Microsoft Azure Integration with DefectDojo
Microsoft Azure Integration with DefectDojo
Microsoft Azure is Microsoft's public cloud platform. Azure organizes resources into subscriptions, and larger tenants group those subscriptions under a tree of management groups that starts at the tenant root group. Access is controlled through Microsoft Entra ID, and Azure Resource Manager is the API that exposes this structure. The DefectDojo Pro connector for Azure is an asset connector: it reads that hierarchy and builds matching Assets and Organizations in DefectDojo, and it does not import findings.
Microsoft Azure Integration with DefectDojo
We connected Microsoft Azure to DefectDojo because our cloud findings kept arriving faster than anyone could create Assets for them. The Azure connector reads our tenant and creates one Asset per subscription, grouped by management group, so when Microsoft Defender for Cloud findings arrive they already have a home with the right name and the right parent. Nobody maintains a spreadsheet of subscriptions anymore, and new subscriptions show up in DefectDojo on the next sync instead of when someone remembers to add them.
Why Microsoft Azure Matters
In most Azure estates, subscriptions are the unit of ownership and billing, and management groups mirror how the business is organized. That structure is exactly what a vulnerability program needs, and it already exists.
- Subscriptions map naturally to teams or environments, which is how findings should be assigned and reported.
- Management groups capture business units or platform boundaries, which is how security leads want to roll up risk.
- Tenants change constantly. Subscriptions get created for new projects and disabled when projects end, and a hand-built Asset list falls behind within weeks.
- Without a matching hierarchy, findings from cloud tools land on Assets that someone created ad hoc, with names that don't match the console.
Advantages of This Integration
What the Azure asset connector gives a DefectDojo Pro instance:
- An Asset for every active subscription. Enabled and Warned subscriptions are imported automatically, each named with the subscription name and ID.
- Management groups as Organizations. Each management group becomes an Asset and the Organization of everything directly beneath it, so reporting by business unit works from day one.
- A real hierarchy. The tenant root group, management groups, and subscriptions appear as an Asset hierarchy that matches the Azure portal.
- No duplicate Assets for Defender findings. Subscription Assets use the same name Microsoft Defender for Cloud uses, so findings from that connector land on the Asset this one created.
- Safe handling of removed subscriptions. A disabled or deleted subscription drops out of the next sync and its Record is marked MISSING. DefectDojo never deletes an Asset on its own.
- Tags carried over. Subscription tags are recorded on the Record in a TAGS attribute.
How This Integration Works
The Azure connector is available in DefectDojo Pro under Connect > Upstream. It authenticates with an Entra ID app registration and reads Azure Resource Manager.
1. Create an app registration. In the Azure portal, go to Microsoft Entra ID > App registrations > New registration and register an application for DefectDojo. On its Certificates & secrets page, create a client secret and copy the value. Note the Directory (tenant) ID and Application (client) ID from the Overview page.
2. Grant read access. Assign the app's service principal the built-in Reader role at the tenant root management group (Management groups > Tenant Root Group > Access control (IAM) > Add role assignment). Reader at the root covers every management group and subscription beneath it in one assignment.
3. Configure the connector. Keep the pre-filled Location URL, https://management.azure.com, unless you use a sovereign cloud, in which case enter that cloud's Resource Manager URL. Enter the Tenant ID, Client ID, and Client Secret. Leave Login URL blank unless you are on a sovereign cloud (for example https://login.microsoftonline.us).
4. Discover and Sync. With Auto-Map enabled, one Discover plus one Sync builds the whole Organization and Asset structure. With Auto-Map disabled, discovered subscriptions and management groups appear as Records waiting for you to map them.
If your organization will not grant Reader at the root management group, the connector still works. When it cannot read management groups, it logs a warning and imports a flat list of subscriptions with no hierarchy and no Organization grouping. Grant the root assignment later and the hierarchy appears on the next Discover.
Data Granularity: What Gets Mapped
This connector maps inventory, not vulnerabilities. Here is what it creates, per the connector documentation.
| DefectDojo Object | Source in Azure | Notes |
|---|---|---|
| Asset (subscription) | Subscription | Named with the subscription name and "Azure Subscription" plus the subscription ID |
| Asset (management group) | Management group | Named with the group name and "Azure Management Group" plus the group ID |
| Organization | Management group | Becomes the Organization of everything directly beneath it |
| Asset hierarchy | Management group tree | Tenant root group, then management group, then subscription |
| Record TAGS attribute | Subscription tags | Recorded on the Record |
| Record state | Subscription state | Only Enabled and Warned subscriptions are imported; removed ones become MISSING |
| Locations | Individual Azure resources | Virtual machines, App Services, AKS clusters, and storage accounts are not Assets; they arrive separately as Locations |
| Findings | None | Use a findings connector such as Microsoft Defender for Cloud alongside it |
Resource groups are not imported as an extra hierarchy level.
Use Cases
Running alongside Microsoft Defender for Cloud: A team enables the Azure connector first so every subscription already exists as an Asset in the right Organization. When the Defender for Cloud connector syncs, its findings land on those same Assets instead of creating duplicates with slightly different names.
Reporting by business unit: A tenant with management groups for retail, payments, and corporate IT ends up with matching Organizations in DefectDojo. Security leads can compare open Critical findings and SLA breaches by business unit without maintaining a mapping table.
Tracking subscription sprawl: New subscriptions created for short-lived projects appear on the next Discover. When a project ends and the subscription is disabled, its Record turns MISSING, which is a prompt to review and close out what is left rather than an automatic deletion.
Restricted environments: Where management group access is not available to security tooling, the connector imports a flat list of subscriptions. That still gives every subscription an Asset, and the hierarchy can be added later without remapping.
Operational Tips
- Grant Reader at the tenant root management group if you can. It is one assignment, and it is what turns a flat subscription list into Organizations and a hierarchy.
- Moving a subscription to a different management group in Azure does not move its Asset, because DefectDojo never overwrites an existing hierarchy edge. Re-map the Record to pick up the new parent.
- Renaming a subscription in Azure does not rename an Asset that is already mapped. The Record keeps the name it had at mapping time.
- Treat MISSING Records as a review queue. They usually mean a subscription was disabled or deleted, or that the app registration lost access.
- Turn on the Connector Health Warning notification so you hear about expired client secrets or lost visibility without watching the Upstream Connectors page.
- Sovereign clouds (US Gov, China) are untested in this version, so validate results carefully if you run in one.