Checks Defender for Cloud plan coverage and activity logging in an Azure subscription.
AvailableRead-only collection
What vCISO.ai observes
Defender for Cloud plan status
Activity log configuration
Authorization and permissions
Microsoft Entra application credentials for an Azure subscription
Reader role on the subscription
Security Reader role on the subscription
Read-only Azure Resource Manager calls
Setup path
Setup remains administrator-controlled inside the authenticated workspace.
Register an Entra application
Assign Reader and Security Reader on the subscription
Provide the tenant, application, secret, and subscription IDs
Run and review the first collection
Collection limitations
A limited or failed read stays visible and never becomes a passing result.
The released connector reads one configured subscription
Current observations focus on Defender for Cloud plans and activity-log export
Connection does not change Azure resources or security settings
Disconnect and deletion behavior
An administrator can disconnect the integration. Stored credentials and configuration are removed locally and connector-derived evidence is expired. The customer should also remove or rotate the Entra application secret.
Existing historical records remain available as review history
Connector-derived evidence is marked expired when the source is disconnected
Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Microsoft Azure does not automatically verify a control, complete a framework, or produce an audit conclusion.
Start with the roadmap
Put Microsoft Azure into a prioritized readiness plan.
Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.