Integration Guide

Microsoft cloud integration

TENET provides native integration with Azure & M365, delivering comprehensive visibility across your environment.

START FOR FREEREQUEST DEMO

14-day free trial · 2 min setup · No credit card required

TENET — Azure IntegrationConnected ✓
Tenants (4 connected)
Production
a1b2-****-prod
148 resources
Development
c3d4-****-dev
62 resources
Shared Services
e5f6-****-ss
34 resources
Staging
g7h8-****-stg
21 resources
Managing multiple Azure tenants?

Each Azure tenant requires a separate integration. Repeat the setup steps below for each tenant you want to connect to TENET.

Integration Setup Guide

Connect your Azure environment to TENET using the automated wizard or the manual steps below.

TENET Setup Wizard (Recommended)

The fastest way to connect TENET to your Azure environment is with the TENET Setup Wizard. It guides you through the entire process automatically — creating the app registration, configuring API permissions, and assigning the required roles — in just a few clicks. Watch the video below to see how it works.

Manual Setup

Follow these steps to manually configure the Azure app registration and permissions required by TENET.

Step 1: Creating an app registration in the Azure Portal

A. Log into your Azure Portal
B. Search for App Registrations in the top search bar.
Search for App registrations in Azure Portal
C. Click on + New registration
Click New registration button in Azure Portal
D. Fill in the details:
  • Name: TENET
  • Redirect URI: Select a platform: Single-page application (SPA)
  • URL: https://tenet-portal.com
  • Click Register
Fill in app registration details - Name: TENET, Redirect URI: Single-page application

Step 2: Configure API Permissions

A. In the top toolbar, search for TENET (or the name you used for the app registration)
Copy Application (client) ID and Directory (tenant) ID from Azure Portal
B. Navigate to Manage → API permissions
Navigate to API permissions menu
C. Select + Add a permission → Microsoft Graph → Application permissions.
Add Microsoft Graph permissions

Ensure you select Application Permissions, not Delegated. This is required for the integration to work correctly.

D. Search for and select AuditLog.Read.All, Directory.Read.All, Reports.Read.All, SecurityEvents.Read.All, SecurityIncident.Read.All, Sites.Read.All, DeviceManagementManagedDevices.Read.All, ThreatHunting.Read.All, ServiceHealth.Read.All, MailboxSettings.Read, and AgentIdentity.Read.All

  • Click add permissions
Add Microsoft Graph permissions
E. Grant admin consent
  • Then click on Grant admin consent for [Your Tenant] and confirm selection
Grant admin consent for permissions
F. Ensure all permissions have a green check in the Status column.
Permissions status with green checkmarks
G. Add Office 365 Management Activity API permission
  • Click + Add a permission → APIs my organization uses
  • Search for Office 365 Management Activity API and select it
  • Select Application permissionsActivityFeed.Read
  • Click Add permissions, then Grant admin consent
H. Add Microsoft Defender for Endpoint API permissions
  • Click + Add a permission → APIs my organization uses
  • Search for WindowsDefenderATP and select it
  • Select Application permissions: Machine.Read.All, Vulnerability.Read.All, Alert.Read.All
  • Click Add permissions, then Grant admin consent

These permissions are non-fatal if your tenant has no Microsoft Defender for Endpoint licence. TENET will skip Defender data for unlicensed tenants.

I. Add Application Insights API permission
  • Click + Add a permission → APIs my organization uses
  • Search for Application Insights API and select it
  • Select Delegated permissionsData.Read
  • Click Add permissions, then Grant admin consent (tenant-wide)

Step 3: Assign RBAC roles

The following steps grant TENET read access to all subscriptions within the management group. To limit access to specific subscriptions only, follow the same steps but search for individual subscription names instead of Management Groups.

A. In the top toolbar, search for Management Groups
Navigate to subscription IAM
B. Select your root management group (usually Tenant Root Group).
Navigate to subscription IAM

Global Administrator but can't access Management Groups? Follow Microsoft's guide to elevate your access.

