Auto Checks Integration Guide for Azure
Important:
You must have admin rights in your Google Cloud environment to complete the setup.
Without sufficient permissions, you won’t be able to assign the necessary roles, enable APIs, or create service accounts.
Why reconfigure?
Since the launch of the Auto Checks feature on June 10th, 2025, Kertos requires additional permissions in your Azure environment.
These permissions go beyond the original Azure integration setup. Without them, Auto Checks cannot scan and validate your cloud configurations against compliance controls.
First Time Setting Up Azure Integration?
If you haven't yet integrated Azure with Kertos, follow our full step-by-step onboarding guide here:
https://docs.kertos.io/en/article/discovery-setup-azure
Permissions Required
To enable Auto Checks, follow the steps below to grant the required permissions in your Azure environment.
Step 1: Add API Permissions
- Open the App Registrations in Azure Portal
- Select your existing Kertos app
- Go to Manage → API Permissions
- Click Add a permission → Select Microsoft Graph
- Choose Application permissions, then add:
Domain.Read.All
Policy.Read.All
UserAuthenticationMethod.Read.All
Step 2: Assign Reader Role to the App
- Open the Subscriptions page in Azure Portal
- Select the subscription that contains your cloud assets
- Copy the Subscription ID and enter it into Kertos
- Go to Access control (IAM)
- Click Add → Add role assignment
- Select the Reader role
- Click Next, then Select members
- Search for and select your app (e.g., "Kertos")
- Click Review + Assign to complete the setup
Once this is complete, don’t forget to enable the "Auto Checks" toggle and run a sync in Kertos.