Documentation — September 02, 2026
6 files changed, 77 insertions, 122 deletions — view the commit on the mirror.
Azure agentless disk scanning drops from six custom RBAC roles to three; compliance authoring reworked
- Microsoft Azure provider permissions replaces the six ADS custom RBAC roles with three, confining every write and delete to the Cortex-created resource group.
- Three compliance catalog pages rewrite custom standard authoring: categories and controls are no longer built inside the standard wizard, and a control may now belong to more than one custom standard.
- The Azure APIM ingestion page drops a duplicated inbound policy snippet.
- The Threat Management landing page gains a link to an Extended Threat Intelligence section.
- A quiet day otherwise: six pages changed, nothing added or removed.
Highlights
-
Agentless Disk Scanning is re-split into three Azure roles, with writes and deletes confined to one resource group
ADSScannedAssetsRole, ADSOutpostRole and ADSEphemeralResourcesRole replace ADSConnectorDiskRole, ADSConnectorGalleryImageRole, ADSConnectorSnapshotRole, ADSConnectorVMRole and ADSGalleryImagesRole; only the ephemeral role can delete, and it is scoped to the Cortex-created resource group rather than the onboarded scope.
-
Terraform subscription onboarding names the outpost role without "Role"
A new note states that Terraform subscription onboarding creates it as ADSOutpost-{suffix}, while Terraform management group onboarding and both ARM paths create ADSOutpostRole-{suffix}.
-
Custom standards no longer build their own categories and controls
The Categories & Controls step becomes Select Controls, picking from existing controls or deferring via Create and Assign New Controls; the documented ceiling of 600 controls per standard goes with it.
-
A control can now be associated with more than one custom standard
Both the create and edit metadata lists change from "a single custom standard" to one or more, and category and sub-category move to the top of the create form.
-
The Azure APIM inbound policy snippet was duplicated
Three lines setting requestBody and requestHeaders appeared twice in the copy-paste block; the first copy is removed.
-
Threat Management links to an Extended Threat Intelligence section
A content reference to threat-management/extended-threat-intelligence is inserted between Analytics and Threat Intel Management.
Changes
6 files listed, 6 written up and shaded below.
-
▸ ▾ Choose compliance standards from the compliance catalog modified +1 −1 Drops the RBAC and Pod security example and now states that controls are grouped into categories and sub-categories rather than that they can be.
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalogRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -9,11 +9,11 @@ description: >-The compliance catalogs provide a list of available compliance standards and controls.The compliance catalogs provide a list of available compliance standards and controls.Cortex provides lists of available standards and controls in the Standards and Controls catalogs under Posture Management → Compliance → Catalogs.Cortex provides lists of available standards and controls in the Standards and Controls catalogs under Posture Management → Compliance → Catalogs.## What are standards and controls?## What are standards and controls?Standards are guidelines that organizations follow in order to comply with industry best practices and regulations, as well as internal organizational policies and procedures. They improve security and quality in operational practices.Standards are guidelines that organizations follow in order to comply with industry best practices and regulations, as well as internal organizational policies and procedures. They improve security and quality in operational practices.Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls can be grouped into categories, for example RBAC and Pod security.Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls are grouped into categories and sub-categories.The Standards and Controls catalogs include built-in industry standards and controls and custom organizational standards and controls.The Standards and Controls catalogs include built-in industry standards and controls and custom organizational standards and controls.Show markdown source
@@ -9,11 +9,11 @@ description: >- The compliance catalogs provide a list of available compliance standards and controls. Cortex provides lists of available standards and controls in the Standards and Controls catalogs under **Posture Management → Compliance → Catalogs**. ## What are standards and controls? Standards are guidelines that organizations follow in order to comply with industry best practices and regulations, as well as internal organizational policies and procedures. They improve security and quality in operational practices. -Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls can be grouped into categories, for example RBAC and Pod security. +Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls are grouped into categories and sub-categories. The **Standards** and **Controls** catalogs include built-in industry standards and controls and custom organizational standards and controls.
-
▸ ▾ Use a built-in or custom control modified +9 −9 A control can be associated with one or more custom standards rather than a single one, and the edit step now documents reassigning or creating categories and sub-categories.
