Files
prowler/docs/user-guide/providers/azure/getting-started-azure.mdx
T
Lydia Vilchez 3762c9ba6b feat(ui): add Azure Deploy-to-Azure wizard, Bicep template, and docs
Add the Azure certificate authentication onboarding to the
add-provider wizard. The wizard shows a credential-type selector
(certificate authentication recommended, service principal with
client secret as fallback) and, for the certificate flow, an in-browser
key-pair generator plus a Deploy-to-Azure quick-start that opens the
Azure Portal with the Prowler Bicep template pre-loaded.

Also publishes the ARM template through Prowler documentation with
byte-for-byte drift tests, and rewrites the Azure authentication
guide to reflect the new flow.
2026-08-31 18:22:58 +02:00

151 lines
4.8 KiB
Plaintext

---
title: "Getting Started With Azure on Prowler"
---
## Prowler Cloud
<iframe
width="560"
height="380"
src="https://www.youtube-nocookie.com/embed/v1as8vTFlMg"
title="Prowler Cloud Onboarding Azure"
frameborder="0"
allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
allowfullscreen="1"
></iframe>
> Walkthrough video onboarding an Azure Subscription using Service Principal.
<Note>
**Government Cloud Support**
Government cloud subscriptions (Azure Government) are not currently supported, but we expect to add support for them in the near future.
</Note>
### Prerequisites
Before setting up Azure in Prowler Cloud, you need to create a Service Principal with proper permissions.
For detailed instructions on how to create the Service Principal and configure permissions, see [Authentication > Service Principal](/user-guide/providers/azure/authentication#service-principal-application-authentication-recommended).
---
### Step 1: Get the Subscription ID
1. Go to the [Azure Portal](https://portal.azure.com/#home) and search for `Subscriptions`
2. Locate and copy your Subscription ID
![Search Subscription](/images/providers/search-subscriptions.png)
![Subscriptions Page](/images/providers/get-subscription-id.png)
---
### Step 2: Access Prowler Cloud
1. Navigate to [Prowler Cloud](https://cloud.prowler.com/) or launch [Prowler Local Server](/user-guide/tutorials/prowler-app)
2. Navigate to `Configuration` > `Providers`
![Providers Page](/images/prowler-app/cloud-providers-page.png)
3. Click `Add Provider`
![Add a Provider](/images/prowler-app/add-cloud-provider.png)
4. Select `Microsoft Azure`
![Select Microsoft Azure](/images/providers/select-azure-prowler-cloud.png)
5. Add the Subscription ID and an optional alias, then click `Next`
![Add Subscription ID](/images/providers/add-subscription-id.png)
### Step 3: Add Credentials to Prowler Cloud
Azure supports two authentication methods in the add-provider wizard. Prowler Cloud shows a credential-type selector where you can pick the one that fits.
#### Certificate Authentication (Recommended)
Certificate authentication uses a Microsoft Entra ID App Registration with an X.509 certificate. Complete the App Registration, certificate upload, Microsoft Graph permissions, and subscription permissions by following [Azure Certificate Authentication](/user-guide/providers/azure/authentication#certificate-authentication).
1. In the Azure wizard, select **Certificate Authentication (Recommended)**.
2. Paste the Directory (tenant) ID and Application (client) ID from the App Registration.
3. Paste the base64-encoded certificate and private key bundle. To create a new key pair, click **Generate certificate**, upload the downloaded `prowler-cert.cer` file to the App Registration, and keep the generated bundle in the form.
4. Click **Next**, then **Launch Scan**.
#### Service Principal with Client Secret
Client-secret authentication remains available when certificate authentication is not suitable.
1. Follow [Creating Prowler Service Principal](/user-guide/providers/azure/create-prowler-service-principal) to create the App Registration, assign the [Entra](/user-guide/providers/azure/create-prowler-service-principal#assigning-proper-permissions) and [Subscription](/user-guide/providers/azure/subscriptions) scope permissions, and issue a client secret.
2. In the Azure wizard, select **Service Principal with Client Secret**.
3. Paste `Tenant ID`, `Client ID`, and `Client Secret`.
![Prowler Cloud Azure Credentials](/images/providers/add-credentials-azure-prowler-cloud.png)
4. Click `Next`, then **Launch Scan**.
![Launch Scan Azure](/images/providers/launch-scan.png)
---
## Prowler CLI
### Configure Azure Credentials
To authenticate with Azure, Prowler CLI supports multiple authentication methods. Choose the method that best suits your environment.
For detailed authentication setup instructions, see [Authentication](/user-guide/providers/azure/authentication).
**Service Principal with Client Secret**
Set up environment variables:
```console
export AZURE_CLIENT_ID="XXXXXXXXX"
export AZURE_TENANT_ID="XXXXXXXXX"
export AZURE_CLIENT_SECRET="XXXXXXX"
```
Then run:
```console
prowler azure --sp-env-auth
```
**Azure CLI Credentials**
Use stored Azure CLI credentials:
```console
prowler azure --az-cli-auth
```
**Browser Authentication**
Authenticate using your default browser:
```console
prowler azure --browser-auth --tenant-id <tenant-id>
```
**Managed Identity**
When running on Azure resources:
```console
prowler azure --managed-identity-auth
```
### Subscription Selection
To scan a specific Azure subscription:
```console
prowler azure --subscription-ids <subscription-id>
```
To scan multiple Azure subscriptions:
```console
prowler azure --subscription-ids <subscription-id1> <subscription-id2> <subscription-id3>
```