Microsoft Azure Data Collection Prerequisites

Microsoft Azure Data Collection Prerequisites

#410110

Obtaining Azure Account Credentials

Use the following information to create and configure the user name and password for your Azure account. You will then use this information to create a cloud connection from your Densify instance.

Note:  Azure Stack is not supported. This data collection method currently only supports Azure Cloud.

Additionally, only the standalone Azure Active Directory is supported. If you are using a federated (local) account, see Microsoft Azure Data Collection Prerequisites for a Service Principal for details on obtaining the required keys and IDs from your Azure account.

The account must be assigned the role of "Reader" for each of the subscriptions from which data will be collected.

If you are using the Densify API you must use a service principle to create the connection. See Microsoft Azure Data Collection Prerequisites for a Service Principal for details

Create User Account

  1. Login into your Azure account and click on Azure Active Directory > Users.
  2. Click New user to create the new account.
  3. Enter a name and user name. The user name should be a valid email address. The user name is the identifier that you will use to sign into Azure Active Directory.
  4. Optionally, configure a profile.
  5. Optionally, select the Group(s) to which this user belongs.
  6. Optionally, select a Directory role. By default the directory role is set to user, which is adequate for the purpose of creating a cloud connection through Densify.
  7. The password is auto-generated. Click Show Password to see the password and copy it for later use
  8. Note:  Depending on your company's password policy, you may need to change this password before using it to create the Densify cloud connection. If necessary, change the automatically generated password and then create the cloud connection.

  9. Click Create to create the user account. This button only comes visible when you have correctly entered the required information.

Assigning User Access to Subscriptions

The user, created above, now needs access to each of your subscriptions. You need to assign the "Reader" role to the user for each subscription being audited, by doing the following:

  1. Navigate to Subscriptions in the main menu. You may need to click on More services to see Subscriptions.
  2. Click on a subscription to select and open the configuration page.
  3. Click Access Control (IAM).
  4. Click Add.
  5. In the Add Permissions pane select the Role of "Reader".
  6. Ensure Assign Access to is set to Azure AD user, group or application.
  7. Search for or scroll to locate the user that you created. above.
  8. Select the user. It will appear under Selected members.
  9. Click Save to save these changes.
  10. The user account that will be used to create the cloud connection will need access to all subscriptions from which you want to collect data, so repeat this process for each subscription to be included.

Once the account has been configured you can use the user name and password to create the cloud connection as outlined in Using the Public Cloud Connections Wizard.

Creating the Cloud Connection in Densify

Once all of the prerequisites are complete, you can create the cloud connection through the Cloud Connection wizard. See Using the Public Cloud Connections Wizard.

Modifying Your Azure Cloud Connection

When you create the Azure cloud connection for the first time, Densify discovers all of the subscriptions, associated with the user or service principal. Upon saving the connection it will schedule data collection from each of the discovered and selected subscriptions.

If subsequently, subscriptions are added, they will not be included in data collection. Additionally, subscriptions that are removed will continue to be included, resulting in wasted time and resources. To add new subscriptions or remove old ones, edit the cloud connection. See Editing a Connection.