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-controlRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -13,21 +13,21 @@ When using custom standards, you can use built-in controls or create custom contCortex XSIAM provides built-in controls that cannot be edited or deleted. When you edit or create a custom standard you can add the built-in control.Cortex XSIAM provides built-in controls that cannot be edited or deleted. When you edit or create a custom standard you can add the built-in control.## Create a custom control to use in a custom standard## Create a custom control to use in a custom standardYou can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.1. In the Controls catalog, click + Create Control.1. In the Controls catalog, click + Create Control.2. Define control metadata, including:2. Define control metadata, including:• A single category• A single sub category (optional)• Control name• Control name• Description (optional)• Description (optional)• Category• One or more custom standards to associate the control with• Sub category (optional)• A single custom standard to associate the control with3. Click Create.3. Click Create.4. Assign a custom detection rule to the control as follows.4. Assign a custom detection rule to the control as follows.## Associate a custom control to a detection rule## Associate a custom control to a detection ruleYou can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules.You can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules.hint infohint info@@ -60,16 +60,16 @@ To associate a custom compliance control:## Edit a custom control## Edit a custom controlYou can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.1. In the Controls catalog, click 🖼 cortex-cloud-compliance-three-dots.png on the built-in control you want to edit and click Save as new.\1. In the Controls catalog, click 🖼 cortex-cloud-compliance-three-dots.png on the built-in control you want to edit and click Save as new.\To edit a custom control, click 🖼 cortex-cloud-compliance-three-dots.png on the custom control and click Edit.To edit a custom control, click 🖼 cortex-cloud-compliance-three-dots.png on the custom control and click Edit.2. Click Next.2. Click Next.3. Define control metadata, including:3. Edit control metadata, including:• Control name• Category: You can reassign the control to a different existing category or create a new category.• Description• Sub category (optional): You can reassign the control to a different existing sub category or create a new sub category.• Category• Control name: You can update the control name.• Sub category• Description (optional): You can update the control description.• A single custom standard to associate the control with• Select custom standards: You can modify the list of custom standards with which the control should be associated.4. Click Save.4. Click Save.5. If the control does not already contain a rule, assign a custom detection rule to the control.5. If the control does not already contain a rule, assign a custom detection rule to the control.Show markdown source
@@ -13,21 +13,21 @@ When using custom standards, you can use built-in controls or create custom cont Cortex XSIAM provides built-in controls that cannot be edited or deleted. When you edit or create a custom standard you can add the built-in control. ## Create a custom control to use in a custom standard You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard. 1. In the **Controls** catalog, click **+ Create Control**. 2. Define control metadata, including: + * A single category + * A single sub category (optional) * Control name * Description (optional) - * Category - * Sub category (optional) - * A single custom standard to associate the control with + * One or more custom standards to associate the control with 3. Click **Create**. 4. Assign a custom detection rule to the control as follows. ## Associate a custom control to a detection rule You can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules. {% hint style="info" %} @@ -60,16 +60,16 @@ To associate a custom compliance control: ## Edit a custom control You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control. 1. In the **Controls** catalog, click [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the built-in control you want to edit and click **Save as new**.\ To edit a custom control, click [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the custom control and click **Edit**. 2. Click **Next**. -3. Define control metadata, including: - * Control name - * Description - * Category - * Sub category - * A single custom standard to associate the control with +3. Edit control metadata, including: + * Category: You can reassign the control to a different existing category or create a new category. + * Sub category (optional): You can reassign the control to a different existing sub category or create a new sub category. + * Control name: You can update the control name. + * Description (optional): You can update the control description. + * Select custom standards: You can modify the list of custom standards with which the control should be associated. 4. Click **Save**. 5. If the control does not already contain a rule, assign a custom detection rule to the control. -
▸ ▾ Use a built-in or custom standard modified +6 −12 Creating or editing a custom standard now ends in a Select Controls step; the inline Add Category, Add Subcategory and Add Control flow and the 600-control limit are gone.
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-standardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -29,38 +29,32 @@ You can create a custom compliance standard that is tailored to your own businesTo organize controls within a custom compliance standard, you establish categories and optional sub-categories. Every control is defined as part of a specific standard and assigned to a single category within it. Sub-categories offer an additional layer of organizational structure.To organize controls within a custom compliance standard, you establish categories and optional sub-categories. Every control is defined as part of a specific standard and assigned to a single category within it. Sub-categories offer an additional layer of organizational structure.1. In the Standards catalog, click Create Standard.1. In the Standards catalog, click Create Standard.2. Define compliance standard metadata, including:2. Define compliance standard metadata, including:1. Name1. Name2. Description (optional)2. Description (optional)3. Labels (optional)3. Labels (optional)3. Click Next.3. Click Next.4. Under Categories & Controls:4. Under Select Controls, you can do one of the following:1. Select +Add Category to create a new category. You must create at least one category. A category serves as a container for organizing controls within the specific standard.1. Select the controls that you would like to add to the standard and click Create.2. (Optional) Select +Add Subcategory to add a new sub-category using. A sub-category serves as an optional sub-container for organizing controls within the specific category.2. You can use the option to Create and Assign New Controls if you would like to save the standard and then create new controls and assign them to the standard.3. Select +Add Control to define controls within the category (and sub-category if selected). Next, enter Control Name and an optional Description. Repeat this step for each control. You can define up to 600 controls per standard.4. Add additional categories and sub-categories and then add controls to them. When done, click Next.5. Review the summary of your changes.6. Click Create.## Edit a custom standard## Edit a custom standardYou can edit an existing custom standard.You can edit an existing custom standard.1. In the Standards catalog, right-click on the custom standard (or select
next to it) and then select Edit.
1. In the Standards catalog, right-click on the custom standard (or select
next to it) and then select Edit.
2. Define compliance standard metadata, including:2. Define compliance standard metadata, including:1. Name1. Name2. Description (optional)2. Description (optional)3. Labels (optional)3. Labels (optional)3. Click Next.3. Click Next.4. Under Categories & Controls:4. Under Select Controls, you can do one of the following:1. Update or define new categories, sub-categories, and controls as needed.1. Select the controls that you would like to add to the standard and click Save.2. When done, click Next.2. You can use the option to Save and Assign New Controls if you would like to save the standard and then create new controls and assign them to the standard.5. Review the summary of your changes and6. Click Save.## Delete a custom standard## Delete a custom standardTo delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps.To delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps.1. In the Standards catalog, right-click on the custom standard (or select
next to it ) and then select Delete.
1. In the Standards catalog, right-click on the custom standard (or select
next to it ) and then select Delete.
