Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Integrate Microsoft Azure

Prev Next

Connecting your Microsoft Azure infrastructure to Scrut automates compliance evidence collection, eliminates manual configuration checks, and keeps your security posture continuously evaluated across your Azure environment. On successful integration, Scrut automatically scans your Azure infrastructure every 24 hours. You can integrate one or multiple Azure accounts, as needed.

This guide walks you through the step-by-step process of connecting your Azure infrastructure with Scrut.

What This Integration Does in Scrut

  • Automated Tests: Runs automated compliance checks that continuously evaluate your Azure configurations against applicable compliance frameworks.

  • Scrut Monitor: Collects evidence through Scrut Monitor. This helps automate evidence gathering and significantly speeds up compliance workflows.

  • Asset Management: Populates the Asset Management module in Scrut with discovered Azure assets and supports the collection of asset-related compliance evidence.

Prerequisites

  • An active Azure account with administrator access.

  • You must be an Organization Administrator, Global Administrator, or User Access Administrator in Azure or have a custom role with equivalent permissions.

Pro Tip!

Log in to your Microsoft Azure account before starting the integration setup. This keeps the setup steps uninterrupted.

Permissions and Access Requirements

For Azure

Scrut requires the following read-only Microsoft Graph API permissions for this integration:

  • AuditLog.Read.All: Grants access to activity logs, including changes in user accounts, directory configurations, and login attempts.

  • Directory.Read.All: Grants access to view group memberships, organizational hierarchy, and directory data.

  • User.Read: Grants access to retrieve user profiles, including names, emails, and roles.

For Scrut

  • Admin access to Scrut (or Contributor role with access to the Integration module).

Data Collected

  • Subscriptions

  • Resource Groups

  • Resources

  • Virtual Machines

  • Storage Accounts

  • SQL Servers

  • SQL Databases

  • Cosmos DB Accounts

  • Load Balancers

  • Key Vaults

  • Backup Jobs

  • Backup Policies

  • Alerts

  • Monitor Alerts

  • Monitor Alert Rules

  • Role Assignments

  • Network Security Groups

Sync Frequency

Data is synced automatically once every 24 hours from your Azure infrastructure to Scrut.

Note: Manual sync is not supported for this integration.

Integration Setup

The Microsoft Azure integration setup involves the following steps:

  1. Register a Scrut application in Azure and note the Application (client) ID and Directory (tenant) ID.

  2. Add the required API permissions to the registered application.

  3. Create a client secret for the registered application.

  4. Create an IAM role and assign it to the registered application in Azure.

  5. Connect your Azure account in Scrut.

  6. Configure the subscription scope.

Step 1: Create Scrut App Registration in Azure

  1. Go to the Azure Home Page.

  2. Search for “Azure Active Directory” in the search field and select Microsoft Entra ID.

  3. Expand the Manage menu in the left navigation panel and select App registrations.

  4. Click + New registration from the top menu.

  5. The Register an Application page opens. In the Application Name field, enter a name for the application, such as Scrut Evidence Collection or Scrut Application.

    Screenshot 2023-09-17 at 11.25.17 PM.png

  6. Under Account Type, select Accounts in this organizational directory only ([Default Directory] only - Single tenant).

  7. Click Register.

  8. Copy the Application (client) ID and Directory (tenant) ID.

Step 2: Add API Permissions to the Registered Application

  1. Expand the Manage menu and select API permissions from the left navigation panel.

  2. Click Add a permission.


  3. Select Microsoft Graph from the flyout menu.

  4. Select application permissions.

  5. In the Select permissions search field, enter AuditLog.Read.All.


  6. Select the AuditLog.Read.All checkbox.

  7. Search for Directory.Read.All.

  8. Select the Directory.Read.All checkbox.

  1. Click Add permissions.

  2. Click Grant admin consent for [Default Directory].

  3. Click Yes to confirm.

Step 3: Create a Client Secret for the Registered Application

  1. Select Certificates & secrets from the left-hand navigation.

  2. Click + New Client Secret.

  3. Add a description.

  4. Select a duration from the expires drop-down menu.

  5. Click Add to save the new Client Secret.

  6. Copy the Client Secret Value (third column) for later use.

Important

  • You cannot retrieve this Value after you leave this page. Copy and store it securely before proceeding.

  • Do not enter the Secret ID in place of the client secret value when connecting Scrut. Only the client secret value is accepted.

Note

To restrict access to the Scrut integration to a specific Resource Group in your Azure subscription, please follow the guidelines outlined in the section "Use Case: Create IAM Role on a Resource Group." We recommend not limiting access in this way and configuring the scope directly in Scrut. To do this please move on to Step 4.

Use Case: Create IAM Role on a Resource Group

  1. In Azure, click on your preferred Resource Group, navigate to Access Control (IAM), click Add and select Add role assignment.

  2. Select Reader from the Role dropdown menu and click Next.

  3. Select User, group or service principal.

  4. Click on Select members and search for the app you created earlier (Scrut Application).

  5. Click review + assign.

  6. Watch out for the notification indicating successful role assignment.  

Note:

Proceed to Step 5.

Step 4: Create IAM Role

  1. In Azure, click on your subscription, navigate to Access Control (IAM), click Add and select Add role assignment.

  2. Select Reader from the Role dropdown menu and click Next.

  3. Select User, group or service principal.

  4. Click Select members and search for the app you created earlier (Scrut Application).

  5. Click Review + assign.

  6. Watch out for the notification indicating successful role assignment.  

Step 5: Connect Azure With Scrut

  1. Sign in to Scrut and click Integrations on the left navigation panel.

  2. Click the Integrations Library tab and navigate to Cloud Providers in the Categories section.

  3. Locate the Microsoft Azure integration tile and click Integrate.

  4. Enter the Client ID, Tenant ID and Client Secret, which we fetched from Azure in the previous steps. Enter an Account Nickname.

