_public_ip |
azure_network_firewall_policy | EXTENDS | azure_network_firewall_policy |
azure_network_watcher | HAS | azure_security_group_flow_logs |
azure_openai_account | HAS | azure_private_endpoint |
azure_oracle_exadata_infrastructure | HAS | azure_oracle_db_server |
azure_oracle_exadb_vm_cluster | HAS | azure_oracle_db_node |
azure_oracle_exadb_vm_cluster | USES | azure_vnet |
azure_oracle_exadb_vm_cluster | USES | azure_subnet |
azure_policy_assignment | USES | azure_policy_set_definition |
azure_policy_assignment | USES | azure_policy_definition |
azure_policy_assignment | HAS | azure_policy_state |
azure_policy_definition | DEFINES | azure_policy_state |
azure_policy_set_definition | CONTAINS | azure_policy_definition |
azure_postgresql_flexible_server | HAS | azure_postgresql_flexible_database |
azure_postgresql_flexible_server | HAS | azure_postgresql_server_firewall_rule |
azure_postgresql_flexible_server | HAS | azure_postgresql_flexible_server_entra_admin |
azure_postgresql_flexible_server | HAS | azure_postgresql_flexible_server_configuration |
azure_postgresql_flexible_server | HAS | azure_postgresql_flexible_server |
azure_postgresql_flexible_server | HAS | azure_private_endpoint |
azure_postgresql_flexible_server | USES | azure_subnet |
azure_postgresql_flexible_server | USES | azure_keyvault_key |
azure_postgresql_server | HAS | azure_postgresql_database |
azure_postgresql_server | HAS | azure_postgresql_server_firewall_rule |
azure_powerbi_private_link_service | USES | azure_private_endpoint |
azure_private_dns_zone | HAS | azure_private_dns_record_set |
azure_private_dns_zone | HAS | azure_private_dns_zone_virtual_network_link |
azure_private_dns_zone_virtual_network_link | USES | azure_vnet |
azure_private_endpoint | USES | azure_nic |
azure_private_endpoint | CONNECTS | ANY_RESOURCE |
azure_recovery_services_vault | HAS | azure_private_endpoint |
azure_recovery_services_vault | HAS | azure_backup_protected_item |
azure_recovery_services_vault | USES | azure_managed_identity |
azure_recovery_services_vault | ASSIGNED | azure_managed_identity |
azure_redis_cache | HAS | azure_firewall_rule |
azure_redis_cache | CONNECTS | azure_redis_cache |
azure_redis_enterprise_cluster | HAS | azure_redis_enterprise_database |
azure_redis_enterprise_cluster | USES | azure_private_endpoint |
azure_resource_group | HAS | azure_gallery |
azure_resource_group | HAS | azure_image |
azure_resource_group | HAS | azure_managed_disk |
azure_resource_group | HAS | azure_vm |
azure_resource_group | HAS | azure_vm_scale_set |
azure_resource_group | HAS | azure_cosmosdb_account |
azure_resource_group | HAS | azure_data_factory |
azure_resource_group | HAS | azure_data_protection_backup_vault |
azure_resource_group | HAS | azure_datamigration_service |
azure_resource_group | HAS | azure_data_share_account |
azure_resource_group | HAS | azure_mariadb_server |
azure_resource_group | HAS | azure_mysql_server |
azure_resource_group | HAS | azure_mysql_flexible_server |
azure_resource_group | HAS | azure_postgresql_server |
azure_resource_group | HAS | azure_postgresql_flexible_server |
azure_resource_group | HAS | azure_sql_server |
azure_resource_group | HAS | azure_sql_managed_instance |
azure_resource_group | HAS | azure_databricks_workspace |
azure_resource_group | HAS | azure_keyvault_service |
azure_resource_group | HAS | azure_managed_hsm |
azure_resource_group | HAS | azure_machine_learning_workspace |
azure_resource_group | HAS | azure_desktop_virtualization_workspace |
azure_resource_group | HAS | azure_desktop_virtualization_host_pool |
azure_resource_group | HAS | azure_desktop_virtualization_application_group |
azure_resource_group | HAS | azure_document_intelligence_account |
azure_resource_group | HAS | azure_search_service |
azure_resource_group | HAS | azure_cognitive_services_account |
azure_resource_group | HAS | azure_openai_account |
azure_resource_group | HAS | azure_content_safety_account |
azure_resource_group | HAS | azure_language_account |
azure_resource_group | HAS | azure_speech_account |
azure_resource_group | HAS | azure_public_ip |
azure_resource_group | HAS | azure_nic |
azure_resource_group | HAS | azure_vnet |
azure_resource_group | HAS | azure_security_group |
azure_resource_group | HAS | azure_lb |
azure_resource_group | HAS | azure_network_firewall |
azure_resource_group | HAS | azure_network_watcher |
azure_resource_group | HAS | azure_private_endpoint |
azure_resource_group | HAS | azure_nat_gateway |
azure_resource_group | HAS | azure_bastion_host |
azure_resource_group | HAS | azure_route_table |
azure_resource_group | HAS | azure_storage_account |
azure_resource_group | HAS | azure_api_management_service |
azure_resource_group | HAS | azure_arc_machine |
azure_resource_group | HAS | azure_arc_sql_server_instance |
azure_resource_group | HAS | azure_dns_zone |
azure_resource_group | HAS | azure_private_dns_zone |
azure_resource_group | HAS | azure_container_registry |
azure_resource_group | HAS | azure_service_bus_namespace |
azure_resource_group | HAS | azure_cdn_profile |
azure_resource_group | HAS | azure_batch_account |
azure_resource_group | HAS | azure_bot_service_bot |
azure_resource_group | HAS | azure_recovery_services_vault |
azure_resource_group | HAS | azure_redis_cache |
azure_resource_group | HAS | azure_redis_enterprise_cluster |
azure_resource_group | HAS | azure_container_group |
azure_resource_group | HAS | azure_frontdoor |
azure_resource_group | HAS | azure_frontdoor_profile |
azure_resource_group | HAS | azure_traffic_manager_profile |