2. Click Delete.2. Click Delete.Show markdown source
@@ -29,38 +29,32 @@ You can create a custom compliance standard that is tailored to your own busines To organize controls within a custom compliance standard, you establish categories and optional sub-categories. Every control is defined as part of a specific standard and assigned to a single category within it. Sub-categories offer an additional layer of organizational structure. 1. In the **Standards** catalog, click **Create Standard**. 2. Define compliance standard metadata, including: 1. **Name** 2. **Description** (optional) 3. **Labels** (optional) 3. Click **Next.** -4. Under **Categories & Controls**: - 1. Select **+Add Category** to create a new category. You must create at least one category. A category serves as a container for organizing controls within the specific standard. - 2. (Optional) Select **+Add Subcategory** to add a new sub-category using. A sub-category serves as an optional sub-container for organizing controls within the specific category. - 3. Select **+Add Control** to define controls within the category (and sub-category if selected). Next, enter **Control Name** and an optional **Description**. Repeat this step for each control. You can define up to 600 controls per standard. - 4. Add additional categories and sub-categories and then add controls to them. When done, click **Next**. -5. Review the summary of your changes. -6. Click **Create**. +4. Under **Select Controls**, you can do one of the following:  + 1. Select the controls that you would like to add to the standard and click **Create**.  + 2. You can use the option to **Create and Assign New Controls** if you would like to save the standard and then create new controls and assign them to the standard.   ## Edit a custom standard You can edit an existing custom standard. 1. In the **Standards** catalog, right-click on the custom standard (or select <img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FY4XEarbH6eoofHx6zLlS%2Freusable-menu.png?alt=media&token=bae02a0f-56cb-4d38-acb0-9cbc5b21b741" alt="" data-size="line"> next to it) and then select **Edit**. 2. Define compliance standard metadata, including: 1. **Name** 2. **Description** (optional) 3. **Labels** (optional) 3. Click **Next**. -4. Under **Categories & Controls**: - 1. Update or define new categories, sub-categories, and controls as needed. - 2. When done, click **Next**. -5. Review the summary of your changes and -6. Click **Save**. +4. Under **Select Controls**, you can do one of the following:  + 1. Select the controls that you would like to add to the standard and click **Save**.  + 2. You can use the option to **Save and Assign New Controls** if you would like to save the standard and then create new controls and assign them to the standard.   ## Delete a custom standard To delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps. 1. In the **Standards** catalog, right-click on the custom standard (or select <img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FY4XEarbH6eoofHx6zLlS%2Freusable-menu.png?alt=media&token=bae02a0f-56cb-4d38-acb0-9cbc5b21b741" alt="" data-size="line"> next to it ) and then select **Delete**. 2. Click **Delete**. -
▸ ▾ Ingest Azure APIM modified +0 −3 Removes a duplicated copy of the inbound policy snippet that set requestBody and requestHeaders twice.
xsiam/cloud-security/overview/secure-your-api-landscape/configure-api-security-from-end-to-end/ingest-azure-apimRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -78,19 +78,16 @@ Follow the steps to configure the policy.•<outbound>•<outbound>The `<inbound>` includes the request before it's sent to the `<outbound>`. The parameters are saved before they're sent.The `<inbound>` includes the request before it's sent to the `<outbound>`. The parameters are saved before they're sent.Add the following inside the `<inbound>`:Add the following inside the `<inbound>`:```programlisting```programlisting<!-- Save the request body and headers to be sent to Cortex. This should always be placed at the very beginning of the inbound element. --><!-- Save the request body and headers to be sent to Cortex. This should always be placed at the very beginning of the inbound element. --><set-variable name="requestBody" value="@((context.Request?.Body?.As<string>(preserveContent: true)) ?? string.Empty)" /><set-variable name="requestHeaders" value="@(JsonConvert.SerializeObject(context.Request.Headers))" /><!-- End of setting variables for sending to Cortex --><!-- Save the request body and headers to be sent to Cortex. This should always be placed at the very beginning of the inbound element. --><set-variable name="requestBody" value="@((context.Request?.Body?.As<string>(preserveContent: true)) ?? string.Empty)" /><set-variable name="requestBody" value="@((context.Request?.Body?.As<string>(preserveContent: true)) ?? string.Empty)" /><set-variable name="requestHeaders" value="@(JsonConvert.SerializeObject(context.Request.Headers))" /><set-variable name="requestHeaders" value="@(JsonConvert.SerializeObject(context.Request.Headers))" /><!-- End of setting variables for sending to Cortex --><!-- End of setting variables for sending to Cortex -->``````<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If any other inbound policies should be added, they must be added after these elements.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If any other inbound policies should be added, they must be added after these elements.</p></div>The `<outbound>` includes the request before it returns a response.The `<outbound>` includes the request before it returns a response.Show markdown source
@@ -78,19 +78,16 @@ Follow the steps to configure the policy. * `<outbound>` The `<inbound>` includes the request before it's sent to the `<outbound>`. The parameters are saved before they're sent. Add the following inside the `<inbound>`: ```programlisting <!-- Save the request body and headers to be sent to Cortex. This should always be placed at the very beginning of the inbound element. --> - <set-variable name="requestBody" value="@((context.Request?.Body?.As<string>(preserveContent: true)) ?? string.Empty)" /> - <set-variable name="requestHeaders" value="@(JsonConvert.SerializeObject(context.Request.Headers))" /> - <!-- End of setting variables for sending to Cortex --><!-- Save the request body and headers to be sent to Cortex. This should always be placed at the very beginning of the inbound element. --> <set-variable name="requestBody" value="@((context.Request?.Body?.As<string>(preserveContent: true)) ?? string.Empty)" /> <set-variable name="requestHeaders" value="@(JsonConvert.SerializeObject(context.Request.Headers))" /> <!-- End of setting variables for sending to Cortex --> ``` <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If any other inbound policies should be added, they must be added after these elements.</p></div> The `<outbound>` includes the request before it returns a response. -
