Microsoft Azure offboarding overview

When you delete an Azure cloud instance from Cortex XSIAM, the cloud instance is removed from the platform. However, the Azure resources created during onboarding, including role assignments, role definitions, diagnostic settings, deployment stacks, resource groups, and managed identities, remain in your Azure environment until you explicitly clean them up.

The offboarding method depends on two factors:

  • The scope at which the cloud instance was onboarded (subscription, management group, tenant, or tenant with Entra ID only).
  • The template type used during onboarding (ARM or Terraform).

Use the table below to identify the correct offboarding procedure for your Microsoft Azure cloud instance.

Onboarding scopeTemplate typeProcedure
All scopesTerraformOffboard Terraform-based Azure deployments (all scopes)
SubscriptionARMOffboard Azure subscription (ARM)
Management group or tenantARMOffboard Azure management group or tenant scope (ARM)
Tenant (Entra ID only)ARMOffboard Azure tenant with Entra ID only