1.0 Introduction
This article describes how to configure or onboard the Azure connection to Fortanix Key Insight to scan your keys and services.
2.0 Terminology Reference
For Azure connection concepts and supported features, refer to Azure Connection Concepts.
3.0 Start the Connection Setup
Before configuring an Azure connection, ensure you can access Fortanix Key Insight.
For information about signing up for Fortanix Armor, creating an Armor account, and accessing Fortanix Key Insight, refer to Getting Started with Key Insight.
You can start the connection setup when you first access Fortanix Key Insight or after you have entered the application.
First-time users: When you access Fortanix Key Insight for the first time, the connection setup wizard is displayed automatically. Proceed to Section 5: Select Cloud Provider to select Azure and configure the connection.
Existing users: In Fortanix Key Insight, go to Configuration → Connections → CLOUD → ADD CLOUD CONNECTION. Proceed to Section 5: Select Cloud Provider to select Azure and configure the connection.
4.0 Prerequisites
The following are the prerequisites before configuring an Azure cloud connection on Fortanix Key Insight:
4.1 Set Up Azure Permissions
Before onboarding the Azure cloud,
Follow the steps described in Azure Connection Scanning Configuration Using Custom Roles to set up your Azure permissions using custom roles.
Follow the steps described in Azure Connection Scanning Configuration Using Built-In Roles to set up your Azure permissions using built-in roles.
4.2 IP Whitelisting Requirements in Azure
To enable secure and reliable communication between Fortanix Key Insight and your Azure cloud environment, certain network connections may need to be allowed.
If IP whitelisting is required, retrieve the current Fortanix IP ranges from the Fortanix SaaS IP Ranges endpoint and allow the applicable IP ranges in your firewall or network infrastructure.
For information about Fortanix SaaS IP ranges and how to determine the applicable IP addresses based on traffic direction, region, and service, refer to Fortanix SaaS IP Whitelisting.
IP whitelisting is not mandatory. It is required only if there are network restrictions on your Azure accounts for inbound traffic.
5.0 Select Cloud Provider
Perform the following steps to select the scan type, connection type, and Azure cloud provider:
On the Select Connection Type step, select Automated Scan as the scan type.
Under Select connection type, select Cloud Connections. Under Select cloud provider, select Azure.
Click NEXT.

Figure 1: Select Azure cloud provider
6.0 Set Up Authentication
Azure supports the secret-based and federated authentication methods to control how users and applications obtain credentials to access Azure services.
6.1 Configure Secret-based Authentication
An authentication method in which an application stores long-lived Azure credentials (Client ID, Client Secret, and Tenant ID) and uses them directly to sign Azure API requests.
Perform the following steps to add a secret-based Azure authentication:
On the Set Up Authentication step, select the Secret based authentication.
Client ID: Enter the Client ID of your IdP.
Client secret: Enter the Client secret of your IdP.
Tenant ID: Enter the Tenant ID of your IdP.
For detailed steps on obtaining the secret-based authentication credentials, refer to Azure Connection Scanning Configuration Using Custom Roles.
Click NEXT.

Figure 2: Select Azure secret-based authentication
6.2 Configure Federated Authentication - Authorization Code Flow
An authentication method where users or applications access Azure resources using existing credentials from an external identity provider (IdP), such as PingOne or Microsoft Entra ID. This eliminates the need to store long-lived secrets.
Azure commonly uses the following OAuth flow in federated authentication scenarios:
Authorization code flow: Used when a user is involved. The user authenticates with the IdP, the application receives an authorization code, and the code is exchanged for tokens (ID, access, and/or refresh tokens).
Fortanix Key Insight supports configuring Azure connections using the Authorization code flow with PingOne and Microsoft Entra ID as the identity providers (IdPs).
For more information on how to configure the IdPs and obtain the credentials (Client ID, Well-known URL, and Scopes), refer to the following:
Azure Configuration For Microsoft Entra ID as OpenID Connect Identity Provider
Azure Configuration For PingOne as OpenID Connect Identity Provider
NOTE
Fortanix Key Insight recommends creating a dedicated user account in the respective IdP for Azure federated authentication. This account is used to authenticate with the IdP or authorization server and to grant the necessary authorization consent during the connection setup.
The dedicated user account must remain active, and any modifications to the account will require re-authorization to update and refresh the authentication configuration.
Perform the following steps to add an IdP configuration using the Authorized Code flow:
On the Set Up Authentication step, select Federated authentication.
Azure application client ID: Enter the Azure application ID.
Tenant ID: Enter the Azure Tenant ID.
In the Select configuration section, click ADD CONFIGURATION to add a new IdP configuration.
In the Add New Configuration dialog box, the Authorization code flow option is selected by default.
Name of configuration: Enter a name for the configuration.
Client ID: Enter the Client ID of your IdP.
Well-known URL: Enter the Well-known URL of your IdP.
Scope: Add the required scope(s). The default scopes are available to select. You can also add custom scopes if they are already configured.
NOTE
Ensure to include the
offline_accessscope when configuring a Microsoft Entra ID IdP.Click AUTHORIZE to add a new IdP. A new browser window opens for authorization, depending on the IdP. After you complete the required steps, the new IdP is added to theSelect configurationlist.