▸ ▾ Microsoft Azure provider permissions modified +57 −97 ADSScannedAssetsRole, ADSOutpostRole and ADSEphemeralResourcesRole replace the six ADSConnector-era roles; every write and delete is now scoped to the Cortex-created resource group.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/cloud-service-provider-permissions/microsoft-azure-provider-permissionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -173,17 +173,17 @@ Custom Azure RBAC role with the read-like posture-assessment actions Cortex needMicrosoft.Compute/availabilitySets/read│Read availability sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/availabilitySets/read│Read availability sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/cloudServices/read│Read cloud services. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/cloudServices/read│Read cloud services. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/cloudServices/roleInstances/read│Read cloud service role instances. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/cloudServices/roleInstances/read│Read cloud service role instances. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/diskEncryptionSets/read│Read disk encryption sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/diskEncryptionSets/read│Read disk encryption sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/disks/read│Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment.Microsoft.Compute/disks/read│Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment.Microsoft.Compute/galleries/images/read│Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations.Microsoft.Compute/galleries/images/read│Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations.Microsoft.Compute/galleries/read│Read galleries. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/galleries/read│Read galleries. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/hostGroups/read│Read host groups. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/hostGroups/read│Read host groups. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/snapshots/read│Read snapshot metadata across the tenant to manage ADS scan snapshot lifecycleMicrosoft.Compute/snapshots/read│Read snapshot metadata to manage ADS scan snapshot lifecycleMicrosoft.Compute/virtualMachineScaleSets/networkInterfaces/read│Read network interfaces of VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read│Read network interfaces of VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/publicIPAddresses/read│Read public IP addresses of VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/publicIPAddresses/read│Read public IP addresses of VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/read│Read virtual machine scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/read│Read virtual machine scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/virtualMachines/instanceView/read│Read public IPs of VM scale set VM NICs IP configurations. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/virtualMachines/instanceView/read│Read public IPs of VM scale set VM NICs IP configurations. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/ipConfigurations/publicIPAddresses/read│Read public IPs of VM scale set VM NICs IP configurations. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/ipConfigurations/publicIPAddresses/read│Read public IPs of VM scale set VM NICs IP configurations. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read│Read virtual machines in VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read│Read virtual machines in VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachines/extensions/read│Read VM extensions. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachines/extensions/read│Read VM extensions. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachines/instanceView/read│Read VM instance view. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.Microsoft.Compute/virtualMachines/instanceView/read│Read VM instance view. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment.@@ -531,125 +531,85 @@ Microsoft built-in Azure RBAC role granting read, write, and delete access to blAssigned to│Customer-owned Audit UAMI cortexAuditUAMI-{suffix}.Assigned to│Customer-owned Audit UAMI cortexAuditUAMI-{suffix}.Assignment scope│The Cortex-created Storage Account cxa{suffix} only. No access to any customer-owned Storage Account.Assignment scope│The Cortex-created Storage Account cxa{suffix} only. No access to any customer-owned Storage Account.Used by│Cortex, to write Event Hub processing checkpoints (offsets and sequence numbers, no customer data).Used by│Cortex, to write Event Hub processing checkpoints (offsets and sequence numbers, no customer data).### Agentless Disk Scanning (ADS)### Agentless Disk Scanning (ADS)The Agentless Disk Scanning (ADS) permissions enable Cortex to securely analyze virtual machine workloads and storage resources without installing software agents. These permissions grant the necessary access to create temporary snapshots, manage disk copies, and inventory VM metadata, allowing Cortex to perform deep vulnerability scanning while keeping production environments completely untouched.The Agentless Disk Scanning (ADS) permissions enable Cortex to securely analyze virtual machine workloads and storage resources without installing software agents. These permissions grant the necessary access to create temporary snapshots, manage disk copies, and inventory VM metadata, allowing Cortex to perform deep vulnerability scanning while keeping production environments completely untouched.ADS Disk Role:ADSConnectorDiskRole-{suffix}ADS access is split into three roles so that the permissions which create and destroy resources are confined to a resource group Cortex owns, while the permissions that reach across your estate are kept as narrow as possible.Custom Azure RBAC role granting read, write, and delete access to managed disks.• TheADSScannedAssetsRoleandADSOutpostRoleroles apply across the onboarded subscription or management group, and neither can delete anything.• TheADSEphemeralResourcesRolerole holds every permission that writes or deletes a disk, snapshot, or gallery image, and is confined to the Cortex-created resource group. Because that role is scoped to that resource group alone, Cortex cannot delete a disk, snapshot, or image anywhere else in your environment.| | |#### ADS Scanned Assets Role:ADSScannedAssetsRole-{suffix}| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assignment scope│Matches the onboarded scope.Used by│Cortex ADS scanner during a scan run, to materialize a snapshot as a temporary disk, attach it to a scanner instance, and remove it on completion.ADSConnectorDiskRolepermissions:Custom Azure RBAC role granting read access to compute inventory, the ability to create snapshots, and time-limited read access to the contents of a managed disk.Permission│DescriptionCreated when│ADS capability enabled.| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Microsoft.Compute/disks/delete│Delete disks after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary disks used during analysis do not remain as dangling resources.Assigned to│Cortex Service Principal.Microsoft.Compute/disks/read│Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment.Assignment scope│Matches the onboarded scope.Microsoft.Compute/disks/write│Create a disk from a snapshot before attaching it to a workload. This permission is essential for dynamic scanning and analysis without affecting the live environment. It allows the creation of a temporary disk copy to be analyzed securely by the scanner.Used by│Cortex ADS during discovery and at the start of a scan run, to:
- Identify which virtual machines and images are in scope.
- Create a snapshot of a target disk.
- Obtain temporary read access to that disk's contents.