azure_resource_group | HAS | azure_event_grid_domain |
azure_resource_group | HAS | azure_event_grid_topic |
azure_resource_group | HAS | azure_automation_account |
azure_resource_group | HAS | azure_chaos_studio_experiment |
azure_resource_group | HAS | azure_kubernetes_fleet_manager |
azure_resource_group | HAS | azure_monitor_activity_log_alert |
azure_resource_group | HAS | azure_web_app |
azure_resource_group | HAS | azure_function_app |
azure_resource_group | HAS | azure_app_service_plan |
azure_resource_group | HAS | azure_kubernetes_cluster |
azure_resource_group | HAS | azure_ddos_protection_plan |
azure_resource_group | HAS | azure_event_hub_namespace |
azure_resource_group | HAS | azure_event_hub |
azure_resource_group | HAS | azure_app_configuration_store |
azure_resource_group | HAS | azure_virtual_wan |
azure_resource_group | HAS | azure_virtual_hub |
azure_resource_group | HAS | azure_vpn_gateway |
azure_resource_group | HAS | azure_log_analytics_workspace |
azure_resource_group | HAS | azure_application_insights |
azure_resource_group | HAS | azure_rm_deployment |
azure_resource_group | HAS | azure_managed_identity |
azure_resource_group | HAS | azure_oracle_exadata_infrastructure |
azure_resource_group | HAS | azure_oracle_exadb_vm_cluster |
azure_resource_group | HAS | azure_oracle_db_system |
azure_resource_group | HAS | azure_sql_vm |
azure_resource_group | HAS | azure_stream_analytics_cluster |
azure_resource_group | HAS | azure_stream_analytics_job |
azure_resource_group | HAS | azure_static_site |
azure_resource_group | HAS | azure_sre_agent |
azure_role_assignment | ALLOWS | ANY_SCOPE |
azure_role_assignment | USES | azure_role_definition |
azure_route_table | HAS | azure_route |
azure_search_service | USES | azure_private_endpoint |
azure_security_assessment | IDENTIFIED | azure_advisor_recommendation |
azure_security_assessment | HAS | azure_security_assessment_finding |
azure_security_assessment | SCANS | azure_container_registry |
azure_security_group | PROTECTS | azure_vm_scale_set |
azure_security_group | PROTECTS | azure_subnet |
azure_security_group | PROTECTS | azure_nic |
azure_security_group | HAS | azure_security_rule |
azure_security_group | ALLOWS | azure_subnet |
azure_security_group | DENIES | azure_subnet |
azure_security_group | HAS | azure_security_group_flow_logs |
azure_security_group_flow_logs | USES | azure_storage_account |
azure_service_bus_namespace | HAS | azure_service_bus_queue |
azure_service_bus_namespace | HAS | azure_service_bus_topic |
azure_service_bus_topic | HAS | azure_service_bus_subscription |
azure_service_principal | USES | azure_service_principal_key_credential |
azure_service_principal | USES | azure_oauth2_permission_grant |
azure_service_principal | HAS | azure_ad_role_definition |
azure_service_principal | ASSIGNED | azure_group |
azure_service_principal | ASSIGNED | azure_user |
azure_service_principal | ASSIGNED | azure_service_principal |
azure_service_principal | OWNS | azure_application |
azure_shared_image | HAS | azure_shared_image_version |
azure_speech_account | HAS | azure_private_endpoint |
azure_sql_managed_instance | HAS | azure_sql_managed_instance_database |
azure_sql_managed_instance | HAS | azure_sql_managed_instance_active_directory_admin |
azure_sql_managed_instance | HAS | azure_private_endpoint |
azure_sql_server | HAS | azure_sql_database |
azure_sql_server | HAS | azure_sql_server_firewall_rule |
azure_sql_server | HAS | azure_sql_server_active_directory_admin |
azure_sql_vm | USES | azure_vm |
azure_sre_agent | USES | azure_managed_identity |
azure_sre_agent | ASSIGNED | azure_managed_identity |
azure_sre_agent | USES | azure_application_insights |
azure_sre_agent | USES | azure_subnet |
azure_static_site | HAS | azure_static_site_build |
azure_static_site | HAS | azure_static_site_custom_domain |
azure_static_site | USES | azure_private_endpoint |
azure_storage_account | USES | azure_keyvault_service |
azure_storage_account | HAS | azure_storage_file_share |
azure_storage_account | HAS | azure_storage_container |
azure_storage_account | HAS | azure_storage_queue |
azure_storage_account | HAS | azure_storage_table |
azure_storage_account | HAS | azure_storage_blob_service |
azure_storage_account | HAS | azure_storage_account_key |
azure_storage_account | USES | azure_managed_identity |
azure_storage_account | ASSIGNED | azure_managed_identity |
azure_stream_analytics_cluster | HAS | azure_stream_analytics_job |
azure_stream_analytics_cluster | HAS | azure_stream_analytics_private_endpoint |
azure_subnet | ALLOWS | azure_security_group |
azure_subnet | DENIES | azure_security_group |
azure_subnet | HAS | azure_private_endpoint |
azure_subnet | HAS | azure_security_group_flow_logs |
azure_subnet | USES | azure_route_table |
azure_subnet | HAS | azure_vm |
azure_subscription | CONTAINS | azure_role_definition |
azure_subscription | HAS | azure_resource_group |
azure_subscription | HAS | azure_usage_details |
azure_subscription | PERFORMED | azure_security_assessment |
azure_subscription | HAS | azure_security_center_contact |
azure_subscription | HAS | azure_security_center_subscription_pricing |
azure_subscription | HAS | azure_security_center_setting |
azure_subscription | HAS | azure_security_center_auto_provisioning_setting |
azure_subscription | HAS | azure_defender_alert |
azure_subscription | HAS | azure_monitor_log_profile |
azure_subscription | HAS | azure_activity_log_event |
azure_subscription | HAS | azure_kube_service |
azure_subscription | HAS | azure_synapse |
azure_subscription | HAS | azure_ddos_protection_plan |
