Security Lifecycle Review (SLR) for Azure Overview
Focus
Focus
Prisma AIRS

Security Lifecycle Review (SLR) for Azure Overview

Table of Contents

Security Lifecycle Review (SLR) for Azure Overview

This page walks you through the steps to deploy Security Lifecycle Review (SLR) in your cloud environment using the deployment workflow in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Prisma AIRS AI Runtime Security Risk Assessment in Azure
The Security Lifecycle Review (SLR) report gives you a comprehensive view of application workloads, traffic flows, and threats detected across your Azure cloud infrastructure:
EnhancementDetails
Multi-cloud threat coverageSLR covers AWS and Azure — previously only AWS packet mirror mode was supported.
Inline and monitor-mode supportReports include data from AI Runtime firewalls deployed inline or in monitor mode.
VM-Series inline supportVM-Series firewalls deployed inline are included in the report.
Multi-account report structureReports are broken down per cloud and per account for customers with multiple accounts.
Threats blocked vs. detectedInline firewalls exporting logs to Strata Logging Service (SLS) now distinguish between blocked and detected threats.
Protected vs. monitored trafficTraffic inspected by inline firewalls is labeled Protected instead of Monitored.
When viewing SLR reports for Azure, consider the following:
  • Supported regions. East US, East US 2, West US, West US 2, Central US, North Central US, South Central US, West Central US, Canada Central, Canada East, UK South, North Europe, West Europe
  • Supported VM types:
    • D-series only — Dsv3, Dsv4, Dsv5
    • B-series is notsupported
  • Post-deployment VM restart required:
    • All app VMs must be restarted after FW deployment for VTAP activation
    • Allow ~5 minutes after restart for traffic mirroring to begin
  • Dual-NIC VMs:
    • Default route must point to the dataplane (dp) subnet gateway
    • Single-NIC VMs require no route change
  • Throughput: ~1 Gbps per VTAP
  • Deployment Modes:
    • Dedicated (Per App VNet)— single-phase deployment, FW + VTAP deployed together inside the app VNet
    • Centralized— two-phase deployment (security project first, then application project); destroy in reverse order
  • Known Limitations:
    • No cross-region mirroring
    • 13 VTAP-supported regions only (listed above)
  1. Log in to the Hub and launch Strata Cloud Manager.
  2. Onboard and Activate a Cloud Account in Strata Cloud Manager.
    When you apply the onboarding Terraform in your cloud environment, it generates a service account with the necessary permissions to enable cloud asset discovery. The discovery identifies both applications and ENIs. The ENIs are used to send traffic to the SLR.
    You can onboard multiple projects or VPCs.
  3. Download SLR reports to assess and identify potential threats.
  4. View the threat logs and AI security logs generated by SLR in the log viewer.
  5. After you assess the threats, deploy Prisma AIRS AI Runtime: Network intercept to secure your cloud assets.