ADS Gallery Image Read Role: ADSConnectorGalleryImageRole-{suffix}ADSScannedAssetsRole-{suffix}permissions:Custom Azure RBAC role granting read access to Azure Compute Gallery images and to Compute images. Read-only.Permission│Description| ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Microsoft.Compute/virtualMachines/read│Enable reading VM configurations. Cortex uses this to inventory virtual machines and identify those requiring security scanning.Microsoft.Compute/images/read│Read managed images in order to create disks for image scanning. Cortex uses this to inventory managed VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations.Microsoft.Compute/galleries/images/read│Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations.Microsoft.Compute/galleries/images/versions/read│Read gallery image version details within Cortex-managed resource groups. Cortex uses this to track the status of temporary image versions created during image scanning operations.Microsoft.Compute/snapshots/write│Create a snapshot of a target disk. Cortex uses this to make a temporary, read-only copy of your disk so the scanner can analyze the copy securely without touching your live environment. Snapshots are always written into the Cortex-created resource group.Microsoft.Compute/disks/beginGetAccess/action│Issue a time-limited SAS URL that begins to grant read access to the contents of a managed disk. This is how the scanner reads disk data to assess it for vulnerabilities, so it is a data-access grant rather than a metadata read. The access is time-limited and read-only, and Cortex can delete or modify resources only within its own resource group.| | |#### ADS Outpost Role:ADSOutpostRole-{suffix}| ---------------- | -------------------------------------------------------------------------- |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assignment scope│Matches the onboarded scope.Used by│Cortex ADS scanner to identify VM images that are candidates for scanning.ADSConnectorGalleryImageRole-{suffix}permissions:Custom Azure RBAC role granting read access to snapshots.Permission│Descriptionhint info| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Note: With Terraform subscription onboarding, this role is created asADSOutpost-{suffix}, without "Role" in the name. Terraform management group onboarding and both ARM onboarding paths create it asADSOutpostRole-{suffix}.Microsoft.Compute/disks/beginGetAccess/action│Begin get access on disks (action). Cortex uses this for security assessment and operational visibility across the Azure environment.endhintMicrosoft.Compute/galleries/images/read│Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations.ADS Snapshot Write Role:ADSConnectorSnapshotRole-{suffix}Custom Azure RBAC role granting create and delete access to disk snapshots.| | || ---------------- | ------------------------------------------------------------------------------------------------------------------------ |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assignment scope│The Cortex-created resource group.Used by│Cortex ADS scanner at the start of a scan run, to snapshot the customer VM disk, and at the end, to delete the snapshot.ADSConnectorSnapshotRole-{suffix}permissions:Permission│Description| ---------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Microsoft.Compute/snapshots/delete│Delete snapshots after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary snapshots used during analysis do not remain as dangling resources.Microsoft.Compute/snapshots/write│Create a snapshot of a disk. This permission is essential for dynamic scanning and analysis without affecting the live environment. It allows the creation of a temporary disk copy to be analyzed securely by the scanner.ADS VM Role:ADSConnectorVMRole-{suffix}Custom Azure RBAC role granting read access to virtual machine metadata. Read-only.| | || ---------------- | --------------------------------------------------------------------------------------- |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assignment scope│Matches the onboarded scope.Used by│Cortex ADS scanner, on each scan cycle, to enumerate VMs and identify scanning targets.ADSConnectorVMRole-{suffix}permissions:Permission│Description| -------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- |Microsoft.Compute/virtualMachines/read│Enable reading VM configurations. Cortex uses this to inventory virtual machines and identify those requiring security scanning.ADS Gallery Image Write Role:ADSGalleryImagesRole-{suffix}Custom Azure RBAC role granting create and delete access to Azure Compute Gallery image versions.| | || ---------------- | -------------------------------------------------------------------------------------------------------------------------------------- |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assignment scope│The Cortex-created resource group.Used by│Cortex ADS scanner during a scan run, to publish and later remove the Compute Gallery image version used to boot the scanner instance.ADSGalleryImagesRole-{suffix}permissions:Permission│Description| -------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Microsoft.Compute/galleries/images/delete│Delete temporary gallery images within Cortex-managed resource groups. Cortex uses this to clean up temporary gallery images created during legacy image scanning, ensuring no stale resources remain after analysis is complete.Microsoft.Compute/galleries/images/versions/delete│Delete temporary gallery image versions after legacy image scanning completes. Cortex uses this to clean up temporary image versions created during the scanning process, ensuring no orphaned resources remain in Cortex-managed resource groups.Microsoft.Compute/galleries/images/versions/read│Read gallery image version details within Cortex-managed resource groups. Cortex uses this to track the status of temporary image versions created during legacy image scanning operations.Microsoft.Compute/galleries/images/versions/write│Create temporary gallery image versions within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary image versions that facilitate the scanning process.Microsoft.Compute/galleries/images/write│Create temporary gallery images within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary gallery images that facilitate the scanning process.ADS Snapshot Read Role:ADSOutpostRole-{suffix}Custom Azure RBAC role granting read access to disk snapshot metadata. Read-only.| | |Created when│ADS capability enabled.| ---------------- | ---------------------------------------------------------------------------------- || ---------------- | -------------------------------------------------------- |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assigned to│Cortex Service Principal.Assignment scope│Matches the onboarded scope.Assignment scope│Matches the onboarded scope.Used by│Cortex ADS, to read snapshot metadata during a scan run.Used by│Cortex ADS scanner to inspect existing disk snapshots and track scanning progress.ADSOutpostRole-{suffix}permissions:ADSOutpostRole-{suffix}permissions:Permission│DescriptionPermission│Description| -------------------------------- | ------------------------------------------------------------------------------ || -------------------------------- | ------------------------------------------------------------------------------- |Microsoft.Compute/snapshots/read│Read snapshot metadata across the tenant to manage ADS scan snapshot lifecycleMicrosoft.Compute/snapshots/read│Read snapshot metadata across the tenant to manage ADS scan snapshot lifecycle.#### ADS Ephemeral Resources Role:ADSEphemeralResourcesRole-{suffix}Custom Azure RBAC role granting read, write, and delete access to the temporary disks, snapshots, and gallery images that a scan creates and removes.Field│Value| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Created when│ADS capability enabled.Assigned to│Cortex Service Principal.Assignment scope│The Cortex-created resource group only. This is narrower than the onboarded scope.Used by│Cortex ADS during a scan run, to:
- Copy a snapshot into a gallery image version.
- Materialize that image as a temporary disk which is attached to a scanner instance at launch.
- Delete the temporary disk, snapshot, and image version on completion.
