AQUILA CSPM - Azure Integration
This manual explains how to get started monitoring the security posture of your Azure CSP using the Cloud Security Posture Management (CSPM) feature.
Requirements
- The user who gives the CSPM integration permissions in Azure must be an Azure subscription admin.
Setup
Option 1: Service principal with client secret (recommended)
Before using this method, you must have set up a Microsoft Entra application and service principal that can access resources. Please go here before following the steps below.
- The following information is required.
- Directory (tenant) ID and Application (client) ID
- To get these values:
- Go to the Registered apps section of Microsoft Entra ID.
- Click on New Registration, name your app and click Register.
- Copy your new app’s Directory (tenant) ID and Application (client) ID.
- To get these values:
- Directory (tenant) ID and Application (client) ID
- Client Secret
- In Azure portal, select Certificates & secrets, then go to the Client secrets tab. Click New client secret.
- Copy the new secret.
Option 2: Managed identity (optional)
This method involves creating an
Azure VM (or using an existing one), giving it read accessHow to the resources you wantintegrate to monitorAQUILA withCSPM CSPM,Module
Pre-requisites
- Access to CyTech - AQUILA
-
Only users assigned the
installing"Owner" or "Admin" role can access the Log Collectoroninstallation resources within theAzure VM.platform.Go to the Azure portal to create a new Azure VM.Followthe setup process, and make sure you enableSystem assigned managed identityunder theManagementtab.Go to your Azure subscription list and select the subscription or management group you want to monitor with CSPM.Go toAccess control (IAM)and selectAdd Role Assignment.Select theReaderrole, assign access toManaged Identity, then select your VM.
Step 1: Log in to CyTech - AQUILA. Click here --> AQUILACYBER.aiStep 2: Click on Cyber Monitoring.Step 3: Choose Cloud Security Posture Management (CSPM).
Step 4: Click the "Let's Go" or "Onboard CSPM" icon to launch installation window.
Step 5: Click "Let's go" to start the integration process.
Step 6: Choose your log collector. If you haven't installed a log collector yet choose "New Log Collector" click here --> Log Collector Installation. If you have already have an existing log collector choose "Current Log Collector" and click "Next".
Step 7: Click "Next" if the requirements are met.
Step 8: Choose your current log collector. This will collect the logs coming from your log sources.
Step 9: Choose Azure and click "Next" to proceed.
Step 10: Input all the required credentials from the previous Azure configurations and click "Next" to initiate the integration process. Wait for couple of minutes until a success window shows up.
Please refer to this manual for the full guidelines of our CSPM Module. click here--> CyTech - AQUILA CSPM Manual
If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.
-