Azure Cloud Account Onboarding
Learn about Azure cloud account onboarding prerequisites and the onboarding
workflow in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS AI Runtime Security in
Azure
|
|
Onboarding your Azure cloud account connects it to Strata Cloud Manager so Prisma® AIRS™
can discover and protect your AI workloads. Without onboarding, Prisma AIRS cannot
see your cloud resources or intercept AI traffic flowing through virtual machines,
containers, or Azure OpenAI services in your Azure environment.
The onboarding process uses a Terraform template you download from
Strata Cloud Manager
to create a service account in your Azure tenant. The service account grants Prisma
AIRS the permissions it needs to read virtual network flow logs, enumerate assets such
as AKS clusters, virtual machines, and Azure OpenAI resources, and—if you choose—
orchestrate security VNETs and redirect application traffic through the AI Runtime
firewall.
Azure Required Permissions lists the specific permissions
requested for each function you enable.
Before running the onboarding workflow in
Strata Cloud Manager, complete the
Azure Cloud Account Onboarding Prerequisites: create a storage
account for flow log and audit log storage, enable VNet flow logs and Azure OpenAI
audit logs, add Prisma AIRS IP addresses to the storage account allow list, and—if
you plan to onboard more than one subscription on the same tenant—assign the required
Azure roles.