mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
Add the Azure certificate authentication onboarding to the add-provider wizard. The wizard shows a credential-type selector (certificate authentication recommended, service principal with client secret as fallback) and, for the certificate flow, an in-browser key-pair generator plus a Deploy-to-Azure quick-start that opens the Azure Portal with the Prowler Bicep template pre-loaded. Also publishes the ARM template through Prowler documentation with byte-for-byte drift tests, and rewrites the Azure authentication guide to reflect the new flow.
151 lines
4.8 KiB
Plaintext
151 lines
4.8 KiB
Plaintext
---
|
|
title: "Getting Started With Azure on Prowler"
|
|
---
|
|
|
|
## Prowler Cloud
|
|
|
|
<iframe
|
|
width="560"
|
|
height="380"
|
|
src="https://www.youtube-nocookie.com/embed/v1as8vTFlMg"
|
|
title="Prowler Cloud Onboarding Azure"
|
|
frameborder="0"
|
|
allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
|
|
allowfullscreen="1"
|
|
></iframe>
|
|
> Walkthrough video onboarding an Azure Subscription using Service Principal.
|
|
|
|
<Note>
|
|
**Government Cloud Support**
|
|
|
|
Government cloud subscriptions (Azure Government) are not currently supported, but we expect to add support for them in the near future.
|
|
|
|
</Note>
|
|
### Prerequisites
|
|
|
|
Before setting up Azure in Prowler Cloud, you need to create a Service Principal with proper permissions.
|
|
|
|
For detailed instructions on how to create the Service Principal and configure permissions, see [Authentication > Service Principal](/user-guide/providers/azure/authentication#service-principal-application-authentication-recommended).
|
|
|
|
---
|
|
|
|
### Step 1: Get the Subscription ID
|
|
|
|
1. Go to the [Azure Portal](https://portal.azure.com/#home) and search for `Subscriptions`
|
|
2. Locate and copy your Subscription ID
|
|
|
|

|
|

|
|
|
|
---
|
|
|
|
### Step 2: Access Prowler Cloud
|
|
|
|
1. Navigate to [Prowler Cloud](https://cloud.prowler.com/) or launch [Prowler Local Server](/user-guide/tutorials/prowler-app)
|
|
2. Navigate to `Configuration` > `Providers`
|
|
|
|

|
|
|
|
3. Click `Add Provider`
|
|
|
|

|
|
|
|
4. Select `Microsoft Azure`
|
|
|
|

|
|
|
|
5. Add the Subscription ID and an optional alias, then click `Next`
|
|
|
|

|
|
|
|
### Step 3: Add Credentials to Prowler Cloud
|
|
|
|
Azure supports two authentication methods in the add-provider wizard. Prowler Cloud shows a credential-type selector where you can pick the one that fits.
|
|
|
|
#### Certificate Authentication (Recommended)
|
|
|
|
Certificate authentication uses a Microsoft Entra ID App Registration with an X.509 certificate. Complete the App Registration, certificate upload, Microsoft Graph permissions, and subscription permissions by following [Azure Certificate Authentication](/user-guide/providers/azure/authentication#certificate-authentication).
|
|
|
|
1. In the Azure wizard, select **Certificate Authentication (Recommended)**.
|
|
2. Paste the Directory (tenant) ID and Application (client) ID from the App Registration.
|
|
3. Paste the base64-encoded certificate and private key bundle. To create a new key pair, click **Generate certificate**, upload the downloaded `prowler-cert.cer` file to the App Registration, and keep the generated bundle in the form.
|
|
4. Click **Next**, then **Launch Scan**.
|
|
|
|
#### Service Principal with Client Secret
|
|
|
|
Client-secret authentication remains available when certificate authentication is not suitable.
|
|
|
|
1. Follow [Creating Prowler Service Principal](/user-guide/providers/azure/create-prowler-service-principal) to create the App Registration, assign the [Entra](/user-guide/providers/azure/create-prowler-service-principal#assigning-proper-permissions) and [Subscription](/user-guide/providers/azure/subscriptions) scope permissions, and issue a client secret.
|
|
2. In the Azure wizard, select **Service Principal with Client Secret**.
|
|
3. Paste `Tenant ID`, `Client ID`, and `Client Secret`.
|
|
|
|

|
|
|
|
4. Click `Next`, then **Launch Scan**.
|
|
|
|

|
|
|
|
---
|
|
|
|
## Prowler CLI
|
|
|
|
### Configure Azure Credentials
|
|
|
|
To authenticate with Azure, Prowler CLI supports multiple authentication methods. Choose the method that best suits your environment.
|
|
|
|
For detailed authentication setup instructions, see [Authentication](/user-guide/providers/azure/authentication).
|
|
|
|
**Service Principal with Client Secret**
|
|
|
|
Set up environment variables:
|
|
|
|
```console
|
|
export AZURE_CLIENT_ID="XXXXXXXXX"
|
|
export AZURE_TENANT_ID="XXXXXXXXX"
|
|
export AZURE_CLIENT_SECRET="XXXXXXX"
|
|
```
|
|
|
|
Then run:
|
|
|
|
```console
|
|
prowler azure --sp-env-auth
|
|
```
|
|
|
|
**Azure CLI Credentials**
|
|
|
|
Use stored Azure CLI credentials:
|
|
|
|
```console
|
|
prowler azure --az-cli-auth
|
|
```
|
|
|
|
**Browser Authentication**
|
|
|
|
Authenticate using your default browser:
|
|
|
|
```console
|
|
prowler azure --browser-auth --tenant-id <tenant-id>
|
|
```
|
|
|
|
**Managed Identity**
|
|
|
|
When running on Azure resources:
|
|
|
|
```console
|
|
prowler azure --managed-identity-auth
|
|
```
|
|
|
|
### Subscription Selection
|
|
|
|
To scan a specific Azure subscription:
|
|
|
|
```console
|
|
prowler azure --subscription-ids <subscription-id>
|
|
```
|
|
|
|
To scan multiple Azure subscriptions:
|
|
|
|
```console
|
|
prowler azure --subscription-ids <subscription-id1> <subscription-id2> <subscription-id3>
|
|
```
|