Review the permissions required to deploy resources and the permissions granted when
connecting Azure subscriptions to TrendAI Vision One™.
The following permissions are required to be able to successfully deploy TrendAI Vision One™ cloud security resources to your Azure subscription.
NoteThe permissions listed here are required for single Azure subscriptions. If you are
deploying an Azure Management Group, see Azure management group required permissions.
|
-
For Microsoft Entra ID users, your sign in must have the following roles:
-
Application Administrator
-
Privileged Role Administrator
-
-
For Microsoft Azure users, your sign in must have the following or higher role on the subscription you are connecting:
-
User Access Administrator
-
Contributor
-
-
To enable Microsoft Defender for Endpoint Collection or Azure Activity logs, your Microsoft Azure sign in must have the following role:
- Key Vault Secrets Officer
The Terraform process assigns certain permissions to itself to establish the connection
with Cloud Accounts and TrendAI Vision One™ cloud security services. These permissions include enabling the Cloud Accounts app
and security services to obtain temporary credentials and complete tasks within your
Azure cloud environment.
Select a feature to view its required permissions:
Core features
|
Permission type
|
Required permissions
|
|
Azure Resource Manager (ARM) permissions
|
|
|
API permissions
|
|
Server & Workload Protection
|
Permission category
|
Required permissions
|
|
Subscription permissions
|
|
|
Virtual Machine (VM) permissions
|
|
|
Virtual Machine Scale Set (VMSS) permissions
|
|
|
Classic Virtual Machine (VM) permissions
|
|
|
Network permissions
|
|
|
Azure Metadata API permissions
|
|
|
Authentication and IAM permissions
|
|
Cloud Security Posture
|
Permission category
|
Required permissions
|
|
requiredResourceAccess
|
|
|
requiredRoleAccess
|
|
|
requiredTenantScopeRoleAccess
|
|
Agentless Vulnerability & Threat Detection
|
Permission category
|
Required permissions
|
|
Azure Resource Manager (ARM) permissions
|
|
|
TrendAI™ Resource Group permissions
|
Azure built-in role: Contributor
Azure built-in role: AcrPull
Azure built-in role: Storage Blob Data Owner
|
|
TrendAI™ Storage ID permissions
|
Azure built-in role: Storage Blob Data Reader
|
Data Security Posture
|
Permission type
|
Required permissions
|
|
Azure Resource Manager (ARM) permissions
|
|
File Storage Security
|
Permission type
|
Required permissions
|
|
Azure Resource Manager (ARM) permissions
|
|
|
Data actions
|
|
Cloud Detections for Azure Activity Log
|
Permission type
|
Required permissions
|
|
No required permissions.
|
|
Microsoft Defender for Endpoint Log Collection
|
Permission type
|
Required permissions
|
|
Azure Resource Manager (ARM) permissions
|
|
