<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Manual Azure Onboarding Fail in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/manual-azure-onboarding-fail/m-p/560028#M1067</link>
    <description>&lt;P&gt;HI,&lt;BR /&gt;after carrying out all the steps reported in the official guide, Azure onboarding fails.&lt;BR /&gt;Part of the error is as follows:&lt;BR /&gt;Prisma Cloud application is not assigned following action(s): ["Microsoft.Logic/integrationAccounts/read", "Microsoft.Insights/actionGroups/read", "Microsoft.Network/networkSecurityGroups/read", "Microsoft.RecoveryServices/Vaults/ read", "Microsoft.Sql/servers/administrators/read", "Microsoft.Network/networkSecurityGroups/securityRules/read", "Microsoft.Authorization/classicAdministrators/read", "Microsoft.Network/networkWatchers/securityGroupView/action", " Microsoft.Quantum/Workspaces/Read", "Microsoft.StorageSync/storageSyncServices/privateLinkResources/read", "Microsoft.Sql/servers/databases/transparentDataEncryption/read"&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If I use the terraform script instead, everything works correctly.&lt;BR /&gt;In the manual procedure I also tried to use the custom role, which creates the terraform script where there are all the permissions inside (including those above)&lt;/P&gt;
&lt;P&gt;What can I do to understand the problem on Azure?&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;Dario&lt;/P&gt;</description>
    <pubDate>Fri, 29 Sep 2023 12:31:37 GMT</pubDate>
    <dc:creator>DSarnelli</dc:creator>
    <dc:date>2023-09-29T12:31:37Z</dc:date>
    <item>
      <title>Manual Azure Onboarding Fail</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/manual-azure-onboarding-fail/m-p/560028#M1067</link>
      <description>&lt;P&gt;HI,&lt;BR /&gt;after carrying out all the steps reported in the official guide, Azure onboarding fails.&lt;BR /&gt;Part of the error is as follows:&lt;BR /&gt;Prisma Cloud application is not assigned following action(s): ["Microsoft.Logic/integrationAccounts/read", "Microsoft.Insights/actionGroups/read", "Microsoft.Network/networkSecurityGroups/read", "Microsoft.RecoveryServices/Vaults/ read", "Microsoft.Sql/servers/administrators/read", "Microsoft.Network/networkSecurityGroups/securityRules/read", "Microsoft.Authorization/classicAdministrators/read", "Microsoft.Network/networkWatchers/securityGroupView/action", " Microsoft.Quantum/Workspaces/Read", "Microsoft.StorageSync/storageSyncServices/privateLinkResources/read", "Microsoft.Sql/servers/databases/transparentDataEncryption/read"&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If I use the terraform script instead, everything works correctly.&lt;BR /&gt;In the manual procedure I also tried to use the custom role, which creates the terraform script where there are all the permissions inside (including those above)&lt;/P&gt;
&lt;P&gt;What can I do to understand the problem on Azure?&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;Dario&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 12:31:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/manual-azure-onboarding-fail/m-p/560028#M1067</guid>
      <dc:creator>DSarnelli</dc:creator>
      <dc:date>2023-09-29T12:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: Manual Azure Onboarding Fail</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/manual-azure-onboarding-fail/m-p/560979#M1075</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A id="link_9" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/319377" target="_self" aria-label="View Profile of DSarnelli"&gt;&lt;SPAN class=""&gt;DSarnelli&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prisma Cloud allows you to add an Azure permissions Manually or via Terraform Script.&lt;/P&gt;
&lt;P&gt;One thing to keep in mind, if you do add permissions manually, please note that if the Cloud account onboarded is a Subscription. You would need to add the permission at the Subscription level (IAM).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you onboarded a Azure Tenant, the permissions would need to be added ad the Tenant Root Group (IAM). So even if the Prisma App contains the permissions at the Subscription level. You will still see missing permission as these permissions need to bee added at the Tenant Root Group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 18:52:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/manual-azure-onboarding-fail/m-p/560979#M1075</guid>
      <dc:creator>BCastillo</dc:creator>
      <dc:date>2023-10-09T18:52:32Z</dc:date>
    </item>
  </channel>
</rss>

