Microsoft Azure Subscription Provider

Enhanced Azure cloud topology modeling provides improved visibility and path analysis across virtual networks, native Azure components, and third-party security devices, enabling organizations to view cloud infrastructure as an extension of the enterprise network.

Because release 2026.2.3 introduces a new Azure cloud architecture model, customers upgrading to this feature release should be aware of the following operational changes:

  • Existing Azure device pack will be overwritten during the upgrade

  • Existing Azure-related cloud licensing will be removed as part of the transition

  • Updated licensing must be applied after the upgrade completion

Because cloud licensing usage may vary across environments, we recommend reviewing your Azure deployment and associated licensing with your FireMon account team or Customer Experience representative prior to upgrade planning.

Upgrade Procedure

  1. Starting from an older version prior to 2026.2.3 with Azure legacy device instances.

  2. Update to FMOS 2026.2.3

  3. Install a new license with appropriate VNET/VPC license.

  4. Relicense the cloud provider instances by navigating to Administration > Device > Management Stations.

  5. Select the Azure device, in the Action menu (. . .) select Retrieve Configuration.

Device Details

Support: Levels 1 - 5*. *Support policy for native firewalls, but not automation.

License: This device type requires a Cloud Network Segment (CNS) license.

Notes:

  • APA will route through Azure firewalls, but will not evaluate policy in 2026.2.3, this functionality is deferred until 2026.2.4.

  • Rule Recommendation will only returns NSG recommendations, no native firewall rules for Azure Firewall.

To add a Microsoft Azure Subscription Provider, complete the following steps.

Step 1: Configure the Device

FireMon strives to provide up-to-date product information, however we are not always aware when vendors change their device UI. If any Configure the Device procedure differs from your device version (UI location of fields, not information needed), please consult your device's user guide.
  1. Log on to Microsoft Azure portal.
  2. Copy the following to notepad: 
    • The Tenant ID. Microsoft Entra ID > Overview > Tenant ID.
  3. Register an application.
    1. Microsoft Entra ID > Manage > App registrations and click New registration.
    2. Enter a Name for the application.
    3. For Supported account types, select Single Tenant Only.
    4. Leave Redirect URL (optional) blank.
    5. Click Members tab.
    6. Click Register.
    7. Copy the Application (client) ID to notepad.
  4. Create a client secret.
    1. From the Manage menu, click Certificates & secrets.
    2. Click New client secret.
    3. Enter a Description for the client secret key.
    4. Select an Expires option from the list that meets your business standards.
    5. Click Add.
    6. Copy the data in the Value field to notepad.

Save the secret values before you leave the Certificates & secrets page. Once you leave the page, you will not be able to view the secret value again.

  1. Grant access from Microsoft Entra ID to Security Manager.
    1. Open the subscription.
    2. Click Access control (IAM).
    3. Click Add.
    4. For the Role field, select Reader.
    5. Leave the Assign access to field as is.
    6. In the Select field, find the name of your application (used in step 3).
    7. Click Save.
  2. Set a Proxy Server (optional).

Step 2: Onboard the Device in the Administration Module

Contact FireMon Support to receive a specific device pack (a .jar file) if it was not included in the FMOS GA release. Review the steps to upload a device pack.

After onboarding, if you change any device settings, confirm that those updates were automatically applied to the discovered devices.
  1. On the toolbar, click Device > Management Stations.
  2. Click Create, and then click Microsoft > Azure Subscription Provider.
  1. Complete the General Properties section.
  1. In the Name box, type the name of the device as you want to see it in SIP.
  2. In the Description box, type an optional description of the device being added.
  3. The Management IP Address box can be left blank.

    A Management IP Address is not needed, however assigning an arbitrary, but unique IP is suggested. For example, 0.0.0.0 or 1.1.1.1 with an incremental increase for each similar vendor management station used (0.0.0.0, 0.0.0.1, 0.0.0.2, etc.). If you don't enter an IP address, logs about the device are sent to a specific directory that is named after the device ID. If you have the IP address in the system it will be used to name the directory, which makes it easier for support to find. For example, a non-IP address device would have a directory with domain_deviceID (example: 1_61).

  1. In the Data Collector box, type the IP address of the data collector that will collect data from this device.
  2. In the Central Syslog Server box, type the syslog server from the list (optional).

Syslog fields are optional if the device uses the same IP for syslog and management.
A central syslog server is required only if syslog messages come from a different IP. A central syslog server must be created before it can be assigned to a device. To track usage via syslog, the device must support Level 3+.

  1. In the Syslog Match Names box, type the syslog match names (optional). You can enter multiple names separated by a comma.
  2. By default, the Automatically Retrieve Configuration checkbox is selected.
  3. In the External ID box, type a unique identifier to be used when the device identifier is different than what is displayed in SIP.
  4. For Collection Configuration, enable Update Rule Documentation on Member Devices to allow Rule Documentation fields on member devices to inherit a value from the management station. Any management stations Rule Documentation field updates will override updates on the member device. A rule marked to be removed will not be updated.
  1. Device Settings section.

    Credentials

  1. Enter the Tenant ID in the TSG ID field.
  2. Enter the Application (client) ID copied from the new registration in the Client ID field.
  3. Enter the client secret value copied from the Certificates & secrets page in the Client Secret field, and then enter it again.
  4. Enter an Alternate Subscription ID for Hit Count Retrievals if the NSGs in this subscription log to a storage account with a different Subscription ID. If set, this setting will populate to all discovered devices. Leave this field blank to set it individually on child devices, if different on a per-device basis.

    Proxy

  1. Enter the Proxy Server.
  2. Enter the Proxy Username.
  3. Enter the Proxy Password, and then enter it again.
  1. Monitoring section.

Log Monitoring

Select the Enable Log Monitoring checkbox to use for Rule Usage Analysis.

  • Track Usage Via is set to Syslog.
  • Log Update Interval is set to 10 (minutes); this number determines how often usage data is sent to the application server.
  1. Retrieval section.

Scheduled Retrieval

Select the Enable Scheduled Retrieval checkbox to perform a retrieval at a set time regardless of change detection. This will activate additional fields to complete.

  • Set the Scheduled Retrieval Time to fit your requirements.

  • Choose a Scheduled Retrieval Time Zone from the list.

Check for Change Retrieval

Select the Enable Check for Change checkbox to check for configuration changes after the specified interval and perform a retrieval if changes are detected. This will activate an additional field to complete.

  • The default Check for Change Interval time is 1440 minutes (every 24 hours). You can change the check interval time to best fit your requirements. The minimum required interval is 60 minutes (1 hour).

  1. Advanced section.
  • Retrieval options:
    • The NTP Server will be used to check for clock offset if Azure rejects the device credentials. Leaving this setting blank disables this check.
    • Use the Retrieval Timeout in Seconds field to set a maximum time to wait for a response during retrieval.
    • Select the Use Azure China Endpoint checkbox to enable retrievals for Azure China users. Azure China differs from Azure global.
  • Azure Element Discovery: In the Asset Exclusions field, enter an asset that will not be created for virtual machines with source image plan names matching this list. Enter one asset per field. Click the + plus icon to add additional assets.
  • Granular Changes: Select the Retrieve Granular Change Log checkbox to read logs from disk. This may cause extended retrieval time and high CPU usage on the device.
  1. Click Save.
Devices being managed will be listed in the Discovered Devices section. Click Device Details to open Security Manager to view more details about these managed devices.