# NG SIEM - Azure CSPM Integration

<span style="color: rgb(0, 0, 0);">This manual explains how to get started monitoring the security posture of your Azure CSP using the Cloud Security Posture Management (CSPM) feature.</span>

#### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

<div class="ulist itemizedlist" id="bkmrk-cspm-only-works-in-t">- <span style="color: rgb(0, 0, 0);">The user who gives the CSPM integration permissions in Azure must be an Azure subscription **admin**.</span>

</div>#### <span style="color: rgb(53, 152, 219);">**Setup**</span>

<span style="color: rgb(0, 0, 0);">**Service principal with client secret** </span>

<span style="color: rgb(0, 0, 0);">Before using this method, you must have set up a **Microsoft Entra application** and **service principal that can access resources**. Please go **<span style="color: rgb(132, 63, 161);">[here](https://learn.microsoft.com/en-us/entra/identity-platform/howto-create-service-principal-portal#get-tenant-and-app-id-values-for-signing-in)</span>** before following the steps below.</span>

<div class="olist orderedlist" id="bkmrk-on-the%C2%A0add-cloud-sec">1. <span style="color: rgb(0, 0, 0);">The following information is required.</span>
    1. <span style="color: rgb(0, 0, 0);">Directory **(tenant) ID** and **Application (client) ID**</span>
        - <span style="color: rgb(0, 0, 0);">To get these values:</span>
            - <span style="color: rgb(0, 0, 0);">Go to the <span class="strong strong">**Registered apps**</span> section of Microsoft Entra ID.</span>
            - <span style="color: rgb(0, 0, 0);">Click on <span class="strong strong">**New Registration**</span>, name your app and click <span class="strong strong">**Register**</span>.</span>
            - <span style="color: rgb(0, 0, 0);">Copy your new app’s **Directory (tenant) ID** and **Application (client) ID**. </span>
    2. <span style="color: rgb(0, 0, 0);">**Client Secret**</span>
        - <span style="color: rgb(0, 0, 0);">In Azure portal, select <span class="strong strong">Certificates &amp; secrets</span>, then go to the <span class="strong strong">Client secrets</span> tab. Click <span class="strong strong">New client secret</span>.</span>
        - <span style="color: rgb(0, 0, 0);">Copy the new secret.</span>
2. <span style="color: rgb(0, 0, 0);">Return to Azure. Go to your Azure subscription list and select the subscription or management group you want to monitor with CSPM.</span>
3. <span style="color: rgb(0, 0, 0);">Go to <span class="strong strong">**Access control (IAM)**</span> and select <span class="strong strong">**Add Role Assignment**</span>.</span>
4. <span style="color: rgb(0, 0, 0);">Select the **Reader** function role, assign access to <span class="strong strong">**User, group, or service principal**</span>, and select your new app.</span>

</div><p class="callout warning">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Please saved and provide this values to AQUILA Support Team.</span></span>**</p>

1. <span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Directory (tenant) ID</span></span>**</span>
2. <span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Application (client) ID</span></span>**</span>
3. <div aria-label="Client Secret" class="euiFlexItem css-kpsrin-euiFlexItem-growZero"><span style="color: rgb(0, 0, 0);">**Client Secret Value:**</span></div>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>