Azure · Guided onboarding

Connect Transilienceto your Azure environment

Azure onboarding splits cleanly into two tracks: one for subscription-level posture and one for logs, Entra, and Microsoft security telemetry. This page turns the raw support steps into a guided handoff your cloud or identity admin can actually follow.

Why this page exists

  • Two guided Azure tracks: subscription posture and logs / Entra telemetry
  • Built for compliance teams that need clean handoff steps, not raw support docs
  • Use one app registration, then layer only the roles and Graph permissions you need
How It Works

One app, two Azure access tracks

The cleanest rollout is to create one Azure app registration, then layer the exact subscription roles and Graph permissions you need.

01

Choose the Azure track

Start with Subscription Access for resource posture, then add Logs & Entra Access if you want identity, Defender, Intune, or audit-log visibility.

02

Create or reuse one Azure app

Both tracks assume the same Azure app registration. Subscription Access establishes the app and secret; Logs & Entra adds API permissions and admin consent.

03

Send the final identifiers

Once access is assigned, share the requested IDs and secret details with Transilience so the environment can be connected without back-and-forth.

Azure Access

Pick the Azure access track you need

Most managed compliance deployments need both tracks: subscription access for resource posture and logs / Entra access for identity and telemetry review.

Need both?

Start with Subscription Access to establish the app and subscription visibility. Then add Logs & Entra Access when you want Entra, Defender, Intune, audit logs, or Conditional Access evidence included in the review.

One app registration · two permission layers

Subscription Access

Resource posture and subscription configuration

Use this track to let Transilience inspect Azure subscriptions, resource posture, and configuration state for managed compliance reviews.

Best for: Teams starting Azure onboarding or reviewing subscription-level posture, CIS alignment, and resource configuration.

What this grants

  • App registration and secret for backend access
  • Reader assignment on each in-scope subscription
  • Reader and Data Access for resource inspection
  • Optional Sentinel Reader + Log Analytics Reader

Before you start

  • Azure administrator who can create app registrations
  • Ability to assign roles on every Azure subscription you want reviewed
  • A secure path to share client and tenant details with your Transilience contact
01

Create the app registration and generate a secret

Create a dedicated Azure app registration for Transilience, then open Certificates & secrets and generate a new client secret.

  • Use one shared app registration for both subscription and logs onboarding
  • Copy the Application (client) ID, secret value, and secret ID immediately
  • Keep the app name recognizable so it is easy to find during role assignment
Show screenshots for this step
Azure App registrations page
Open Microsoft Entra ID and start from App registrations.
Azure client secret creation view
Generate a client secret under Certificates & secrets and copy the value immediately.
02

Assign the app to every target subscription

Go to each Azure subscription you want Transilience to assess, open IAM, and create a role assignment for the app registration.

  • Repeat this on every subscription in scope
  • Use Select members to choose the app registration you just created
  • This is the step that usually requires User Administrator or equivalent rights
If you skip a subscription here, Transilience will not be able to audit or inventory resources in that subscription.
Show screenshots for this step
Azure subscription IAM page
Assign the app at the subscription scope so Transilience can read posture and configuration data.
Azure select members dialog for app assignment
Search for the app registration you created and add it as the member on the role assignment.
03

Apply Reader and Reader and Data Access

Assign the app the roles needed to inspect configuration safely without making changes.

  • Reader is the baseline role for configuration and posture review
  • Reader and Data Access adds the resource/data visibility the Freshdesk guide calls out
  • Treat these as the default baseline for managed compliance onboarding
Show screenshots for this step
Azure reader and data access permissions screenshot
Apply Reader and Reader and Data Access so configuration and resource state can be inspected.
04

Add Sentinel roles only if your logs live there

If Microsoft Sentinel is part of your logging stack, add Sentinel Reader and Log Analytics Reader so Transilience can inspect that telemetry path too.

  • Do this only when Sentinel is actually in use
  • It complements, but does not replace, the separate Logs & Entra track
Subscription access handles resource posture. Logs & Entra access is still needed for Microsoft Graph permissions and Entra/Defender review.
Show screenshots for this step
Azure Sentinel roles screenshot
If your security telemetry lives in Microsoft Sentinel, also add Sentinel Reader and Log Analytics Reader.
05

Capture tenant and subscription identifiers

Before handoff, record the tenant ID and every subscription ID that should be connected to Transilience.

  • Subscription ID comes from the Subscriptions page
  • Tenant ID comes from the Entra tenant properties view
Show screenshots for this step
Azure subscription ID screenshot
Capture each subscription ID you want Transilience to review.
Azure tenant ID screenshot
Capture the tenant ID from the Entra tenant properties page for the same app registration.

What to send Transilience

Once this track is complete, hand off the following details to your account manager or forward deployed engineer.

  • Application (client) ID
  • Client secret value
  • Client secret ID
  • Tenant ID
  • All in-scope subscription IDs
FAQ

Common Azure onboarding questions

  • Do we need both Subscription Access and Logs & Entra Access?
    Usually yes. Subscription Access covers resource posture and configuration state. Logs & Entra Access covers identity, audit, Defender, Intune, and related telemetry. Together they give Transilience complete compliance coverage.
  • Do we need to repeat the role assignment on every subscription?
    Yes. The support flow explicitly assigns the app on each subscription in scope. If one subscription is missed, Transilience cannot audit resources there.
  • What if we use Microsoft Sentinel?
    Add Sentinel Reader and Log Analytics Reader in the subscription flow when Sentinel stores the security telemetry you want Transilience to inspect.
  • When do we add MFA and Conditional Access permissions?
    Only when you want Transilience to review Entra MFA enforcement or Conditional Access rule configuration. Those scopes are optional and can be added later.
  • What exact values should we send after setup?
    At minimum: client ID, tenant ID, and the app secret details. For subscription onboarding, also share all in-scope subscription IDs. For logs onboarding, confirm admin consent and whether MFA / Conditional Access visibility was included.

Blocked on Entra permissions, tenant roles, or admin consent?

We can walk your Azure or identity admin through the exact roles, Graph scopes, and final handoff details in a short working session.