This section describes how to download an onboarding Terraform template when
using AI Agent Discovery. When you apply this template in your cloud
environment, it generates a service account with sufficient permissions. These
permissions enable AI Agent Discovery within your cloud environment, granting
access to network flow logs, asset inventory details, and other essential cloud
resources.
When you onboard an Azure cloud account, consider the following:
- For new accounts, you'll need to onboard a cloud account if one is not
present in the tenant.
- For existing accounts in an enabled state, you need to re-apply the
Terraform to provide AI Agent Discovery access for existing onboarded
accounts. This process updates the inline discovery permissions. To re-apply
the onboarding Terraform, refer to Step 12 (Download
Terraform) above:
- For existing accounts in a disabled state (that is, cloud accounts
that are disabled), attempts to re-enable the account results in failed
validation. To resolve this issue, download the onboarding Terraform before
enabling the account again.