mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 18:44:24 +00:00
29 lines
1.7 KiB
Plaintext
29 lines
1.7 KiB
Plaintext
---
|
|
title: 'Azure Subscription Scope'
|
|
---
|
|
|
|
Prowler performs security scans within the subscription scope in Azure. To execute checks, it requires appropriate permissions to access the subscription and retrieve necessary metadata.
|
|
|
|
By default, Prowler operates multi-subscription, scanning all subscriptions it has permission to list. If permissions are granted for only a single subscription, Prowler will limit scans to that subscription.
|
|
|
|
## Configuring Specific Subscription Scans in Prowler
|
|
|
|
Additionally, Prowler supports restricting scans to specific subscriptions by passing a set of subscription IDs as an input argument. To configure this limitation, use the appropriate command options:
|
|
|
|
```console
|
|
prowler azure --az-cli-auth --subscription-ids <subscription ID 1> <subscription ID 2> ... <subscription ID N>
|
|
```
|
|
|
|
Prowler allows you to specify one or more subscriptions for scanning (up to N), enabling flexible audit configurations.
|
|
|
|
<Warning>
|
|
The multi-subscription feature is available only in the CLI. In Prowler Cloud, each scan is limited to a single subscription.
|
|
|
|
</Warning>
|
|
## Assigning Permissions for Subscription Scans
|
|
Check the [Authentication > Subscription Scope Permissions](/user-guide/providers/azure/authentication#subscription-scope-permissions) guide for more information on how to assign permissions for subscription scans.
|
|
|
|
## Recommendation for Managing Multiple Subscriptions
|
|
|
|
Scanning multiple subscriptions requires creating and assigning roles for each, which can be a time-consuming process. To streamline subscription management and auditing, use [Azure Management Groups](/user-guide/providers/azure/management-groups) to organize subscriptions and assign permissions collectively.
|