Skip to main content

Illumio Segmentation for the Cloud User Guide

Azure Least-Privileged Access Onboarding

Limited Availability

Currently, this feature is accessible to only a limited number of organizations.

Azure least-privileged users who cannot use Global Administrator privileges because of company security requirements must use Advanced Onboarding. This follows Microsoft's recommended approach for third-party access to an application in a customer's Azure tenant.

During the Advanced Onboarding process, Azure least-privileged users request approval from an Azure administrator and complete onboarding once approval is granted.

Prerequisites

Review the prerequisites and permissions before you onboard Azure.

Onboard Azure as a least-privileged access user
  1. If you are logging in for the first time, click + Azure on the Onboarding page to onboard your first account.

  2. If you've already onboarded other accounts, choose Onboarding from the left navigation. Click +Add Azure at the top of the page.

  3. The Add Azure Cloud wizard opens and displays the first step: Choose Your Experience.

  4. Select Advanced Onboarding.

  5. Select Tenant or Subscription and copy the fields from the Azure portal.

  6. In Connect your Azure Cloud provide the following information about your Azure account:

    • Name: Specify a descriptive name for the account. This name appears in Cloud.

    • Tenant ID: Paste the parent management group ID that you copied from Azure.

    • Subscription ID: Select the subscription you want to onboard.

  7. Click Sign in with Microsoft.

    • Azure users who don't have Global Administrator privileges must click Request approval to alert an Azure admin, then Save & Exit.

      Once an admin approves, the least-privileged user returns to the Illumio onboarding page, hovers Setup in progress for the subscription and clicks Continue Onboarding to confirm by clicking I confirm my admin has approved the consent request for Illumio.

  8. Select permissions and click Continue.

    • Read Only provide the required permissions to build your AI security graph for visibility across your subscription or tenant. This provides the Illumio Cross Account Role read-only access.

    • Read and Write provide the required permissions for visibility and the use of one-click quarantine remediation capabilities across your subscription or tenant. This grants the Illumio Cross Account Role permission to view your Azure subscription resources and to apply policy to them.

    Note

    To view the permissions you are granting Illumio Segmentation for the Cloud to your Azure subscription, click Show Permissions (Optional) and download them. This is required for you to onboard the subscription if you are unable to run the script, because you must manually provide the listed permissions.

  9. Select an existing service account or create a new one. Make sure to copy and save the credentials.

  10. Paste the service account token from the service account credentials.

  11. Run the PowerShell Callback Script in Azure and click I have run the script and confirmed that it completed successfully in the Illumio onboarding wizard.

  12. Save & Continue and click Complete.

Note

You must set up flow logs and grant flow log access for onboarding to succeed.

Set up flow logs and grant access

The Onboarding page opens and displays a new row for what you onboarded.

What's Next After Onboarding your Subscription

When finished, the Onboarding page opens and displays a new row for that account.

For the next steps after onboarding a subscription, After onboarding your accounts.

If you originally set the permissions to read only, and wish to change them to read and write, see Change Azure permissions from read to read and write.