    Important:

    Do NOT enter the secret ID in place of client secret value. Only enter the client secret value.

  5. If you’re integrating with Azure GovCloud, make sure to enable the GovCloud toggle in this step. This enables connecting with government entities. This ensures that customers working in regulated environments can leverage Scrut's capabilities while staying compliant with government cloud requirements.

  6. Select the appropriate region for the Azure GovCloud from the dropdown.

  7. Click Connect.

Watch out for the “Integration Successful” and “Credentials Validated Successfully” notifications.

Step 6: Configure Scopes & Nicknames

The final step in the integration process is to configure which Azure subscriptions Scrut should scan:

  • Select one or multiple subscriptions to include in the scan

  • Enter a suitable nickname for each, and click Finish

Watch out for the success notification and the connected status flag.

Note:

Scrut does not scan unselected subscriptions, and tests for those subscriptions do not appear in the Cloud module.

Integrating Multiple Azure Accounts

To connect an additional Azure account:

  1. Sign in to Scrut and click Integrations on the left navigation panel.

  2. Navigate to the Connected Integrations tab and search for 'Azure'.

  3. Click Configure on the Azure integration tile.

  4. Click Add.

  5. Follow the same steps as those for your first Azure account, starting from Step 5.

What Happens Next?

Initial data sync

The initial sync begins automatically after setup. It may take up to 24 hours for Scrut to populate the first scan results. Check the Audit Logs tab on the Microsoft Azure integration page to track the sync status.

Note: If results are not available after 24 hours, contact support@scrut.io for help.

Review synced data

Once the sync completes, verify that data has landed correctly in the following modules:

  • Navigate to Cloud to view automated test results and flagged misconfigurations.

  • Navigate to Evidence Tasks to set up Scrut Monitors to automate evidence collection from Azure.

  • Navigate to Asset Management to view discovered Azure assets.

Common Errors & Troubleshooting

Integration shows as not connected after submitting

Possible solutions: Verify that the Client ID, Tenant ID, and Client Secret were copied correctly from Azure. Leading or trailing spaces can cause validation failures. Confirm that admin consent was granted for all required API permissions before connecting. Ensure you entered the client secret Value, not the Secret ID.

Data not appearing after 24 hours

Possible solutions: Check the Audit Logs tab on the Microsoft Azure integration page to confirm whether the scan completed successfully. Verify that at least one subscription was selected in the scope configuration. If the Audit Logs show errors, contact support@scrut.io with the error details.

Resources are missing in the Cloud module

Possible solutions: Confirm that the subscription containing the resource is selected in your scope configuration. Confirm that the AuditLog.Read.All and Directory.Read.All permissions are granted, and the admin consent was applied.

Client secret has expired

Possible solutions: Azure client secrets have a defined expiry period. If your integration stops working after the expiry date, generate a new client secret in Azure and update it in Scrut by clicking the edit icon on your connected Azure integration.

FAQs


1: Can I modify the scope of a connected Azure integration?

Yes. You can update the Azure subscriptions Scrut monitors at any time. Click the edit icon on your connected Azure integration, update the subscription selection or nicknames, and click Finish.

  1. Click the edit Pencil icon.pngicon in your connected Azure integration.

  2. The Client ID, Tenant ID, and Client Secret will be auto-filled.

    Note: You can also edit the Client Secret. Replace it with a new client secret when the current one expires, based on the expiration period configured during setup.

  3. Enter an Account Nickname and choose the Entities to which the integration applies.

  4. Click Save.

  5. Watch out for the “Fetched Azure subscriptions successfully” notifications.

  6. Select the Azure Subscription IDs that you want to connect with Scrut. You can also unselect previously selected subscriptions.

    Note: Deselecting a subscription will:

    • Remove all tests associated with that subscription in the Cloud module

    • Decrease overall compliant/non-compliant test counts

    • Remove the subscription from the account selection dropdown in the Cloud module

  7. Enter a suitable nickname for each, and click Finish.

Watch out for the connected status flag.

2: Can I integrate multiple Azure accounts with Scrut?

Yes. Scrut supports multiple Azure accounts. Each account requires its own app registration and client secret in Azure.

3: What happens if I deselect a subscription from my scope?

Deselecting a subscription removes all associated tests from the Cloud module, decreases overall compliant and non-compliant test counts, and removes the subscription from the account selection dropdown in the Cloud module.

4: What happens if I rotate my Azure client secret?

If the client secret expires or is rotated, your integration stops syncing. Generate a new client secret in Azure, then update the value in your Scrut integration settings before the expiry date to avoid a coverage gap.

5: Can I restrict the integration to a specific Resource Group instead of an entire subscription?

Yes. To limit access to a specific Resource Group, follow the IAM role assignment steps (Step 4) at the Resource Group level instead of the subscription level. Note that Scrut recommends configuring scope at the subscription level in Scrut for broader coverage.

6: Where can I view the full list of automated tests and evidence collected for Azure?

Sign in to Scrut, click Integrations on the left navigation panel, and click the Microsoft Azure tile to expand it. The expanded view lists all Automated Tests and Automated Evidence collected via Scrut Monitor for your connected Azure account.

7: Does Scrut support Azure GovCloud?

Yes. To connect an Azure GovCloud account, turn on the GovCloud account toggle in the Credentials step and select your GovCloud region when setting up your Microsoft Azure integration.