Connect Microsoft Azure
Argus scans an Azure subscription read-only through a service principal, an app registered in Microsoft Entra ID (formerly Azure AD). Nothing is installed in the subscription, and Argus only ever reads.
Before you start
- Permission to register an application in Microsoft Entra ID and assign it a role on the subscription.
- An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.
Provider-side setup
- In the Microsoft Entra admin center, register an application. This creates the service principal Argus authenticates as.
- On the subscription, assign the service principal a read-only role, such as Reader, scoped to what you want scanned. Argus only reads, so no write role is needed.
- Create a client secret for the app, and copy the Client ID and the Tenant ID from the app's Overview.
Required permissions
Assign the service principal, at subscription scope:
- the built-in Reader role (read-only), and
- a small custom role granting two read actions that Reader does not cover,
needed for the Azure Functions checks:
Microsoft.Web/sites/host/listkeys/actionMicrosoft.Web/sites/config/list/Action
For the Microsoft Entra (identity) checks, also grant the app these read-only Microsoft Graph permissions:
AuditLog.Read.AllDirectory.Read.All(orDomain.Read.All)Policy.Read.All
Connect in Argus
Go to Accounts and click Connect account. Pick Microsoft Azure, then the Service principal method. Enter:
| Field | Value |
|---|---|
| Subscription ID | the subscription's UUID |
| Client ID | the Application (client) ID |
| Client secret | the secret created in step 3 |
| Tenant ID | the Directory (tenant) ID |
Connection test
Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.