Azure
Microsoft Azure security scanning
Scan 46 Azure services across identity, storage, networking and data for misconfiguration.
How you connect
Connect with a service principal — tenant ID, subscription ID, client ID and client secret. Reader on the subscription covers the resource checks; Microsoft Entra ID also needs Directory.Read.All and Policy.Read.All on the app registration.
What A1 Cloud Guard looks for
- Blob containers set to public access
- Network security groups exposing management ports
- Key Vaults without purge protection or soft delete
- SQL databases without transparent data encryption
- Defender plans left off for a subscription
46 services covered
Choose any combination per scan — you are never forced to scan the whole estate.
Scan your Azure estate
Connect a read-only credential and see the full report on the free plan.