Create a Microsoft Azure Connector
The following is not supported in Tenable FedRAMP Moderate environments. For more information, see the Tenable FedRAMP Moderate Product Offering.
Required User Role: Administrator
Before you begin:
- Complete the required Microsoft Azure configuration steps.
- Update your plugin set to 2018-12-19 or later.
To create a Microsoft Azure connector:
-
In the upper-left corner, click the button.
The left navigation plane appears.
-
In the left navigation plane, click Settings.
The Settings page appears.
-
Click the Cloud Connectors tile.
The Cloud Connectors page appears and displays the configured connectors table.
-
In the upper-right corner of the page, click the Create Cloud Connector button.
The Cloud Connectors plane appears.
- In the Cloud Connectors section, click Microsoft Azure.
The Microsoft Azure settings plane appears.
- In the Connector Name box, type a name to identify the connector.
- In the Application ID box, type the Azure application ID that you obtained when configuring Microsoft Azure.
- In the Tenant ID box, type the Azure Tenant ID obtained when configuring Microsoft Azure.
- In the Client Secret box, type the client secret obtained when configuring Microsoft Azure.
- Use the Auto Account Discovery toggle to enable or disable automatic discovery of Azure subscription ID(s).Note: Auto account discovery is enabled by default. The Azure connector automatically discovers your subscription ID and any linked subscription ID(s).
-
(Optional) If Auto Account Discovery is disabled, manually add one or more subscription IDs:
- In the Subscription IDs section, click the button next to Subscription IDs.
The Add Subscription IDs plane appears.
-
In the Subscription ID box, type the subscription ID obtained when configuring Microsoft Azure.
-
(Optional) Click the button next to Add Another Subscription ID to add additional linked Azure accounts.
-
In the Subscription ID box, type the subscription ID for the Azure account that you want to link. For information about configuring linked subscriptions, see Link Azure Subscription.
-
To add the Subscription ID(s), click Add.
Tenable Vulnerability Management displays the Microsoft Azure settings plane, and the Subscription ID(s) you linked are listed under Subscription IDs.
- In the Subscription IDs section, click the button next to Subscription IDs.
-
In the Select or Create Network drop-down box, select an existing network for your connector or click the button to create a new network.Note: Networks help to avoid IP address collisions between cloud assets and Nessus-discovered assets. Tenable recommends creating a network for each connector type in use to prevent asset records in different cloud environments from overwriting each other. For more information about the network feature, see Networks.
- Use the Schedule Import toggle to enable or disable scheduled imports.Note: By default, Tenable Vulnerability Management requests new and updated asset records every (1) days.
When enabled:
- In the Import text box, type the frequency with which Tenable Vulnerability Management sends data requests to the Azure server.
- In the drop-down box select Minutes, Hours, or Days.Note: When you schedule a connector configuration to sync every 30 minutes, a discovery job is placed in a queue every 30 minutes. The results of the discovery job become available in the Tenable Vulnerability Management interface and logs depending on the workload for the connector services. So, the results of the discovery job can take more than 30 minutes depending on the queue.
- Do one of the following:
- To save the connector, click Save.
- To save the connector and import your assets from Azure, click Save & Import.
Note: There may be a short delay before your assets appear in Tenable Vulnerability Management.