Azure

Microsoft Azure security scanning

Scan 46 Azure services across identity, storage, networking and data for misconfiguration.

How you connect

Connect with a service principal — tenant ID, subscription ID, client ID and client secret. Reader on the subscription covers the resource checks; Microsoft Entra ID also needs Directory.Read.All and Policy.Read.All on the app registration.

What A1 Cloud Guard looks for

  • Blob containers set to public access
  • Network security groups exposing management ports
  • Key Vaults without purge protection or soft delete
  • SQL databases without transparent data encryption
  • Defender plans left off for a subscription

46 services covered

Choose any combination per scan — you are never forced to scan the whole estate.

  • Virtual Machines
  • Blob Storage
  • Microsoft Entra ID
  • AKS Clusters
  • Key Vault
  • Virtual Networks
  • Azure SQL
  • Cosmos DB
  • Azure Functions
  • App Service
  • Service Bus
  • Event Hubs
  • Azure Monitor
  • Microsoft Defender
  • Network Security Groups
  • Load Balancer
  • Azure DNS
  • Container Registry
  • Azure Policy
  • RBAC Role Assignments
  • Resource Locks
  • Managed Identities
  • Microsoft Sentinel
  • Log Analytics
  • Backup & Recovery Services
  • Azure Firewall
  • Application Gateway & WAF
  • Front Door & CDN
  • Private Link
  • Azure Bastion
  • Public IP Addresses
  • Managed Disks
  • VM Scale Sets
  • Azure Cache for Redis
  • Database for PostgreSQL
  • Database for MySQL
  • Synapse Analytics
  • Data Factory
  • Azure Databricks
  • Container Instances
  • API Management
  • Logic Apps
  • Event Grid
  • Container Apps
  • Cognitive Services & OpenAI
  • Automation Accounts

Scan your Azure estate

Connect a read-only credential and see the full report on the free plan.