azure_subscription | HAS | azure_event_hub |
azure_subscription | HAS | azure_iot_hub |
azure_subscription | HAS | azure_iot_security_solution |
azure_subscription | HAS | azure_expressroute |
azure_subscription | HAS | azure_bgp_service_communities |
azure_subscription | HAS | azure_easm_workspace |
azure_subscription | HAS | azure_rm_deployment |
azure_subscription | HAS | azure_managed_services_registration_definition |
azure_subscription | HAS | azure_managed_services_registration_assignment |
azure_subscription | HAS | azure_fabric_capacity |
azure_subscription | HAS | azure_powerbi_private_link_service |
azure_synapse | HAS | azure_synapse_workspace |
azure_synapse | HAS | azure_synapse_sql_pool |
azure_synapse | HAS | azure_synapse_key |
azure_synapse_sql_pool | HAS | azure_synapse_masking_rule |
azure_synapse_sql_pool | ASSIGNED | azure_synapse_masking_policy |
azure_synapse_workspace | HAS | azure_synapse_sql_pool |
azure_synapse_workspace | HAS | azure_synapse_key |
azure_traffic_manager_profile | HAS | azure_traffic_manager_endpoint |
azure_user | OWNS | azure_device |
azure_user | ASSIGNED | azure_oauth2_permission_grant |
azure_user | HAS | azure_ad_role_definition |
azure_user | APPROVED | azure_access_packages_policy |
azure_user | OWNS | azure_application |
azure_user | CREATED | azure_access_packages_request |
azure_user | ASSIGNED | azure_access_packages_services |
azure_virtual_hub | HAS | azure_vpn_gateway |
azure_virtual_hub | USES | azure_network_firewall |
azure_virtual_wan | HAS | azure_virtual_hub |
azure_vm | GENERATED | azure_shared_image_version |
azure_vm | USES | azure_storage_account |
azure_vm | USES | azure_managed_disk |
azure_vm | USES | azure_vm_extension |
azure_vm | USES | azure_image |
azure_vm | USES | azure_shared_image |
azure_vm | USES | azure_shared_image_version |
azure_vm | USES | azure_vm_scale_set |
azure_vm | USES | azure_nic |
azure_vm | USES | azure_public_ip |
azure_vm_scale_set | USES | azure_lb |
azure_vm_scale_set | USES | azure_subnet |
azure_vm_scale_set | USES | azure_shared_image |
azure_vm_scale_set | USES | azure_shared_image_version |
azure_vm_scale_set | USES | azure_managed_identity |
azure_vm_scale_set | ASSIGNED | azure_managed_identity |
azure_vnet | CONTAINS | azure_subnet |
azure_vnet | HAS | azure_security_group_flow_logs |
azure_vpn_connection | HAS | azure_vpn_link_connection |
azure_vpn_gateway | HAS | azure_vpn_connection |
azure_web_app | USES | azure_app_service_plan |
azure_web_app | USES | azure_managed_identity |
azure_web_app | ASSIGNED | azure_managed_identity |
Mapped Relationships
The following mapped relationships are created:
Source Entity _type | Relationship _class | Target Entity _type | Direction |
|---|---|---|---|
azure_backup_protected_item | PROTECTS | azure_vm | FORWARD |
azure_backup_protected_item | PROTECTS | azure_storage_account | FORWARD |
azure_backup_protected_item | PROTECTS | azure_sql_database | FORWARD |
azure_data_factory_managed_private_endpoint | CONNECTS | azure_resource | FORWARD |
azure_fabric_workspace | HAS | azure_user | FORWARD |
azure_fabric_workspace | HAS | azure_service_principal | FORWARD |
azure_kube_trusted_access_role | IS | kube_cluster_role | FORWARD |
azure_managed_identity | IS | azure_service_principal | FORWARD |
azure_management_group | HAS | azure_subscription | FORWARD |
azure_network_firewall | ALLOWS | internet | FORWARD |
azure_network_firewall | ALLOWS | internet | REVERSE |
azure_network_firewall | DENIES | internet | FORWARD |
azure_network_firewall | DENIES | internet | REVERSE |
azure_network_watcher | HAS | azure_location | REVERSE |
azure_postgresql_flexible_server_entra_admin | IS | azure_user | FORWARD |
azure_postgresql_flexible_server_entra_admin | IS | azure_group | FORWARD |
azure_postgresql_flexible_server_entra_admin | IS | azure_service_principal | FORWARD |
azure_role_assignment | ASSIGNED | azure_unknown_principal_type | FORWARD |
azure_role_assignment | ASSIGNED | azure_application | FORWARD |
azure_role_assignment | ASSIGNED | azure_directory | FORWARD |
azure_role_assignment | ASSIGNED | azure_directory_role_template | FORWARD |
azure_role_assignment | ASSIGNED | azure_everyone | FORWARD |
azure_role_assignment | ASSIGNED | azure_foreign_group | FORWARD |
azure_role_assignment | ASSIGNED | azure_group | FORWARD |
azure_role_assignment | ASSIGNED | azure_msi | FORWARD |
azure_role_assignment | ASSIGNED | azure_service_principal | FORWARD |
azure_role_assignment | ASSIGNED | azure_unknown | FORWARD |
azure_role_assignment | ASSIGNED | azure_user | FORWARD |
azure_subscription | USES | azure_location | FORWARD |
azure_vm | USES | azure_image | FORWARD |
azure_vm | ASSIGNED | azure_service_principal | FORWARD |
Azure Access Review
azure_access_review inherits from Review
| Property | Type | Description | Specifications |
|---|---|---|---|
autoApplyDecisions | boolean | ||
createdOn | number | ||
defaultDecision | string | ||
defaultDecisionEnabled | boolean | ||
descriptionForAdmins | string | ||
descriptionForReviewers | string | ||
durationInDays | number | ||
id | string | ||
justificationRequired | boolean | ||
mailNotificationsEnabled | boolean | ||
recommendationsEnabled | boolean | ||
recurrenceDayOfMonth | number | ||
recurrenceDaysOfWeek | array of strings | ||
recurrenceEndDate | string | ||
recurrenceFirstDayOfWeek | string | ||
recurrenceIndex | string | ||
recurrenceInterval | number | ||
recurrenceMonth | number | ||
recurrenceOccurrences | number | ||
recurrenceRangeType | string | ||
