Azure Connector
The Azure connector connects with your Microsoft Azure account to perform the following high-level functions:
-
Automated ingestion of inventory (and its tags) live from your Azure virtual networks (VNets) Azure allows you to assign metadata to your resources in the form of tags. Secure Workload can ingest the tags associated with virtual machines and network interfaces, which can then be used as labels in Secure Workload for inventory and traffic flow data visualization and policy definitions. This metadata is synchronized constantly.
The tags from workloads and network interfaces of the subscription associated with the connector are ingested. If both workloads and network interfaces are configured, the tags are merged and displayed in Secure Workload. For more information, see Labels Generated by Cloud Connectors.
-
Ingestion of flow logs The connector can ingest flow logs that you set up in Azure . You can then use the telemetry data in Secure Workload to generate visualization and segmentation policy.
-
Segmentation When enforcement of the segmentation policy is enabled for a virtual network, Secure Workload policies will be enforced using Azure's native Network Security Groups.
-
Automated ingestion of metadata from AKS clusters When Azure Kubernetes Services are running on Azure, you can choose to gather all the node, service, and pod metadata related to all the selected Kubernetes clusters.
You can choose which of the above capabilities to enable for each VNet.
Azure connector supports multiple subscriptions.