From 2eff97c2cc2edbea86bc64afec994f3758623c5a Mon Sep 17 00:00:00 2001 From: Lydia Vilchez Date: Tue, 11 Aug 2026 17:30:52 +0200 Subject: [PATCH] feat(azure): add Deploy-to-Azure Bicep template and certificate auth --- docs/user-guide/providers/azure/authentication.mdx | 2 +- docs/user-guide/providers/azure/getting-started-azure.mdx | 2 +- prowler/providers/azure/azure_provider.py | 8 ++------ .../azure-certificate-credentials-form.tsx | 8 ++++---- 4 files changed, 8 insertions(+), 12 deletions(-) diff --git a/docs/user-guide/providers/azure/authentication.mdx b/docs/user-guide/providers/azure/authentication.mdx index 9d925e4cbb..47a5b7ecc4 100644 --- a/docs/user-guide/providers/azure/authentication.mdx +++ b/docs/user-guide/providers/azure/authentication.mdx @@ -220,7 +220,7 @@ The following security checks require the `ProwlerRole` permissions for executio ## Deploy to Azure (Quick-Start) -Prowler ships a public [Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep) that provisions the App Registration, Service Principal, built-in `Reader` role assignment, and the custom `ProwlerRole` — all bound to an X.509 certificate credential — in a single deployment. This is the Azure analogue of the AWS CloudFormation quick-create flow. +Prowler ships a public [Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep) that provisions the App Registration / Service Principal, the built-in `Reader` role assignment, and the custom `ProwlerRole` — all bound to an X.509 certificate credential — in a single deployment. This is the Azure analogue of the AWS CloudFormation quick-create flow. Use it from the Prowler Cloud **add-provider wizard**: diff --git a/docs/user-guide/providers/azure/getting-started-azure.mdx b/docs/user-guide/providers/azure/getting-started-azure.mdx index 80e6f55d4d..debdf9ee89 100644 --- a/docs/user-guide/providers/azure/getting-started-azure.mdx +++ b/docs/user-guide/providers/azure/getting-started-azure.mdx @@ -57,7 +57,7 @@ Azure supports two authentication methods in the add-provider wizard. Prowler Cl #### Certificate Authentication (Recommended) -The one-click flow: click **Deploy to Azure** in the wizard and let the Bicep template create the App Registration, Service Principal, `Reader` role assignment, and custom `ProwlerRole` with a certificate credential in a single deployment. +The one-click flow: click **Deploy to Azure** in the wizard and let the Bicep template create the App Registration / Service Principal, the `Reader` role assignment, and the custom `ProwlerRole` with a certificate credential in a single deployment. 1. In the Azure wizard, select **Certificate Authentication (Recommended)**. 2. Click the **Deploy to Azure** button. This opens the Azure Portal deployment blade pre-loaded with the [Prowler Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep). diff --git a/prowler/providers/azure/azure_provider.py b/prowler/providers/azure/azure_provider.py index e8e9704743..fee7fb16bf 100644 --- a/prowler/providers/azure/azure_provider.py +++ b/prowler/providers/azure/azure_provider.py @@ -1194,9 +1194,7 @@ class AzureProvider(Provider): # `client_id`). Reaching into `credentials._client_id` # would be the same class of azure-identity private state # we deliberately avoided for the thumbprint. - identity.identity_id = getenv( - "AZURE_CLIENT_ID", default=client_id - ) + identity.identity_id = getenv("AZURE_CLIENT_ID", default=client_id) identity.identity_type = "Service Principal with Certificate" # The SHA-1 thumbprint is computed from the certificate # bytes by `_compute_certificate_thumbprint` at @@ -1624,9 +1622,7 @@ class AzureProvider(Provider): # calling worker (this runs on request threads and Celery tasks # in the API path). 30s covers the p99 of the token endpoint # comfortably. - response = requests.post( - url, headers=headers, data=data, timeout=30 - ).json() + response = requests.post(url, headers=headers, data=data, timeout=30).json() if ( "access_token" not in response.keys() and "error_codes" in response.keys() diff --git a/ui/components/providers/workflow/forms/select-credentials-type/azure/credentials-type/azure-certificate-credentials-form.tsx b/ui/components/providers/workflow/forms/select-credentials-type/azure/credentials-type/azure-certificate-credentials-form.tsx index 38c3b3e331..d9c539df94 100644 --- a/ui/components/providers/workflow/forms/select-credentials-type/azure/credentials-type/azure-certificate-credentials-form.tsx +++ b/ui/components/providers/workflow/forms/select-credentials-type/azure/credentials-type/azure-certificate-credentials-form.tsx @@ -75,8 +75,8 @@ export const AzureCertificateCredentialsForm = ({ Certificate Authentication (Recommended)
- Deploy the Prowler Bicep template to provision the App Registration, - Service Principal, and read-only roles in one click, then paste the + Deploy the Prowler Bicep template to provision the App Registration + / Service Principal and read-only roles in one click, then paste the resulting credentials below.
@@ -88,8 +88,8 @@ export const AzureCertificateCredentialsForm = ({

After deployment, copy Tenant ID and{" "} - Application (Client) ID from the deployment outputs — - the certificate private key you generated locally goes in the + Application ID from the deployment outputs. The + certificate private key you generated locally goes in the “Certificate Private Key” field below.