Onboard Microsoft Azure - Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure. - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Follow the Azure onboarding wizard, and Cortex creates a custom authentication template to be executed in Azure.

Use the cloud onboarding wizard to integrate a Microsoft Azure environment with Cortex Cloud. The onboarding wizard requires minimal configuration to set up the integration. To complete the minimum configuration, define the scope of the Microsoft Azure accounts and specify the scan mode. Alternatively, configure the advanced settings for full control of the onboarding process.

Cortex Cloud generates a Terraform or ARM authentication template based on the configuration settings. The authentication template establishes trust with Microsoft Azure. The authentication template also grants required permissions to Cortex Cloud. Execute the authentication template in Microsoft Azure to complete the onboarding process. Executing the authentication template notifies Cortex Cloud of the execution details. Cortex Cloud then creates a new cloud instance.

Onboard Microsoft Entra ID only

You can onboard Microsoft Entra ID independently of a full tenant-level onboarding. When you select the Onboard Microsoft Entra ID only only option during onboarding with Tenant scope, Cortex Cloud connects to Entra ID to unlock identity-based capabilities, including Cloud Infrastructure Entitlement Management (CIEM), identity posture assessment, and Entra ID sign-in log ingestion. This approach enables identity visibility without requiring Cortex Cloud to scan or manage the broader Azure tenant environment.

When you onboard Entra ID only, Cortex Cloud operates in collection-only mode. Scan mode selection and scope modification are not available for this configuration. Both Terraform and ARM authentication templates are supported, and manual onboarding is also available. Cortex Cloud generates the appropriate authentication template based on your selection, and you execute it in Microsoft Azure to complete the onboarding process.

If you enable audit log collection with Entra ID-only onboarding using automated collection, Cortex Cloud ingests sign-in and activity log categories including: SignInLogs, AuditLogs, NonInteractiveUserSignInLogs, ServicePrincipalSignInLogs, ManagedIdentitySignInLogs, ProvisioningLogs, ADFSSignInLogs, and MicrosoftGraphActivityLogs. Administrative category logs are excluded from automated collection. If you configure custom diagnostic settings, log ingestion follows your specified configuration.

You can later expand an Entra ID-only configuration to full tenant scope by editing the onboarding configuration. This allows you to begin with identity-focused onboarding and transition to comprehensive tenant coverage as requirements evolve.