Skip to content

Connect Azure to Black Cat SSPM

Version française

Connect your Azure subscription so Black Cat can review role assignments, network security groups, storage exposure, Key Vault settings and diagnostic logging.

≈ 10 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
Reader (Azure RBAC on subscription)Lets Black Cat review the configuration of resources in the subscription, including networking, storage and databases.Required
Key Vault Reader (Azure RBAC)Lets Black Cat review Key Vault settings, key and secret expiry — never the secret values themselves.Required
Security Reader (Azure RBAC)Lets Black Cat review Microsoft Defender for Cloud settings and the recommendations it raises.Required

What you'll need

  • Subscription identifier Required — Shown on the Subscriptions page of the Azure portal.
  • Directory (tenant) identifier Required — Shown on the overview page of your Microsoft Entra directory.
  • Application (client) identifier Required — Shown on the read-only app registration you create for Black Cat.
  • Client secret Required — Created on the same app registration under Certificates & secrets.

Where to create it

What we check on Azure →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan