Azure Plugin Overview
The Microsoft Azure® Plugin is a component of the Forescout Core Extensions Module.
The Azure Plugin connects to the Microsoft® Azure public cloud environment to retrieve information on Virtual Machine (VM) instances and other Azure entities, such as Virtual Networks (VNets). The VM instances and VNets follow rules similar to those of other endpoints discovered by Forescout eyeSight, where policies and actions can be defined on those entities. The integration of eyeSight with Azure brings the detailed visibility, control, and compliance capabilities of the to Azure VM instances and the associated Azure cloud configurations.
The Azure Plugin lets you:
- See VM instances and VNets in Microsoft Azure’s public cloud
- Create and apply Forescout policies across Azure entities
- Maintain the security and compliance of Azure VM instances and VNets
- Start and stop a VM instance, enable delete protection on a VM instance, and a range of other policy actions
This plugin assists IT with a number of important challenges when it comes to cloud operations. With the integration of eyeSight with Azure, you can:
- Have full visibility of your Azure VM instances and their properties. Since disparate teams may be starting and stopping VMs in a public cloud environment, it is important for all of IT to have a good understanding of the resources that are being used in the cloud. Regular checks provide valuable information on how and when Azure cloud resources are used.
- Use the Forescout Asset Inventory to review the distribution of endpoints in the cloud and mitigate them as required. For example, endpoints with public IP addresses are quickly identified for remediation.
- Enable delete protection for Azure VM instances to prevent accidental deletion of a VM, by establishing a policy in which all compliant and critical VM assets have delete protection enabled. For more information, see Run Azure Policy Actions.
- Collect information about the Azure environment across multiple Azure accounts and subscriptions, all from a common deployment. This includes fine grain details, such as the Azure Tags applied to a virtual machine, Azure VNet settings and routes, as well as the creation of new Subscriptions, and many other Azure operational details.
- Discover cloud-based endpoints early, allowing identification and compliance checking of the workload itself. A non-compliant endpoint can be stopped and/or the Azure account team can be notified. If remediation fails, the endpoint can be stopped to prevent further damage.
- Enable flow data to be extracted from network security group (NSG) flow logs and passed to
the Forescout eyeSegment Module so that you can view and leverage dynamic zone-to-zone
relationship mapping data, simplify segmentation planning, and automate ACL/VLAN assignment
to reduce your attack surface. The extracted data is also used for reporting internal
network device admissions to eyeSight. For more about
enabling flow data, see Add an Azure
Connection.Note: Flow data is only available for traffic that uses TCP or UDP protocols.
About Certification Compliance Mode
Forescout Hybrid Cloud Module: Microsoft Azure Plugin supports Certification Compliance mode. For information about this mode, refer to the "Certification Compliance" section of Security and Compliance and RMM" in the Forescout eyeSight Installation Guide.
How It Works
This plugin uses well-defined APIs from Azure to provide visibility into Azure VMs and VNets.
Once the configuration is completed using an Azure account with the appropriate credentials and permissions, eyeSight communicates with one or more Azure accounts. The Azure Plugin polls both running and non-running VMs on the Azure cloud and retrieves information on the VMs as well as the VNets under that account.
Instance-related properties are collected as Forescout host properties, while other cloud entities, such as VNets, are also displayed as logical endpoints in eyeSight. The query and collection of Azure entities and associated properties are invoked at configured time intervals.
Polling
Full polling, with an optional delta polling mechanism, supports continual updates of Azure properties. This ensures that Azure state changes are recognized in near real-time by eyeSight. The full poll gathers all aspects of the Azure environment from the Azure APIs. The Azure APIs expose multiple attributes of the entities associated with an Azure account.
Because this data can be quite extensive and there are certain API throttle limits in Azure, the full poll takes place at longer intervals (by default, every 120 minutes). The optional delta polling means that VM instance state changes are recognized immediately by eyeSight. The delta poll only looks for changes to VM instances, so it takes place at shorter intervals (by default, one minute intervals).
Best Practices for Integrating with Forescout eyeSegment
Before enabling this feature, it is recommended that you ensure that:
- The Appliance's time, date, and time zone settings are correct.
- A role is enabled that includes the Required Permissions for NSG Flow Log Collection. See Define Azure Users.
minute read