ADSEphemeralResourcesRole-{suffix}permissions:Permission│Description| -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Microsoft.Compute/disks/read│Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment.Microsoft.Compute/disks/write│Create the temporary disk that a scanner instance reads during a scan. This permission is essential for dynamic scanning and analysis without affecting the live environment. It allows the creation of a temporary disk copy to be analyzed securely by the scanner.Microsoft.Compute/disks/delete│Delete disks after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary disks used during analysis do not remain as dangling resources.Microsoft.Compute/snapshots/delete│Delete snapshots after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary snapshots used during analysis do not remain as dangling resources.Microsoft.Compute/galleries/images/write│Create temporary gallery image versions within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary image versions that facilitate the scanning process.Microsoft.Compute/galleries/images/delete│Delete temporary gallery images within Cortex-managed resource groups. Cortex uses this to clean up temporary gallery images created during legacy image scanning, ensuring no stale resources remain after analysis is complete.Microsoft.Compute/galleries/images/versions/write│Create temporary gallery image versions within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary image versions that facilitate the scanning process.Microsoft.Compute/galleries/images/versions/delete│Delete temporary gallery image versions after legacy image scanning completes. Cortex uses this to clean up temporary image versions created during the scanning process, ensuring no orphaned resources remain in Cortex-managed resource groups.### Serverless Scan### Serverless ScanConditional (opt-in). Deployed only when serverless scanning is enabled. Retrieves Function App / Web App publish profiles to download function code for scanning.Conditional (opt-in). Deployed only when serverless scanning is enabled. Retrieves Function App / Web App publish profiles to download function code for scanning.Serverless Scanning Role:serverlessScanningRole-{suffix}Serverless Scanning Role:serverlessScanningRole-{suffix}Custom Azure RBAC role granting read access to App Service and Function App configuration, and the ability to retrieve the publish profile.Custom Azure RBAC role granting read access to App Service and Function App configuration, and the ability to retrieve the publish profile.Show markdown source
@@ -173,17 +173,17 @@ Custom Azure RBAC role with the read-like posture-assessment actions Cortex need | Microsoft.Compute/availabilitySets/read | Read availability sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/cloudServices/read | Read cloud services. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/cloudServices/roleInstances/read | Read cloud service role instances. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/diskEncryptionSets/read | Read disk encryption sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/disks/read | Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment. | | Microsoft.Compute/galleries/images/read | Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations. | | Microsoft.Compute/galleries/read | Read galleries. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/hostGroups/read | Read host groups. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | -| Microsoft.Compute/snapshots/read | Read snapshot metadata across the tenant to manage ADS scan snapshot lifecycle | +| Microsoft.Compute/snapshots/read | Read snapshot metadata to manage ADS scan snapshot lifecycle | | Microsoft.Compute/virtualMachineScaleSets/networkInterfaces/read | Read network interfaces of VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachineScaleSets/publicIPAddresses/read | Read public IP addresses of VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachineScaleSets/read | Read virtual machine scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachineScaleSets/virtualMachines/instanceView/read | Read public IPs of VM scale set VM NICs IP configurations. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachineScaleSets/virtualMachines/networkInterfaces/ipConfigurations/publicIPAddresses/read | Read public IPs of VM scale set VM NICs IP configurations. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachineScaleSets/virtualMachines/read | Read virtual machines in VM scale sets. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachines/extensions/read | Read VM extensions. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | | Microsoft.Compute/virtualMachines/instanceView/read | Read VM instance view. Cortex uses this for comprehensive asset discovery and security posture assessment across the Azure environment. | @@ -531,125 +531,85 @@ Microsoft built-in Azure RBAC role granting read, write, and delete access to bl | Assigned to | Customer-owned Audit UAMI cortexAuditUAMI-{suffix}. | | Assignment scope | The Cortex-created Storage Account cxa{suffix} only. No access to any customer-owned Storage Account. | | Used by | Cortex, to write Event Hub processing checkpoints (offsets and sequence numbers, no customer data). | ### Agentless Disk Scanning (ADS) The Agentless Disk Scanning (ADS) permissions enable Cortex to securely analyze virtual machine workloads and storage resources without installing software agents. These permissions grant the necessary access to create temporary snapshots, manage disk copies, and inventory VM metadata, allowing Cortex to perform deep vulnerability scanning while keeping production environments completely untouched. -**ADS Disk Role: `ADSConnectorDiskRole-{suffix}`** +ADS access is split into three roles so that the permissions which create and destroy resources are confined to a resource group Cortex owns, while the permissions that reach across your estate are kept as narrow as possible. -Custom Azure RBAC role granting read, write, and delete access to managed disks. +* The `ADSScannedAssetsRole` and `ADSOutpostRole` roles apply across the onboarded subscription or management group, and neither can delete anything.  +* The `ADSEphemeralResourcesRole` role holds every permission that writes or deletes a disk, snapshot, or gallery image, and is confined to the Cortex-created resource group. Because that role is scoped to that resource group alone, Cortex cannot delete a disk, snapshot, or image anywhere else in your environment. -| | | -| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -| Created when | ADS capability enabled. | -| Assigned to | Cortex Service Principal. | -| Assignment scope | Matches the onboarded scope. | -| Used by | Cortex ADS scanner during a scan run, to materialize a snapshot as a temporary disk, attach it to a scanner instance, and remove it on completion. | +#### ADS Scanned Assets Role: `ADSScannedAssetsRole-{suffix}` -**`ADSConnectorDiskRole` permissions:** +Custom Azure RBAC role granting read access to compute inventory, the ability to create snapshots, and time-limited read access to the contents of a managed disk. -| Permission | Description | -| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Microsoft.Compute/disks/delete | Delete disks after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary disks used during analysis do not remain as dangling resources. | -| Microsoft.Compute/disks/read | Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment. | -| Microsoft.Compute/disks/write | Create a disk from a snapshot before attaching it to a workload. This permission is essential for dynamic scanning and analysis without affecting the live environment. It allows the creation of a temporary disk copy to be analyzed securely by the scanner. | +| Created when | ADS capability enabled. | +| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Assigned to | Cortex Service Principal. | +| Assignment scope | Matches the onboarded scope. | +| Used by | <p>Cortex ADS during discovery and at the start of a scan run, to: </p><ul><li>Identify which virtual machines and images are in scope.</li><li>Create a snapshot of a target disk.</li><li>Obtain temporary read access to that disk's contents.</li></ul> | -**ADS Gallery Image Read Role: ADSConnectorGalleryImageRole-{suffix}** +**`ADSScannedAssetsRole-{suffix}` permissions:** -Custom Azure RBAC role granting read access to Azure Compute Gallery images and to Compute images. Read-only. +| Permission | Description | +| ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| Microsoft.Compute/virtualMachines/read | Enable reading VM configurations. Cortex uses this to inventory virtual machines and identify those requiring security scanning. | +| Microsoft.Compute/images/read | Read managed images in order to create disks for image scanning. Cortex uses this to inventory managed VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations. | +| Microsoft.Compute/galleries/images/read | Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations. | +| Microsoft.Compute/galleries/images/versions/read | Read gallery image version details within Cortex-managed resource groups. Cortex uses this to track the status of temporary image versions created during image scanning operations. | +| Microsoft.Compute/snapshots/write | Create a snapshot of a target disk. Cortex uses this to make a temporary, read-only copy of your disk so the scanner can analyze the copy securely without touching your live environment. Snapshots are always written into the Cortex-created resource group. | +| Microsoft.Compute/disks/beginGetAccess/action | Issue a time-limited SAS URL that begins to grant read access to the contents of a managed disk. This is how the scanner reads disk data to assess it for vulnerabilities, so it is a data-access grant rather than a metadata read. The access is time-limited and read-only, and Cortex can delete or modify resources only within its own resource group. | -| | | -| ---------------- | -------------------------------------------------------------------------- | -| Created when | ADS capability enabled. | -| Assigned to | Cortex Service Principal. | -| Assignment scope | Matches the onboarded scope. | -| Used by | Cortex ADS scanner to identify VM images that are candidates for scanning. | +#### ADS Outpost Role: `ADSOutpostRole-{suffix}` -**`ADSConnectorGalleryImageRole-{suffix}` permissions:** +Custom Azure RBAC role granting read access to snapshots. -| Permission | Description | -| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Microsoft.Compute/disks/beginGetAccess/action | Begin get access on disks (action). Cortex uses this for security assessment and operational visibility across the Azure environment. | -| Microsoft.Compute/galleries/images/read | Read gallery images in order to create disks for image scanning. Cortex uses this to inventory VM images and identify those requiring security assessment and vulnerability scanning as part of agentless disk scanning operations. | - -**ADS Snapshot Write Role: `ADSConnectorSnapshotRole-{suffix}`** - -Custom Azure RBAC role granting create and delete access to disk snapshots. - -| | | -| ---------------- | ------------------------------------------------------------------------------------------------------------------------ | -| Created when | ADS capability enabled. | -| Assigned to | Cortex Service Principal. | -| Assignment scope | The Cortex-created resource group. | -| Used by | Cortex ADS scanner at the start of a scan run, to snapshot the customer VM disk, and at the end, to delete the snapshot. | - -**`ADSConnectorSnapshotRole-{suffix}` permissions:** - -| Permission | Description | -| ---------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Microsoft.Compute/snapshots/delete | Delete snapshots after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary snapshots used during analysis do not remain as dangling resources. | -| Microsoft.Compute/snapshots/write | Create a snapshot of a disk. This permission is essential for dynamic scanning and analysis without affecting the live environment. It allows the creation of a temporary disk copy to be analyzed securely by the scanner. | - -**ADS VM Role: `ADSConnectorVMRole-{suffix}`** - -Custom Azure RBAC role granting read access to virtual machine metadata. Read-only. - -| | | -| ---------------- | --------------------------------------------------------------------------------------- | -| Created when | ADS capability enabled. | -| Assigned to | Cortex Service Principal. | -| Assignment scope | Matches the onboarded scope. | -| Used by | Cortex ADS scanner, on each scan cycle, to enumerate VMs and identify scanning targets. | - -**`ADSConnectorVMRole-{suffix}` permissions:** - -| Permission | Description | -| -------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -| Microsoft.Compute/virtualMachines/read | Enable reading VM configurations. Cortex uses this to inventory virtual machines and identify those requiring security scanning. | - -**ADS Gallery Image Write Role: `ADSGalleryImagesRole-{suffix}`** - -Custom Azure RBAC role granting create and delete access to Azure Compute Gallery image versions. - -| | | -| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -| Created when | ADS capability enabled. | -| Assigned to | Cortex Service Principal. | -| Assignment scope | The Cortex-created resource group. | -| Used by | Cortex ADS scanner during a scan run, to publish and later remove the Compute Gallery image version used to boot the scanner instance. | - -**`ADSGalleryImagesRole-{suffix}` permissions:** - -| Permission | Description | -| -------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Microsoft.Compute/galleries/images/delete | Delete temporary gallery images within Cortex-managed resource groups. Cortex uses this to clean up temporary gallery images created during legacy image scanning, ensuring no stale resources remain after analysis is complete. | -| Microsoft.Compute/galleries/images/versions/delete | Delete temporary gallery image versions after legacy image scanning completes. Cortex uses this to clean up temporary image versions created during the scanning process, ensuring no