The Azure integration is the infrastructure twin of the AWS integration: read-only visibility into your subscriptions so encryption, exposure, logging, and backup controls verify continuously. If you run both clouds, connect both; the same cross-mapped controls consume evidence from each.
Prerequisites
- An OptiTech workspace with the Admin or Owner role.
- Owner or User Access Administrator on the target subscriptions, to assign the Reader role.
- The Entra ID integration is separate; this integration covers Azure resources, not identity.
Connect the integration
- In the OptiTech Console, go to Integrations and select Microsoft Azure.
- Click Connect and consent to the app registration in your tenant.
- Assign the Reader role (and Backup Reader for vault checks) to the OptiTech application on each subscription or on a management group to cover them all.
- Select which subscriptions are in scope and run the first sync.
Checks the integration activates
- Storage encryption and access: storage accounts verified for encryption, HTTPS-only, and no anonymous blob access.
- Network exposure: NSG rules and public IPs checked for unintended internet exposure, including management ports.
- Activity log coverage: diagnostic settings verified so control-plane actions are logged with required retention.
- Backup configuration: Recovery Services vaults, policy coverage for tagged VMs, and restore-point recency, feeding continuity controls.
- Defender for Cloud posture: secure score and plan coverage recorded per sync.
- Asset inventory sync: subscriptions, resource groups, and key resources enumerate into the asset inventory.
Failures open findings with the affected resource IDs, routed to the owning team.
Verify the connection
- Confirm each subscription shows Connected with a recent sync.
- Filter Controls by Source: Azure and spot-check a couple of results in the portal.
- Open a test NSG rule to the internet in a sandbox subscription and confirm the finding appears on the next sync, then remove it.
Troubleshooting
- Subscriptions missing: the Reader assignment hasn't propagated or was scoped to a resource group instead of the subscription; assign at subscription or management-group level.
- Backup checks empty: add the Backup Reader role; plain Reader can't enumerate vault details.
- Stale results: check the integration's sync schedule; large estates sync incrementally, and a full re-sync can be triggered from the integration page.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.