Connect Azure to Black Cat SSPM
Connect your Azure subscription so Black Cat can review role assignments, network security groups, storage exposure, Key Vault settings and diagnostic logging.
≈ 10 min · audit access · no write-capable permission
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
Reader (Azure RBAC on subscription) | Lets Black Cat review the configuration of resources in the subscription, including networking, storage and databases. | Required |
Key Vault Reader (Azure RBAC) | Lets Black Cat review Key Vault settings, key and secret expiry — never the secret values themselves. | Required |
Security Reader (Azure RBAC) | Lets Black Cat review Microsoft Defender for Cloud settings and the recommendations it raises. | Required |
What you'll need
- Subscription identifier Required — Shown on the Subscriptions page of the Azure portal.
- Directory (tenant) identifier Required — Shown on the overview page of your Microsoft Entra directory.
- Application (client) identifier Required — Shown on the read-only app registration you create for Black Cat.
- Client secret Required — Created on the same app registration under Certificates & secrets.