recurrenceStartDate | string | ||
recurrenceTimeZone | string | ||
recurrenceType | string | ||
reminderNotificationsEnabled | boolean | ||
updatedOn | number |
Azure Activity Log Event
azure_activity_log_event inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
authorizationAction * | string | null | ||
authorizationRole * | string | null | ||
authorizationScope * | string | null | ||
caller * | string | null | ||
category * | string | null | ||
clientIpAddress * | string | null | ||
correlationId * | string | null | ||
eventDataId * | string | null | ||
eventTimestamp * | number | null | ||
httpMethod * | string | null | ||
level * | string | null | ||
numericSeverity * | number | ||
open * | boolean | ||
operationId * | string | null | ||
operationName * | string | null | ||
operationStatus * | string | null | ||
resourceGroupName * | string | null | ||
resourceId * | string | null | ||
resourceProviderName * | string | null | ||
resourceType * | string | null | ||
severity * | string | null | ||
submissionTimestamp * | number | null | ||
subscriptionId * | string | null | ||
subStatus * | string | null |
Azure Api Management Backend
azure_api_management_backend inherits from NetworkEndpoint
| Property | Type | Description | Specifications |
|---|---|---|---|
address * | string | The backend upstream URL (runtime URL). | |
hasAuthorizationHeader * | boolean | null | Whether an authorization header is configured for backend credentials. | |
hasClientCertificate * | boolean | null | Whether the backend is configured with a client certificate. | |
hasServiceFabricCluster * | boolean | null | Whether this backend connects to a Service Fabric cluster. | |
isTlsCertificateChainValidationEnabled * | boolean | null | Whether SSL certificate chain validation is performed for self-signed certificates. | |
isTlsCertificateNameValidationEnabled * | boolean | null | Whether SSL certificate name validation is performed for self-signed certificates. | |
protocol * | string | Communication protocol ('http' or 'soap'). | |
proxyUrl * | string | null | WebProxy URL used for requests to this backend. | |
resourceId * | string | null | ARM resource ID of the external resource (e.g. Logic App, Function App). | |
title * | string | null | Backend title. |
Azure Api Management Named Value
azure_api_management_named_value inherits from Secret
| Property | Type | Description | Specifications |
|---|---|---|---|
isKeyVaultBacked * | boolean | Whether the named value resolves its value from an Azure Key Vault secret rather than storing it inline. Azure forces secret=true on Key Vault-backed named values, so isSecret=true with isKeyVaultBacked=false identifies a secret stored inline in API Management. | |
isSecret * | boolean | Whether the named value is encrypted/secret. If true, the value is never returned by the API. | |
keyVaultIdentityClientId | string | null | Client ID of the user-assigned managed identity used to fetch the Key Vault secret. Null when the system-assigned identity is used. | |
keyVaultLastStatusCheckedOn | number | null | Timestamp (ms since epoch) of the most recent attempt to refresh the secret from Key Vault. | |
keyVaultLastStatusCode | string | null | Status code of the most recent Key Vault secret refresh ('Success' when the secret was retrieved). A non-success code means the gateway is serving a stale value. | |
keyVaultLastStatusMessage | string | null | Details of the most recent Key Vault secret refresh failure, when one occurred. | |
keyVaultSecretIdentifier | string | null | Data-plane URI of the backing Key Vault secret (https://<vault>.vault.azure.net/secrets/<name>[/<version>]). A URI without a version is refreshed automatically; a versioned URI is pinned. |
Azure Api Management Portal Config
azure_api_management_portal_config inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
corsAllowedOrigins * | array | null | Allowed origins for CORS on the developer portal. | |
cspAllowedSources * | array | null | Allowed sources for the Content Security Policy. | |
cspMode * | string | null | Content Security Policy mode ('enabled', 'disabled', or 'reportOnly'). | |
delegationUrl * | string | null | URL of the external delegation service. | |
isBasicAuthEnabled * | boolean | null | Whether basic authentication is enabled on the portal. | |
isDelegateRegistrationEnabled * | boolean | null | Whether user registration is delegated to an external service. | |
isDelegateSubscriptionEnabled * | boolean | null | Whether product subscription management is delegated to an external service. | |
isSigninRequired * | boolean | null | Whether anonymous users are redirected to the sign-in page. | |
isSignupTermsConsentRequired * | boolean | null | Whether user consent to terms of service is required during sign-up. | |
isSignupTermsOfServiceEnabled * | boolean | null | Whether terms of service are displayed during sign-up. |
Azure Api Management Product
azure_api_management_product inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
isApprovalRequired * | boolean | null | Whether administrator approval is required before a subscription is active. | |
isSubscriptionRequired * | boolean | null | Whether a product subscription is required to access the APIs. If false, the product is "open". | |
state * | string | null | Publication state of the product ('published' or 'notPublished'). | |
subscriptionsLimit * | number | null | Maximum number of simultaneous subscriptions a user can have. Null means unlimited. | |
terms * | string | null | Terms of use text that developers must accept before subscribing. |
Azure Api Management Service
azure_api_management_service inherits from Gateway
| Property | Type | Description | Specifications |
|---|---|---|---|
certificateExpiryDates | array | null | Expiry timestamps (ms since epoch) of the service certificates. | |
delegationUrl * | string | null | URL of the external delegation service, when configured. | |
hasCertificates | boolean | null | Whether the service has any custom CA/client certificates configured. | |
hostnameConfigurationsKeyVaultIds | array | null | Key Vault secret identifiers backing the custom hostname TLS certificates. | |
identityType | string | null | The managed identity type configured on the service (e.g. 'SystemAssigned', 'UserAssigned'). | |
isClientCertificateEnabled | boolean | null | Whether client certificate authentication is required at the gateway (Consumption tier). | |
isDelegateRegistrationEnabled * | boolean | null | Whether user registration is delegated to an external service. | |
isDelegateSubscriptionEnabled * | boolean | null | Whether product subscription management is delegated to an external service. | |
isSignInEnabled * | boolean | null | Whether anonymous users must sign in to access the developer portal. | |
isSignUpEnabled * | boolean | null | Whether self-service sign-up is enabled on the developer portal. | |
isSignUpTermsConsentRequired * | boolean | null | Whether consent to the terms of service is required during sign-up. | |
isSignUpTermsOfServiceEnabled * | boolean | null | Whether terms of service are displayed during developer portal sign-up. | |
minApiVersion | string | null | The minimum control-plane API version clients may use, when an apiVersionConstraint is configured. | |
publicNetworkAccess | string | null | Whether public network access is allowed for this API Management service. 'Enabled' when public traffic is accepted; 'Disabled' when the service is private-only. This is the authoritative source for the entity's public property. | |
skuName | string | null | The pricing tier (SKU) name of the service (e.g. 'Developer', 'Basic', 'Standard', 'Premium', 'Consumption'). | |
virtualNetworkSubnetResourceId | string | null | ARM resource ID of the subnet the service is injected into, when VNet-integrated. |
Azure Api Management Subscription
azure_api_management_subscription inherits from AccessKey
| Property | Type | Description | Specifications |
|---|---|---|---|
endedOn * | number | null | Timestamp (ms since epoch) when the subscription was cancelled or expired. | |
isAllowTracingEnabled * | boolean | null | Whether request tracing is enabled for this subscription. | |
ownerId * | string | null | The user resource identifier of the subscription owner (e.g. /users/{userId}). | |
scope * | string | Subscription scope: /products/{productId}, /apis, or /apis/{apiId}. | |
startedOn * | number | null | Timestamp (ms since epoch) when the subscription was activated. | |
state * | string | Subscription state: 'active', 'suspended', 'submitted', 'rejected', 'cancelled', or 'expired'. | |
stateComment * | string | null | Optional comment added by an administrator. |
Azure Api Management Tenant Access
azure_api_management_tenant_access inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
accessId * | string | null | The tenant access identifier. | |
isEnabled * | boolean | Whether direct tenant management API access is enabled. |
Azure Arc Sql Server Database
azure_arc_sql_server_database inherits from Database, DataStore
| Property | Type | Description | Specifications |
|---|---|---|---|
collation * | string | null | Database-level collation, such as SQL_Latin1_General_CP1_CI_AS. | |
compatibilityLevel * | number | null | SQL Server compatibility level of the database, such as 150 for SQL Server 2019. | |
databaseCreatedOn * | number | null | Timestamp (milliseconds since epoch) when the database was created on the SQL Server instance. | |
isAutoCloseOn * | boolean | null | Whether the database shuts down cleanly and frees resources after the last user disconnects. | |
isAutoCreateStatsOn * | boolean | null | Whether the query optimizer automatically creates single-column statistics. | |
isAutoShrinkOn * | boolean | null | Whether the database files are periodically shrunk automatically. | |
isAutoUpdateStatsOn * | boolean | null | Whether the query optimizer automatically updates out-of-date statistics. | |
isChangeTrackingOn * | boolean | null | Whether change tracking is enabled on the database. | |
isFullTextIndexingOn * | boolean | null | Whether full-text indexing is enabled on the database. | |
isReadOnly * | boolean | null | Whether the database is in read-only mode. | |
isRemoteDataArchiveEnabled * | boolean | null | Whether Remote Data Archive (Stretch Database) is enabled for the database. | |
isTrustworthyOn * | boolean | null | Whether the TRUSTWORTHY database option is enabled, allowing database modules to access resources outside the database. | |
lastFullBackupOn * | number | null | Timestamp (milliseconds since epoch) of the most recent full backup. | |
lastLogBackupOn * | number | null | Timestamp (milliseconds since epoch) of the most recent transaction log backup. | |
provisioningState * | string | null | ARM provisioning state of the resource, such as Succeeded, Failed, or Deleting. | |
recoveryMode * | string | null | Recovery model of the database: FULL, SIMPLE, or BULK_LOGGED. | |
region * | string | null | Azure region the parent Arc SQL Server instance is registered in. | |
resourceGroup * | string | null | Name of the Azure resource group containing the database. | |