orphaned resources remain in Cortex-managed resource groups. | -| Microsoft.Compute/galleries/images/versions/read | Read gallery image version details within Cortex-managed resource groups. Cortex uses this to track the status of temporary image versions created during legacy image scanning operations. | -| Microsoft.Compute/galleries/images/versions/write | Create temporary gallery image versions within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary image versions that facilitate the scanning process. | -| Microsoft.Compute/galleries/images/write | Create temporary gallery images within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary gallery images that facilitate the scanning process. | - -**ADS Snapshot Read Role: `ADSOutpostRole-{suffix}`** - -Custom Azure RBAC role granting read access to disk snapshot metadata. Read-only. +{% hint style="info" %} +**Note**: With Terraform subscription onboarding, this role is created as `ADSOutpost-{suffix}`, without "Role" in the name. Terraform management group onboarding and both ARM onboarding paths create it as `ADSOutpostRole-{suffix}`. +{% endhint %} -| | | -| ---------------- | ---------------------------------------------------------------------------------- | -| Created when | ADS capability enabled. | -| Assigned to | Cortex Service Principal. | -| Assignment scope | Matches the onboarded scope. | -| Used by | Cortex ADS scanner to inspect existing disk snapshots and track scanning progress. | +| Created when | ADS capability enabled. | +| ---------------- | -------------------------------------------------------- | +| Assigned to | Cortex Service Principal. | +| Assignment scope | Matches the onboarded scope. | +| Used by | Cortex ADS, to read snapshot metadata during a scan run. | **`ADSOutpostRole-{suffix}` permissions:** -| Permission | Description | -| -------------------------------- | ------------------------------------------------------------------------------ | -| Microsoft.Compute/snapshots/read | Read snapshot metadata across the tenant to manage ADS scan snapshot lifecycle | +| Permission | Description | +| -------------------------------- | ------------------------------------------------------------------------------- | +| Microsoft.Compute/snapshots/read | Read snapshot metadata across the tenant to manage ADS scan snapshot lifecycle. | + +#### ADS Ephemeral Resources Role: `ADSEphemeralResourcesRole-{suffix}` + +Custom Azure RBAC role granting read, write, and delete access to the temporary disks, snapshots, and gallery images that a scan creates and removes. + +| Field | Value | +| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Created when | ADS capability enabled. | +| Assigned to | Cortex Service Principal. | +| Assignment scope | The Cortex-created resource group only. This is narrower than the onboarded scope. | +| Used by | <p>Cortex ADS during a scan run, to:</p><p></p><ul><li>Copy a snapshot into a gallery image version. </li><li>Materialize that image as a temporary disk which is attached to a scanner instance at launch.</li><li>Delete the temporary disk, snapshot, and image version on completion.</li></ul> | + +**`ADSEphemeralResourcesRole-{suffix}`** **permissions:** + +| Permission | Description | +| -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Microsoft.Compute/disks/read | Retrieve disk metadata. This is used to identify disk properties and states, such as detecting dangling disks. It ensures accurate inventory and assessment of storage resources within the environment. | +| Microsoft.Compute/disks/write | Create the temporary disk that a scanner instance reads during a scan. This permission is essential for dynamic scanning and analysis without affecting the live environment. It allows the creation of a temporary disk copy to be analyzed securely by the scanner. | +| Microsoft.Compute/disks/delete | Delete disks after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary disks used during analysis do not remain as dangling resources. | +| Microsoft.Compute/snapshots/delete | Delete snapshots after scanning has finished. This action is critical for remediation and resource hygiene, preventing data exfiltration and reducing the attack surface. It ensures that temporary snapshots used during analysis do not remain as dangling resources. | +| Microsoft.Compute/galleries/images/write | Create temporary gallery image versions within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary image versions that facilitate the scanning process. | +| Microsoft.Compute/galleries/images/delete | Delete temporary gallery images within Cortex-managed resource groups. Cortex uses this to clean up temporary gallery images created during legacy image scanning, ensuring no stale resources remain after analysis is complete. | +| Microsoft.Compute/galleries/images/versions/write | Create temporary gallery image versions within Cortex-managed resource groups. Cortex uses this during legacy image scanning to create temporary image versions that facilitate the scanning process. | +| Microsoft.Compute/galleries/images/versions/delete | Delete temporary gallery image versions after legacy image scanning completes. Cortex uses this to clean up temporary image versions created during the scanning process, ensuring no orphaned resources remain in Cortex-managed resource groups. | ### Serverless Scan Conditional (opt-in). Deployed only when serverless scanning is enabled. Retrieves Function App / Web App publish profiles to download function code for scanning. **Serverless Scanning Role: `serverlessScanningRole-{suffix}`** Custom Azure RBAC role granting read access to App Service and Function App configuration, and the ability to retrieve the publish profile. -
▸ ▾ Threat management modified +4 −0 Gains a content reference to a new Extended Threat Intelligence section alongside Analytics and Threat Intel Management.
xsiam/detect-investigate-and-respond-to-threats/threat-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,11 +3,15 @@content threat-management/detection-rulescontent threat-management/detection-rulesdetection-rulesdetection-rulesendcontentendcontentcontent threat-management/analyticscontent threat-management/analyticsanalyticsanalyticsendcontentendcontentcontent threat-management/extended-threat-intelligenceextended-threat-intelligenceendcontentcontent threat-management/threat-intel-managementcontent threat-management/threat-intel-managementthreat-intel-managementthreat-intel-managementendcontentendcontentShow markdown source
@@ -3,11 +3,15 @@ {% content-ref url="threat-management/detection-rules" %} [detection-rules](threat-management/detection-rules) {% endcontent-ref %} {% content-ref url="threat-management/analytics" %} [analytics](threat-management/analytics) {% endcontent-ref %} +{% content-ref url="threat-management/extended-threat-intelligence" %} +[extended-threat-intelligence](threat-management/extended-threat-intelligence) +{% endcontent-ref %} + {% content-ref url="threat-management/threat-intel-management" %} [threat-intel-management](threat-management/threat-intel-management) {% endcontent-ref %}