C. Click on Access control (IAM) → Role assignments
Navigate to subscription IAM
D. Select Reader role.

Repeat this step three more times to also assign Cognitive Services Usages Reader, Monitoring Reader, and Security Reader. All four roles are required.

Add role assignment
  • Click on the Members tab, and then + Select members.
Click Members tab and Select members
  • In the + Select Members panel, search for the name of the app registration that you created earlier, then click on it
  • Click Select at the bottom
Search for app registration in Select Members panel

All four roles (Reader, Cognitive Services Usages Reader, Monitoring Reader, Security Reader) are required. If not using management groups, ensure each role is assigned per individual subscription.

E. Once all permissions have been added, click Review + assign (twice) to complete
Review and assign role
F. Assign the Global Reader directory role in Microsoft Entra ID
  • Navigate to the Microsoft Entra admin center
  • Go to Roles & administrators → Global Reader
  • Click + Add assignments, search for your TENET app registration, and assign

Global Reader grants read access to Conditional Access policies, Identity Protection, and Intune device compliance — scoped to Entra ID rather than Azure subscriptions.

Step 4: Create Client Secret

A. Return to App registrations and open your registered app

Please take note of the Application (client) ID and Directory (tenant) ID from this page. You will need to copy these across to the TENET Platform later.

Application overview showing Client ID and Tenant ID
B. Navigate to Manage → Certificates & secrets → Client secrets
Navigate to Certificates & secrets
C. Click + New client secret, provide a name and expiry, and then click Add
Copy the client secret value
D. Please take note of the Value of the secret - this is the final data point you will need to copy across to the TENET Platform.
Copy the client secret value

Step 5: Add Credentials to TENET

A. Log in to TENET and navigate to Settings (tenet-portal.com/settings)

Enter a friendly Tenant Name and previously noted Tenant ID, Client ID & Client Secret then click on Start Assessment

TENET settings page - Azure Credentials

Wait for validation and initial data fetch to complete and you can start reviewing TENET's insights.

You're done! 🎉

Managing and Monitoring Assessments

Once connected, TENET continuously monitors your Azure environment. Here's what to expect.

Automatic assessments

Full assessments run every 12 hours. Anomaly detection refreshes every hour. A manual refresh is also available in the Directories tab.

Permission errors

If missing permissions or invalid credentials are detected, TENET surfaces error messages in the platform. Adjust your Azure role assignments accordingly.

Plan Limits

Azure integration is available on all plans. The number of tenants you can connect depends on your plan.

TRIAL — 14 DAYS

Full access to all Scale plan features. Explore every capability with no restrictions during your trial.

SCALE PLAN

Automated and on-demand assessments for a single Azure tenant with up to 5 platform users.

PRO PLAN

Automated and on-demand assessments for multiple tenants simultaneously with a custom number of users.

Integrations

Microsoft and third-party integrations

No agents or deployments required with out of the box integrations.

Compute
Virtual Machines
Virtual Machines

Surface risk exposure across VM configuration, patching, and access

VM Scale Sets
VM Scale Sets

Monitor scale set configurations for drift and exposure risk

Managed Disks
Managed Disks

Flag unencrypted or exposed managed disks across subscriptions

App Platform
App Service (Web Apps)
App Service (Web Apps)

