Azure Cloud Account Onboarding
Focus
Focus
Prisma AIRS

Azure Cloud Account Onboarding

Table of Contents

Azure Cloud Account Onboarding

Learn about Azure cloud account onboarding prerequisites and the onboarding workflow in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Prisma AIRS AI Runtime Security in Azure
Onboarding your Azure cloud account connects it to Strata Cloud Manager so Prisma® AIRS™ can discover and protect your AI workloads. Without onboarding, Prisma AIRS cannot see your cloud resources or intercept AI traffic flowing through virtual machines, containers, or Azure OpenAI services in your Azure environment.
The onboarding process uses a Terraform template you download from Strata Cloud Manager to create a service account in your Azure tenant. The service account grants Prisma AIRS the permissions it needs to read virtual network flow logs, enumerate assets such as AKS clusters, virtual machines, and Azure OpenAI resources, and—if you choose— orchestrate security VNETs and redirect application traffic through the AI Runtime firewall. Azure Required Permissions lists the specific permissions requested for each function you enable.
Before running the onboarding workflow in Strata Cloud Manager, complete the Azure Cloud Account Onboarding Prerequisites: create a storage account for flow log and audit log storage, enable VNet flow logs and Azure OpenAI audit logs, add Prisma AIRS IP addresses to the storage account allow list, and—if you plan to onboard more than one subscription on the same tenant—assign the required Azure roles.
After completing the prerequisites, use Onboard Azure Cloud Account in Strata Cloud Manager to select permission scopes, define application boundaries for asset grouping, download and apply the Terraform template in Azure, and validate asset discovery.