Figure 3: Add an Azure IdP
After adding and selecting the IdP configuration, click NEXT.
NOTE
You can also add an IdP using the Authorization code flow by clicking ADD CONFIGURATION in the top-right corner of the Authentication page. For more information on managing the Federated Authentication IdP configurations, refer to Federated Authentication Identity Provider Configurations.
Currently, Azure does not support configuring Federated authentication using the Client credentials flow.
7.0 Set Up Cloud Connections
Perform the following steps on the Set Up Cloud Connections step:
Azure cloud connection name: Enter the name of your Azure connection. For example, Azure Cloud.
On the Select scope section:
Management Groups: Select this option to onboard all the Azure subscriptions.
Subscription: Select this optionif you want to onboard a single subscription.
Based on the selected scope,
Management group ID: Enter the Management group ID.
or
Subscription ID: Enter the subscription ID.
For detailed steps on obtaining these IDs, refer to Azure Connection Scanning Configuration Using Custom Roles.
Click NEXT.

Figure 4: Configure Azure cloud subscription in Fortanix Key Insight
8.0 Select Azure Subscriptions
Perform the following steps to select the Azure subscriptions:
On the Select Azure Subscriptions step:
If you selected the Management Groups scope in the previous step, choose Select All Subscriptions to onboard all subscriptions in the management group, or manually select the subscriptions you want to onboard.
If you selected Subscription scope, select the single Azure subscription to scan and onboard that subscription.
Click NEXT.
NOTE
Fortanix Key Insight scans only the Azure metadata and does not access any Azure key material.

Figure 5: Select Azure subscriptions
9.0 Select Key Insight Policy
The System Defined Policy is selected by default on the Key Insight Policy step. This policy is designed to facilitate the scanning of keys and services based on predefined key sizes and permitted operations, ensuring compliance with standard security configurations.
Click NEXT to proceed.

Figure 6: Azure Key Insight policy
Additionally,
Click ADD POLICY to add a new user-defined policy to the policy center.
Click
to copy and modify a system-defined policy, converting it into a user-defined policy.
For more information on Fortanix Key Insight policies and features, refer to Cryptographic Policy Management.
NOTE
If you change or update the policy instead of theSystem Defined Policy, you mustRescanthe Azure connection to apply the new policy.
10.0 Select External Key Source
On the Select External Key Source step, you can integrate Fortanix Key Insight with an external key source such as Fortanix DSM to enable key correlation and improve key management.
Select any of the following options:
Yes, connect now: This option allows you to add the external key source for your Azure cloud connection to correlate keys using the ADD EXTERNAL KEY SOURCE feature. For more information, refer to Getting Started with External Key Source Connection. After adding the Fortanix DSM connection, select it from the list.

Figure 7: Add external key source
No, I’ll connect later: This option allows you to onboard the Azure connection without adding an external key source. You can add it later if needed.

Figure 8: Onboard Azure connection without an external key source
Click FINISH to complete the Azure connection onboarding.
NOTE
After onboarding the Azure connection:
View the Azure connection UI (Overview, Assessment, Keys, and so on). You can also switch the region using the region switcher drop down located on the top navigation bar. When the region is changed, the UI updates automatically to show the data, connections, and scan results for that region.
For more information about the Azure connection UI, refer to Azure Connection - User Interface Components.
Users with theAccount AdministratorandGroup Administratorroles can manage (edit, delete, rescan) the connection from theConfiguration → Connections → CLOUD.
Deleting the Azure connection cannot be undone.
A group with the same name will be created on the Fortanix IAM Groups page. For more information, refer to Fortanix Armor Identity and Access Management (IAM).
11.0 Troubleshooting
For information about common issues and troubleshooting steps when configuring Fortanix Key Insight in cloud environments, refer to Cloud Connection Troubleshooting.