Microsoft Azure provider permissions - List of Microsoft Azure provider permissions for Cortex Cloud. - Administrator Guide - Cortex CLOUD

Cortex Cloud Posture Management Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Posture Management
Creation date
2025-01-22
Last date published
2026-06-10
Category
Administrator Guide
Abstract

List of Microsoft Azure provider permissions for Cortex Cloud.

When onboarding Microsoft Azure, Cortex Cloud requests only the permissions needed for the security capabilities you enable, following the principle of least privilege. The required permissions depend on your onboarding scope (tenant, management group, or subscription) and your selected security capabilities. Permissions fall into three categories:

  • Required at all scopes: the Discovery Engine capability, which provides the asset visibility that all other Cortex Cloud capabilities depend on and cannot be deselected. It requires the Microsoft Graph Application.Read.All permission, which is used as follows:

    • Tenant scope: during onboarding to create the Cortex service principal, and post-onboarding for ongoing asset discovery.

    • Management group and subscription scopes: during onboarding only, to create the Cortex service principal.

  • Required at tenant or management group scope only: the Base capability, which grants the remediation role and cross-subscription managed identities. It is not requested at subscription scope.

  • Conditional on selected capabilities: requested only when the corresponding capability is enabled. Capabilities can be added or removed later, and the requested permissions adjust accordingly.

The following reference tables are organized by security module, role, and then the list of the CSP permissions being requested as well as their purpose: