Configure Azure provider
Authentication of Azure provider
To use iac describe
, set up credentials to make authenticated requests to your Azure account. Snyk retrieves configuration information from environment variables.
For a guide to configuring Azure authentication, see the Terraform documentation.
You can also authenticate using the az CLI. Then you must specify only the AZURE_SUBSCRIPTION_ID
:
Least privilege policy
The iac describe
command needs read-only access to your account. If you want to scan your whole Azure account, set up the Reader role on your subscription, as shown in the following screenshot.
data:image/s3,"s3://crabby-images/d08d5/d08d52d8defc70dd440e94a804b1f18fafb480eb" alt="Set up Reader role for the Azure provider"
You may want to scan only a resource group; you can assign the Reader role only on some restricted resource groups.
Last updated
Was this helpful?