Assess web app configurations for public exposure and misconfigurations

Function Apps
Function Apps

Monitor serverless functions for insecure triggers and access risk

App Service Plans
App Service Plans

Track App Service Plan configuration and exposure risk

Static Web Apps
Static Web Apps

Surface exposure risk across static web app deployments

Container Apps
Container Apps

Monitor container app environments for misconfiguration and exposure

AKS Managed Clusters
AKS Managed Clusters

Assess AKS cluster configuration and access risk

Data & Storage
Storage Accounts
Storage Accounts

Flag public access, weak encryption, and exposed storage accounts

SQL Databases
SQL Databases

Surface misconfigurations and exposure risk across SQL databases

Cosmos DB / DocumentDB
Cosmos DB / DocumentDB

Monitor Cosmos DB access and network configuration risk

Cosmos DB for MongoDB
Cosmos DB for MongoDB

Assess Cosmos DB for MongoDB access and exposure risk

PostgreSQL Servers
PostgreSQL Servers

Flag public access and weak configurations on PostgreSQL servers

MySQL Servers
MySQL Servers

Flag public access and weak configurations on MySQL servers

Redis Cache
Redis Cache

Monitor Redis Cache instances for exposure and access risk

Redis Enterprise
Redis Enterprise

Monitor Redis Enterprise instances for exposure and access risk

Networking
Application Gateway
Application Gateway

Surface misconfigured rules and exposure on Application Gateways

Load Balancer
Load Balancer

Monitor Load Balancer rules for unintended public exposure

Virtual Network Gateway
Virtual Network Gateway

Assess VPN and ExpressRoute gateway configuration risk

Front Door / CDN
Front Door / CDN

Flag exposure risk across Front Door and CDN profiles

NAT Gateway
NAT Gateway

Monitor NAT Gateway configuration for outbound exposure risk

API Management
API Management

Surface exposed APIs and weak policies in API Management

Integration & Security
Service Bus
Service Bus

Monitor Service Bus namespaces for access and network risk

Event Hubs
Event Hubs

Flag exposure and access risk across Event Hubs namespaces

Key Vault
Key Vault

Surface overly permissive access policies on Key Vaults

Recovery Services Vaults
Recovery Services Vaults

Track backup coverage and configuration risk on Recovery Vaults

Entra ID
Entra ID

Surface identity risk across users, roles, and conditional access

Security & Monitoring
Microsoft Defender for Cloud
Microsoft Defender for Cloud

Ingest Defender for Cloud findings into a unified risk view

Microsoft Sentinel
Microsoft Sentinel

Correlate Sentinel alerts with TENET's broader risk posture

Application Insights
Application Insights

Pull Application Insights telemetry to surface operational risk

Azure Monitor
Azure Monitor

Ingest Azure Monitor metrics to flag anomalies and risk

Activity Logs
Activity Logs

Analyze Activity Logs to detect risky configuration changes

Resource Health
Resource Health

Track resource health signals alongside risk posture

Azure Policy
Azure Policy

Surface policy compliance gaps as risk exposure

Network Security Groups
Network Security Groups

Flag overly permissive NSG rules across your environment

Azure RBAC
Azure RBAC

Surface excessive permissions and role assignment risk

Log Analytics Workspaces
Log Analytics Workspaces

Query Log Analytics data to detect risk signals

AI & Machine Learning
Azure OpenAI
Azure OpenAI

Monitor Azure OpenAI deployments for access and data risk

Cognitive Services
Cognitive Services

Surface exposure risk across Cognitive Services resources

Azure AI Search
Azure AI Search

Flag misconfigured access on Azure AI Search services

Azure Bot Service
Azure Bot Service

Monitor Bot Service configurations for exposure risk

Azure Machine Learning
Azure Machine Learning

Assess ML workspace access and data exposure risk

AI Foundry
AI Foundry

Surface risk across AI Foundry projects and deployments

Microsoft 365
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint

Ingest device threat signals to surface endpoint risk

Microsoft Intune
Microsoft Intune

Flag non-compliant and unmanaged devices as risk exposure

SharePoint Online
SharePoint Online

Surface oversharing and permission risk across SharePoint sites

OneDrive for Business
OneDrive for Business

Flag external sharing risk across OneDrive accounts

Exchange Online
Exchange Online

Surface mailbox rule abuse and forwarding risk

Microsoft Teams (Alerts)
Microsoft Teams (Alerts)

Send TENET risk alerts directly to your Teams channels

Microsoft 365 Licenses
Microsoft 365 Licenses

Track license usage and unused seats as cost risk

Alerting & Ticketing
Jira
Jira

Open and track TENET findings as tickets in Jira

HaloPSA
HaloPSA

Push TENET risk alerts directly into HaloPSA tickets

Featured Resources

Want to learn more?
Dig into more resources.

Ready to integrate your Azure environment?

Get up and running in minutes with TENET's native Azure integration

FREE ASSESSMENTREQUEST DEMO

14-day free trial · 2 min setup · No credit card required