One registration, two levels
Tenant and subscriptions use the same app registration; the subscription only needs the Reader role.
Check subscriptions for misconfigurations
The connector reads an Azure subscription via the ARM API and checks the configuration of the resources within. It uses the same app registration as Entra ID, plus the Reader role on the subscription. Context factors such as internet-exposed, privileged or unencrypted automatically raise the severity of affected findings.
Vendor: Microsoft · learn.microsoft.com/rest/api/azure
Tenant and subscriptions use the same app registration; the subscription only needs the Reader role.
Individual findings are not dramatised. Instead severity rises when context factors combine.
We show you the connector live in your own environment – non-binding and free of charge.