sizeMB * | number | null | Total size of the database in megabytes. | |
spaceAvailableMB * | number | null | Unused space available within the database files, in megabytes. | |
state * | string | null | Current database state: Online, Offline, Restoring, Recovering, Suspect, Emergency, or OfflineSecondary. |
Azure Arc Sql Server Instance
azure_arc_sql_server_instance inherits from Database, DataStore
| Property | Type | Description | Specifications |
|---|---|---|---|
azureDefenderStatus * | string | null | Microsoft Defender for SQL status reported for the instance: Protected, Unprotected, or Unknown. | |
azureDefenderStatusLastUpdatedOn * | number | null | Timestamp (milliseconds since epoch) when the Microsoft Defender for SQL status was last updated. | |
backupFullFrequency * | string | null | Configured frequency of full backups, such as Weekly or Daily. | |
backupRetentionDays * | number | null | Number of days automated backups are retained for the instance. | |
backupStorageRedundancy * | string | null | Redundancy configured for backup storage, such as Local, Zone, or Geo. | |
collation * | string | null | Server-level collation, such as SQL_Latin1_General_CP1_CI_AS. | |
connectionStatus * | string | null | Connection status of the instance to Azure Arc: Connected, Disconnected, Registered, or Unknown. | |
containerResourceId * | string | null | Resource ID of the Azure Arc-enabled server hosting this SQL Server instance. | |
cores * | string | null | Number of physical cores on the host running the instance. | |
currentVersion * | string | null | Exact SQL Server build number currently installed. | |
edition * | string | null | SQL Server edition: Evaluation, Enterprise, Standard, Web, Developer, or Express. | |
hostType * | string | null | Type of host running the instance, such as Physical Server, Virtual Machine, or Container. | |
instanceName * | string | null | SQL Server instance name as reported by the host, such as MSSQLSERVER for a default instance. | |
instanceType * | string | null | Arc SQL Server instance type, such as Single or AvailabilityGroup. | |
isAzureDefenderEnabled * | boolean | null | Whether Microsoft Defender for SQL reports the instance as Protected. Null when the Defender status is unknown or has not been reported. | |
licenseType * | string | null | License type applied to the instance: Undefined, Free, HADR, ServerCAL, LicenseOnly, PAYG, or Paid. | |
monitoringStatus * | string | null | Monitoring state of the instance, such as Enabled or Disabled. | |
patchLevel * | string | null | Patch level of the SQL Server installation, such as 15.0.4316.3. | |
productId * | string | null | SQL Server product ID of the installation. | |
provisioningState * | string | null | ARM provisioning state of the resource, such as Succeeded, Failed, or Deleting. | |
region * | string | null | Azure region the Arc SQL Server instance is registered in. | |
resourceGroup * | string | null | Name of the Azure resource group containing the instance. | |
tcpDynamicPorts * | string | null | Comma-separated list of dynamic TCP ports the instance listens on. | |
tcpStaticPorts * | string | null | Comma-separated list of static TCP ports the instance listens on. | |
vCore * | string | null | Number of virtual cores available to the instance. | |
version * | string | null | SQL Server product version, such as "SQL Server 2019" or "SQL Server 2022". |
Azure Authentication Methods Policy
azure_authentication_methods_policy inherits from AccessPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
attestationEnforced | boolean | ||
certificateValidationEnabled | boolean | ||
defaultLifetimeMinutes | number | ||
disabledAuthenticationMethods | array of strings | ||
enabledAuthenticationMethods | array of strings | ||
externalIdEmailOtpAllowed | string | ||
hasExclusions | array of strings | ||
includeAllUsers | array of strings | ||
isRegistrationEnforced | boolean | ||
isUsableOnce | boolean | ||
keyRestrictionsEnforced | boolean | ||
lastModifiedDateTime | number | null | ||
maximumLifetimeMinutes | number | ||
minimumLifetimeMinutes | number | ||
officePhoneAllowed | boolean | ||
policyMigrationState | string | null | ||
policyVersion | string | null | ||
registrationCampaignState | string | ||
registrationSnoozeDays | number | ||
requiresRegistration | array of strings | ||
selfServiceRegistrationAllowed | boolean | ||
softwareOathEnabled | boolean |
Azure Authentication Strength Policy
azure_authentication_strength_policy inherits from PasswordPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
allowedCombinations | array of strings | ||
description | string | ||
policyType | string | ||
requirementsSatisfied | string |
Azure Authorization Policy
azure_authorization_policy inherits from AccessPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
allowedToSignUpEmailBasedSubscriptions | boolean | ||
allowedToUseSSPR | boolean | ||
allowEmailVerifiedUsersToJoinOrganization | boolean | ||
allowInvitesFrom | string | null | ||
allowUserConsentForRiskyApps | boolean | null | ||
blockMsolPowerShell | boolean | null | ||
defaultUserRolePermissions.allowedToCreateApps | boolean | ||
defaultUserRolePermissions.allowedToCreateSecurityGroups | boolean | ||
defaultUserRolePermissions.allowedToCreateTenants | boolean | null | ||
defaultUserRolePermissions.allowedToReadBitlockerKeysForOwnedDevice | boolean | null | ||
defaultUserRolePermissions.allowedToReadOtherUsers | boolean | ||
defaultUserRolePermissions.permissionGrantPoliciesAssigned | array | null |
Azure Backup Protected Item
