# AQUILA CSPM - Azure Integration

<span style="color: rgb(0, 0, 0);">This manual explains how to get started monitoring the security posture of your Azure CSP using the Cloud Security Posture Management (CSPM) feature.</span>

#### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

<div class="ulist itemizedlist" id="bkmrk-cspm-only-works-in-t">- <span style="color: rgb(0, 0, 0);">The user who gives the CSPM integration permissions in Azure must be an Azure subscription **admin**.</span>

</div>#### <span style="color: rgb(53, 152, 219);">**Setup**</span>

<span style="color: rgb(53, 152, 219);">**Service principal with client secret** </span>

<span style="color: rgb(0, 0, 0);">Before using this method, you must have set up a **Microsoft Entra application** and **service principal that can access resources**. Please go **<span style="color: rgb(53, 152, 219);">[here](https://learn.microsoft.com/en-us/entra/identity-platform/howto-create-service-principal-portal#get-tenant-and-app-id-values-for-signing-in)</span>** before following the steps below.</span>

<div class="olist orderedlist" id="bkmrk-on-the%C2%A0add-cloud-sec">1. <span style="color: rgb(0, 0, 0);">The following information is required.</span>
    1. <span style="color: rgb(0, 0, 0);">Directory **(tenant) ID** and **Application (client) ID**</span>
        - <span style="color: rgb(0, 0, 0);">To get these values:</span>
            - <span style="color: rgb(0, 0, 0);">Go to the <span class="strong strong">**Registered apps**</span> section of Microsoft Entra ID.</span>
            - <span style="color: rgb(0, 0, 0);">Click on <span class="strong strong">**New Registration**</span>, name your app and click <span class="strong strong">**Register**</span>.</span>
            - <span style="color: rgb(0, 0, 0);">Copy your new app’s **Directory (tenant) ID** and **Application (client) ID**. </span>
    2. <span style="color: rgb(0, 0, 0);">**Client Secret**</span>
        - <span style="color: rgb(0, 0, 0);">In Azure portal, select <span class="strong strong">Certificates &amp; secrets</span>, then go to the <span class="strong strong">Client secrets</span> tab. Click <span class="strong strong">New client secret</span>.</span>
        - <span style="color: rgb(0, 0, 0);">Copy the new secret **"Value"**.</span>
2. <span style="color: rgb(0, 0, 0);">Return to Azure. Go to your Azure subscription list and select the subscription or management group you want to monitor with CSPM.</span>
3. <span style="color: rgb(0, 0, 0);">Go to <span class="strong strong">**Access control (IAM)**</span> and select <span class="strong strong">**Add Role Assignment**</span>.</span>
4. <span style="color: rgb(0, 0, 0);">Select the **Reader** function role, assign access to <span class="strong strong">**User, group, or service principal**</span>, and select your new app.</span>

</div>#### <span style="color: rgb(53, 152, 219);">**How to integrate to AQUILA CSPM Module**</span>

##### <span style="color: rgb(53, 152, 219);">**Pre-requisites**</span>

1. <span style="color: rgb(0, 0, 0);">**Access to CyTech - AQUILA**</span>
    - <span style="color: rgb(0, 0, 0);">Only users assigned the **"Owner"** or **"Admin"** role can access the Log Collector installation resources within the platform.</span>

<p class="callout success">**To navigate to CSPM Module please follow the instructions below:**</p>

<div class="x_elementToProof" id="bkmrk-step1%3A-log-in-to-cyt">**<span style="color: rgb(0, 0, 0);">Step 1: Log in to CyTech - AQUILA. Click here --&gt;</span> [AQUILACYBER.ai](https://aquilacyber.ai/overview-v3/dashboard/maindashboard)**</div><div class="x_elementToProof" id="bkmrk-step2%3A-click-on-cybe"><span style="color: rgb(0, 0, 0);">**Step 2: Click on Cyber Monitoring.**</span></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/hItzqzN09q61CMZZ-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/hItzqzN09q61CMZZ-image.png)

<span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" style="color: rgb(0, 0, 0);" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">**Step 3: Choose Cloud Security Posture Management (CSPM).**</span></span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/EbsP1Kz74gmIWnyZ-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/EbsP1Kz74gmIWnyZ-image.png)

<span style="color: rgb(0, 0, 0);">**Step 4: Click the "Let's Go" or "Onboard CSPM" icon to launch installation window.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/h53Z6TJIUeSrsoc5-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/h53Z6TJIUeSrsoc5-image.png)

<span style="color: rgb(0, 0, 0);">**Step 5: Click "Let's go" to start the integration process.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/7DPNcbHQ3TI5nSmY-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/7DPNcbHQ3TI5nSmY-image.png)

<span style="color: rgb(0, 0, 0);">**Step 6: Choose your log collector. If you haven't installed a log collector yet choose "New Log Collector" click here --&gt;**</span> [Log Collector Installation](https://docs.cytechint.io/books/log-collector-installations). <span style="color: rgb(0, 0, 0);">**If you have already have an existing log collector choose "Current Log Collector" and click "Next".**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/YmaKgMpQPUBQOutG-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/YmaKgMpQPUBQOutG-image.png)

<span style="color: rgb(0, 0, 0);">**Step 7: Click "Next" if the requirements are met.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/9XREDs3GMrovq966-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/9XREDs3GMrovq966-image.png)

<span style="color: rgb(0, 0, 0);">**Step 8: Choose your current log collector. This will collect the logs coming from your log sources.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/6JtsLkQBByfBwsLN-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/6JtsLkQBByfBwsLN-image.png)

<span style="color: rgb(0, 0, 0);">**Step 9: Choose Azure and click "Next" to proceed.**</span>

<div class="olist orderedlist" id="bkmrk-go-to-the-azure-port"></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/emYpLrE9GwYlBYXG-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/emYpLrE9GwYlBYXG-image.png)

<span style="color: rgb(0, 0, 0);">**Step 10: Input all the required credentials from the previous Azure configurations and click "Next" to initiate the integration process. Wait for couple of minutes until a success window shows up.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/rSv3hwdVltbKSxrr-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/rSv3hwdVltbKSxrr-image.png)

<p class="callout info"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">**<span style="color: rgb(224, 62, 45);">Please refer to this manual for the full guidelines of our CSPM Module. *click here--&gt;*</span> [CyTech - AQUILA CSPM Manual ](https://docs.cytechint.io/books/log-collector-installations/page/cytech-aquila-cloud-security-posture-management-cspm-module)**</span></span></p>

 *If you need further assistance, kindly contact our support at **[support@cytechint.com](mailto:info@cytechint.com)** for prompt assistance and guidance.*