Integration Guides

Azure Resource Graph

24min
overview azure resource graph is the functionality inside of the azure portal that provides visibility across your cloud resources background shi has developed a multi cloud governance framework to help organizations achieve governance at scale and accelerate cloud usage in a controlled, secure, compliant, and consistent way the shi cloud governance framework is built upon a set of industry best practices, standards, frameworks, and benchmarks the shi cloud governance framework can be applied regardless of your maturity, if you’re new to the cloud, or are an existing cloud customer getting started prerequisites the following prerequisites must be met to utilize the shi one azure resource graph integration an active subscription in microsoft azure the individual performing the steps below must be an owner to the subscription being delegated if you are a global admin in azure, you can also add yourself as an owner to be able to complete the following steps note that azure govcloud is not supported in shi one note that azure web direct subscriptions (a k a microsoft online subscription program \[mosp]) are not fully supported in shi one web direct subscriptions in shi one will not display cost reporting or consumption data web direct subscriptions in shi one will display data for recommendations and/or security & compliance along with resource graph data if you have set up those integrations this is due to configuration parameters on microsoft's end which prevent full access to web direct subscription data azure subscription types can sometimes be changed; reach out to a microsoft or azure team and ask if it is possible to change your web direct subscription to a different subscription type azure resource graph overview azure resource graph is an azure service designed to extend azure resource management by providing efficient and performant resource exploration with the ability to query at scale across a given set of subscriptions so that you can effectively govern your environment enable azure resource graph azure resource graph is enabled on all active azure subscriptions by default click the following link to visit your azure resource graph explorer https //portal azure com/#blade/hubsextension/argqueryblade https //portal azure com/#blade/hubsextension/argqueryblade pricing azure resource graph is available at no additional cost references overview https //azure microsoft com/en us/get started/azure portal/resource graph https //azure microsoft com/en us/get started/azure portal/resource graph shi one integration overview once shi one azure resource graph is enabled, findings from azure resource graph will be visible from within the shi one asset inventory the following section describes the necessary configuration to integrate your azure resource graph into shi one and details the permissions necessary to ensure the proper functionality of the azure resource graph integration to utilize the azure resource graph integration to its fullest capabilities, an azure marketplace managed service offer must be deployed to every azure subscription participating in the integration with shi one enable shi one integration for customers with multiple subscriptions, the following process can be performed on your primary management azure subscription activate shi cloud governance framework azure marketplace offer prerequisites the individual performing the steps below must be an admin in shi one the individual performing the following steps must be an owner of the subscription being delegated if you are a global admin in azure, you can add yourself as an owner to be able to complete the following steps the microsoft managedservices resource provider must be registered prior to each subscription(s) onboarded the azure marketplace application is only added once per tenant validate that the microsoft managedservices resource provider is registered the microsoft managedservices resource provider must be registered for the subscription(s) being onboarded log in to the azure portal with an account that has the owner role assigned to the subscription navigate to the subscriptions blade and select the subscription being onboarded https //portal azure com/#blade/microsoft azure billing/subscriptionsblade https //portal azure com/#blade/microsoft azure billing/subscriptionsblade click resource providers type microsoft managedservices ensure the microsoft managedservices resource provider is registered; if not, register the resource provider please note this may take 10 15 minutes step by step process log in to the azure portal with an account that has the owner role assigned to the subscription browse to https //azuremarketplace microsoft com/en us/marketplace/apps/shiinternationalcorp shi vigilant cloud?tab=overview https //azuremarketplace microsoft com/en us/marketplace/apps/shiinternationalcorp shi vigilant cloud?tab=overview note this link takes you directly to shi’s cloud governance framework offer for azure; you can also find this offer via the azure marketplace or by adding an offer manually to the “service providers” area within your azure portal select your primary azure subscription for deployment select the region to run the deployment the deployment must be run in one region but it is a global association to the subscription; we recommend using your most common region click review + create check the confirmation box important if your create button is not highlighted there is a bug on this page with some browsers if the create button does not highlight after the box is checked, click the previous button then click next review + create all previously entered information should be retained and the create button should now be highlighted click create you will be redirected to an azure deployment status page; after the deployment is completed, you will see a link to complete the final step of the configuration click give your partner access to your subscriptions or resource groups for the service provider, select shi for the name, select shi cloud governance framework (standard) click delegate subscriptions select all applicable subscriptions and click delegate resources check the confirmation box click delegate you will receive a confirmation message in your azure notifications when the deployment is complete if there are any errors, please follow up with the shi resource that provided this documentation note that it takes azure up to 48 hours to grant shi one access removing existing delegations when updating the application, you may receive an error message such as the following another registration assignment present at this scope {} multiple registration assignments are not allowed if that is the case, remove the existing delegations first before installing the application log in to the azure portal with an account that has the owner role assigned to the subscription navigate to service providers blade by searching for “service providers” select service provider offers from the left navigation select the item shi cloud governance framework (standard) click delete submit a support request in shi one to map the subscriptions in shi one, navigate to support center > new request > service request for contract, select azure for issue type, select azure account management for issue sub type, select add manage account/subscription in the subject box, write " azure tenant id/subscription mapping request " in the description box, include every azure tenant id/subscription click submit the support team will inform you when the mapping process is complete; you can check the status of your ticket at support center > requests verify the integration in shi one once the support team has confirmed that the mapping process is complete, navigate to settings > integrations verify that the slider on the right of each azure integration box is orange/activated click on every azure integration box to verify that every subscription's slider is orange/activated note that it takes azure up to 48 hours to start sending data to shi one troubleshooting my subscription has an hourglass icon next to it the hourglass icon appears when azure has not yet sent data to shi one it can take up to 48 hours after activating a subscription for azure to start sending data to shi one if it has been more than 48 hours since activating a subscription and the hourglass icon is still there, you can submit a support request for shi to manually request data from azure on your behalf perform the following steps in shi one, navigate to support center > new request > service request for contract, select azure for cloud account, select the affected subscription for issue type, select azure account management for issue sub type, select subscription management in the subject box, write " azure subscription manual sync request " in the description box, include the name and id of every azure subscription that has an hourglass icon next to it and include screenshots if possible click submit the support team will inform you when the manual sync has been performed; you can check the status of your support request at support center > requests my subscription has a red exclamation mark next to it the red exclamation mark appears when there is an error with a subscription subscriptions in error are displayed with a message below explaining the nature of the error because there are many error causes and possibilities, there is no way to list all potential methods of rectifying an error often the fastest method is to deactivate the affected subscription(s) and then perform this document's delegation process again if that doesn't solve the problem, submit a support request in shi one; make sure to include the name and id of every subscription in error and include screenshots if possible