azure_backup_protected_item inherits from Backup
| Property | Type | Description | Specifications |
|---|---|---|---|
backupEngineName | string | null | Name of the DPM/MABS backup engine managing the item. | |
backupManagementType | string | null | Backup management engine handling the item: "AzureIaasVM", "AzureWorkload", "AzureStorage", "AzureSql", "MAB", or "DPM". | |
backupSetName | string | null | Name of the backup set the item belongs to. | |
computerName | string | null | Name of the on-premises machine backed up by a MAB (Azure Backup agent) item. | |
containerName | string | null | Name of the protection container holding the item; the only stable identifier for MAB/DPM items that have no ARM resource ID. | |
deferredDeleteOn | number | null | Timestamp (ms since epoch) at which the soft-deleted item is scheduled for permanent deletion. | |
deferredDeleteTimeRemaining | string | null | Free-form time remaining before permanent deletion, as reported by Azure (e.g. "13 days"). | |
friendlyName | string | null | Human-readable name of the protected datasource - the file share name, the "instance/database" pair, or the VM name depending on subtype. | |
hasResourceGuardOperationRequests | boolean | null | Whether a Resource Guard (Multi-User Authorization) protects critical operations on this item. | |
healthStatus | string | null | Backup health of an IaaS VM item: "Passed", "ActionRequired", "ActionSuggested", or "Invalid". Only populated for IaaS VM subtypes - null for SQL, SAP HANA, and file share items. | |
isArchiveEnabled | boolean | null | Whether recovery points for this item are moved to the archive tier, which changes restore latency. | |
isDeferredDeleteScheduleUpcoming | boolean | null | Whether permanent deletion of the soft-deleted backup data is imminent. | |
isPolicyInconsistent | boolean | null | Whether the effective backup policy is inconsistent with the assigned policy, normalized from policyInconsistent (IaaS VM) and policyState === "Inconsistent" (all other subtypes). May be null if the vault-scoped listing omits extended info. | |
isRehydrate | boolean | null | Whether an archived recovery point for this item is currently being rehydrated. | |
isScheduledForDeferredDelete | boolean | null | Whether the item has been soft-deleted and its backup data is on a countdown to permanent deletion. | |
lastBackupErrorCode | string | null | Error code from the most recent failed backup, flattened from the error detail object. | |
lastBackupErrorMessage | string | null | Error message from the most recent failed backup, flattened from the error detail object. | |
lastBackupOn | number | null | Timestamp (ms since epoch) of the most recent backup attempt. Null for Azure SQL protected items, which do not report it. A stale value indicates backups have stopped running. | |
lastBackupStatus | string | null | Status of the most recent backup. The vocabulary varies by subtype (IaaS VM items report free-form values such as "Completed"; workload items report "Healthy"/"Unhealthy"/"IRPending"), so treat it as an opaque string. | |
lastRecoveryPointOn | number | null | Timestamp (ms since epoch) of the newest recovery point available for this item. | |
oldestRecoveryPointOn | number | null | Timestamp (ms since epoch) of the oldest recovery point still retained - the floor of the restore window. May be null if the vault-scoped listing omits extended info. | |
parentName | string | null | SQL instance or availability group containing the protected database. Not an ARM resource ID. | |
parentType | string | null | Kind of parent recorded in parentName, e.g. "SQLInstance" or "SQLAG". | |
policyName | string | null | Name of the backup policy assigned to this item, which determines backup frequency and retention. | |
policyType | string | null | Backup policy generation for IaaS VM items: "V1" or "V2". Null for other subtypes. | |
protectedItemHealthStatus | string | null | Health of an in-VM workload item: "Healthy", "Unhealthy", "NotReachable", or "IRPending". Only populated for AzureVmWorkload subtypes. | |
protectedItemType | string | null | Wire discriminator for the protected item, e.g. "Microsoft.Compute/virtualMachines", "AzureFileShareProtectedItem", or "AzureVmWorkloadSQLDatabase". | |
protectionState | string | null | Backup protection state. Anything other than "Protected" (e.g. "ProtectionStopped", "ProtectionError", "ProtectionPaused", "BackupsSuspended", "IRPending") means the datasource is not currently being protected. | |
protectionStatus | string | null | Overall protection status reported for IaaS VM items: "Healthy" or "Unhealthy". Null for non-IaaS-VM workloads. | |
recoveryPointCount | number | null | Number of recovery points retained for this item. Zero means the datasource has never been successfully backed up. May be null if the vault-scoped listing omits extended info. | |
region | string | null | Azure region of the Recovery Services vault holding this item. | |
resourceGroup | string | null | Resource group of the Recovery Services vault holding this item. | |
serverName | string | null | Host or cluster name running the in-VM workload. Only populated for AzureVmWorkload subtypes. | |
softDeleteRetentionPeriodInDays | number | null | Number of days soft-deleted backup data is retained before permanent deletion - the ransomware recovery window. | |
workloadType | string | null | Datasource type being backed up, e.g. "VM", "AzureFileShare", "SQLDataBase", or "SAPHanaDatabase". |
Azure Bot Service Bot
azure_bot_service_bot inherits from Service
