Subscription Access
Resource posture and subscription configurationUse this track to let Transilience inspect Azure subscriptions, resource posture, and configuration state for managed compliance reviews.
Best for: Teams starting Azure onboarding or reviewing subscription-level posture, CIS alignment, and resource configuration.
What this grants
- App registration and secret for backend access
- Reader assignment on each in-scope subscription
- Reader and Data Access for resource inspection
- Optional Sentinel Reader + Log Analytics Reader
Before you start
- Azure administrator who can create app registrations
- Ability to assign roles on every Azure subscription you want reviewed
- A secure path to share client and tenant details with your Transilience contact
Create the app registration and generate a secret
Create a dedicated Azure app registration for Transilience, then open Certificates & secrets and generate a new client secret.
- Use one shared app registration for both subscription and logs onboarding
- Copy the Application (client) ID, secret value, and secret ID immediately
- Keep the app name recognizable so it is easy to find during role assignment
Show screenshots for this step


Assign the app to every target subscription
Go to each Azure subscription you want Transilience to assess, open IAM, and create a role assignment for the app registration.
- Repeat this on every subscription in scope
- Use Select members to choose the app registration you just created
- This is the step that usually requires User Administrator or equivalent rights
Show screenshots for this step


Apply Reader and Reader and Data Access
Assign the app the roles needed to inspect configuration safely without making changes.
- Reader is the baseline role for configuration and posture review
- Reader and Data Access adds the resource/data visibility the Freshdesk guide calls out
- Treat these as the default baseline for managed compliance onboarding
Show screenshots for this step

Add Sentinel roles only if your logs live there
If Microsoft Sentinel is part of your logging stack, add Sentinel Reader and Log Analytics Reader so Transilience can inspect that telemetry path too.
- Do this only when Sentinel is actually in use
- It complements, but does not replace, the separate Logs & Entra track
Show screenshots for this step

Capture tenant and subscription identifiers
Before handoff, record the tenant ID and every subscription ID that should be connected to Transilience.
- Subscription ID comes from the Subscriptions page
- Tenant ID comes from the Entra tenant properties view
Show screenshots for this step


What to send Transilience
Once this track is complete, hand off the following details to your account manager or forward deployed engineer.
- Application (client) ID
- Client secret value
- Client secret ID
- Tenant ID
- All in-scope subscription IDs