Azure Plugin Overview

The Microsoft Azure® Plugin is a component of the Forescout Core Extensions Module.

The Azure Plugin connects to the Microsoft® Azure public cloud environment to retrieve information on Virtual Machine (VM) instances and other Azure entities, such as Virtual Networks (VNets). The VM instances and VNets follow rules similar to those of other endpoints discovered by Forescout eyeSight, where policies and actions can be defined on those entities. The integration of eyeSight with Azure brings the detailed visibility, control, and compliance capabilities of the to Azure VM instances and the associated Azure cloud configurations.

The Azure Plugin lets you:

  • See VM instances and VNets in Microsoft Azure’s public cloud
  • Create and apply Forescout policies across Azure entities
  • Maintain the security and compliance of Azure VM instances and VNets
  • Start and stop a VM instance, enable delete protection on a VM instance, and a range of other policy actions
Note: In this guide, the terms “endpoint” and “instances” are used interchangeably.

This plugin assists IT with a number of important challenges when it comes to cloud operations. With the integration of eyeSight with Azure, you can:

  • Have full visibility of your Azure VM instances and their properties. Since disparate teams may be starting and stopping VMs in a public cloud environment, it is important for all of IT to have a good understanding of the resources that are being used in the cloud. Regular checks provide valuable information on how and when Azure cloud resources are used.
  • Use the Forescout Asset Inventory to review the distribution of endpoints in the cloud and mitigate them as required. For example, endpoints with public IP addresses are quickly identified for remediation.
  • Enable delete protection for Azure VM instances to prevent accidental deletion of a VM, by establishing a policy in which all compliant and critical VM assets have delete protection enabled. For more information, see Run Azure Policy Actions.
  • Collect information about the Azure environment across multiple Azure accounts and subscriptions, all from a common deployment. This includes fine grain details, such as the Azure Tags applied to a virtual machine, Azure VNet settings and routes, as well as the creation of new Subscriptions, and many other Azure operational details.
  • Discover cloud-based endpoints early, allowing identification and compliance checking of the workload itself. A non-compliant endpoint can be stopped and/or the Azure account team can be notified. If remediation fails, the endpoint can be stopped to prevent further damage.
  • Enable flow data to be extracted from network security group (NSG) flow logs and passed to the Forescout eyeSegment Module so that you can view and leverage dynamic zone-to-zone relationship mapping data, simplify segmentation planning, and automate ACL/VLAN assignment to reduce your attack surface. The extracted data is also used for reporting internal network device admissions to eyeSight. For more about enabling flow data, see Add an Azure Connection.
    Note: Flow data is only available for traffic that uses TCP or UDP protocols.

About Certification Compliance Mode

Forescout Hybrid Cloud Module: Microsoft Azure Plugin supports Certification Compliance mode. For information about this mode, refer to the "Certification Compliance" section of Security and Compliance and RMM" in the Forescout eyeSight Installation Guide.

How It Works

This plugin uses well-defined APIs from Azure to provide visibility into Azure VMs and VNets.

Once the configuration is completed using an Azure account with the appropriate credentials and permissions, eyeSight communicates with one or more Azure accounts. The Azure Plugin polls both running and non-running VMs on the Azure cloud and retrieves information on the VMs as well as the VNets under that account.

Instance-related properties are collected as Forescout host properties, while other cloud entities, such as VNets, are also displayed as logical endpoints in eyeSight. The query and collection of Azure entities and associated properties are invoked at configured time intervals.

Note: Azure classic resources (VM and VNet) are not supported. For details, refer to https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-manager-deployment-model

Polling

Full polling, with an optional delta polling mechanism, supports continual updates of Azure properties. This ensures that Azure state changes are recognized in near real-time by eyeSight. The full poll gathers all aspects of the Azure environment from the Azure APIs. The Azure APIs expose multiple attributes of the entities associated with an Azure account.

Because this data can be quite extensive and there are certain API throttle limits in Azure, the full poll takes place at longer intervals (by default, every 120 minutes). The optional delta polling means that VM instance state changes are recognized immediately by eyeSight. The delta poll only looks for changes to VM instances, so it takes place at shorter intervals (by default, one minute intervals).

Best Practices for Integrating with Forescout eyeSegment

Before enabling this feature, it is recommended that you ensure that:

  • The Appliance's time, date, and time zone settings are correct.
  • A role is enabled that includes the Required Permissions for NSG Flow Log Collection. See Define Azure Users.

Note: We recommend that you run Appliances in the cloud, and not on-premises, for cloud endpoints and for flows that are part of the eyeSegment deployment. The cost of pulling flow data from Azure to eyeSegment is likely to be higher for on-premises Appliances than for Appliances in the cloud.