| Property | Type | Description | Specifications |
|---|---|---|---|
appPasswordHint * | string | null | ||
category * | array | null | ||
cmekEncryptionStatus * | string | null | ||
cmekKeyVaultUrl * | string | null | ||
configuredChannels * | array | null | ||
description * | string | null | ||
developerAppInsightKey * | string | null | ||
developerAppInsightsApiKey * | string | null | ||
developerAppInsightsApplicationId * | string | null | ||
displayName * | string | null | ||
enabledChannels * | array | null | ||
endpoint * | string | null | ||
endpointVersion * | string | null | ||
function * | array | null | ||
iconUrl * | string | null | ||
identityPrincipalId * | string | null | ||
identityTenantId * | string | null | ||
identityType * | string | null | ||
isCmekEnabled * | boolean | ||
isDeveloperAppInsightsApiKeySet * | boolean | null | ||
isLocalAuthenticationEnabled * | boolean | ||
isStreamingSupported * | boolean | ||
kind * | string | null | ||
location * | string | null | ||
luisAppIds * | array | null | ||
luisKey * | string | null | ||
manifestUrl * | string | null | ||
migrationToken * | string | null | ||
msaAppId * | string | null | ||
msaAppMSIResourceId * | string | null | ||
msaAppTenantId * | string | null | ||
msaAppType * | string | null | ||
name * | string | null | ||
openWithHint * | string | null | ||
provisioningState * | string | null | ||
publicNetworkAccess * | string | null | ||
publishingCredentials * | string | null | ||
region * | string | null | ||
resourceGroup * | string | null | ||
schemaTransformationVersion * | string | null | ||
skuName * | string | null | ||
skuTier * | string | null | ||
storageResourceId * | string | null | ||
tenantId * | string | null | ||
zones * | array | null |
Azure Bot Service Channel
azure_bot_service_channel inherits from Channel
| Property | Type | Description | Specifications |
|---|---|---|---|
category * | array | null | ||
channelName * | string | null | ||
function * | array | null | ||
isEnabled * | boolean | null | ||
location * | string | null | ||
name * | string | null | ||
region * | string | null | ||
resourceGroup * | string | null |
Azure Container Registry Repository
azure_container_registry_repository inherits from Repository
| Property | Type | Description | Specifications |
|---|---|---|---|
registry * | string | The registry login server this repository belongs to. | |
repositoryName * | string | The repository (image) name within the registry. |
Azure Data Factory
azure_data_factory inherits from Service
| Property | Type | Description | Specifications |
|---|---|---|---|
encryptionIdentityUserAssigned | string | null | ARM ID of the user-assigned identity used to reach the customer-managed key. Null when the system-assigned identity is used. | |
encryptionKeyName | string | null | Name of the Key Vault key used as the customer-managed key (CMK) for the factory. Null when Microsoft-managed encryption is used. | |
encryptionKeyVersion | string | null | Version of the customer-managed key. Null when the latest version is tracked automatically. | |
encryptionVaultBaseUrl | string | null | Base URL of the Key Vault holding the customer-managed key. | |
etag | string | null | ARM entity tag of the factory resource. | |
identityPrincipalId | string | null | Object ID of the factory system-assigned managed identity. | |
identityTenantId | string | null | Entra ID tenant ID of the factory managed identity. | |
identityType | string | null | Managed identity type: "SystemAssigned", "UserAssigned", or "SystemAssigned,UserAssigned". | |
identityUserAssignedIdentityIds | array | null | ARM IDs of the user-assigned managed identities attached to the factory. | |
isPublicNetworkAccessEnabled | boolean | null | Whether the factory accepts traffic from public networks. False when access is restricted to private endpoints. | |
isRepoPublishDisabled | boolean | null | Whether manual publishing from the Data Factory studio is disabled in favor of automated CI/CD publishing. | |
provisioningState | string | null | Provisioning state of the factory, e.g. "Succeeded" or "Failed". | |
purviewResourceId | string | null | ARM ID of the Microsoft Purview account the factory reports lineage to. | |
region | string | null | Azure region hosting the factory. | |
repoAccountName | string | null | Git account or organization name. | |
repoClientId | string | null | Client ID of the GitHub bring-your-own-app used for repository access. Null for GitHub Enterprise apps and Azure DevOps repositories. | |
repoCollaborationBranch | string | null | Git branch that factory publishes are made from, e.g. "main". | |
repoHostName | string | null | GitHub Enterprise host name. Null for github.com and for Azure DevOps repositories. | |
repoLastCommitId | string | null | Commit ID of the most recent publish from the collaboration branch. | |
repoProjectName | string | null | Azure DevOps project name. Null for GitHub repositories. | |
repoRepositoryName | string | null | Git repository name backing the factory. | |
repoRootFolder | string | null | Folder within the repository holding the factory resources. | |
repoTenantId | string | null | Entra ID tenant ID of the Azure DevOps organization. Null for GitHub repositories. | |
repoType | string | null | Git repository configuration type: "FactoryGitHubConfiguration" or "FactoryVSTSConfiguration". Null when the factory is in live mode with no Git integration. | |
resourceGroup | string | null | Resource group name extracted from the ARM ID. | |
version | string | null | Data Factory version, e.g. "2018-06-01". |