Connecting Microsoft Azure subscriptions with IBM Guardium Exposure Manager

Connect one or more Microsoft™ Azure subscriptions with IBM® Guardium® Exposure Manager by running an Azure cloud shell script to discover sensitive data in the cloud accounts. The connection automatically creates the relevant service principals and Role-Based Access Control (RBAC) that are needed to facilitate the functioning of IBM Guardium Exposure Manager. For more information about the service principal, role, and resources created, see the Results section.

Before you begin

Verify that you have the following before you start the process of connecting your Azure subscriptions with IBM Guardium Exposure Manager:
  • List of the Azure subscriptions to be connected with IBM Guardium Exposure Manager
  • An Azure user with the permission to create the relevant service principals

For more information about the service principals, see App Registration with Service Principal.

About this task

Use the following steps to connect IBM Guardium Exposure Manager with one or more Microsoft Azure subscriptions.

Procedure

  1. From the main menu, click Management hub > Connections.
  2. On the Connections page, click Add connection.
  3. On the Add connection page, select Microsoft Azure, and then click Next.
  4. In the Add subscriptions step, provide the subscription details (Subscriptions ID, Subscriptions name, and Environment), and then click the plus icon.
    Note:
    • By default, the subscription that you add at first is tagged as the Primary account where the analyzer is deployed. To know more about the analyzer, see Analyzer.
    • If you want to add more than one cloud account, repeat step 4 as many times as required.
  5. After you have added all the subscriptions, click Next.
    If you click Cancel instead of Next, then you get the status message, Connection pending, signifying that the list of subscriptions is saved but none of the cloud accounts are connected successfully.
  6. In the Connect subscriptions step, follow the on-screen instructions to connect to the subscriptions that you have added, and then click Next.
    The Next button is enabled only after copy the Guardium Drive Analyzer ID.
    Note: If you click Cancel instead of Next, then you get either of the following status messages:
    • Connection pending, signifying that the list of subscriptions is saved but none of the subscriptions are connected successfully.
    • Progress saved, signifying that the list of subscriptions is saved but only a few of the subscriptions are connected successfully.
  7. In the Review progress step, monitor if the connections to the subscriptions that you have added are successful or failed, and then click Next.
    Note: If the connections to the subscriptions fail, you can try to connect the subscriptions again by following the instructions in the Connect subscriptions step.
  8. In the Authorize step, follow the on-screen instructions to establish the connection of the subscriptions that you have added, and then click Next.
  9. In the Enable Microsoft Purview step, toggle the Enable Microsoft Purview button, if required, and then click Next.
  10. In the Add regions step, follow the on-screen instructions to add regions for the subscriptions that you have added, and then click Done.
    Draft comment:
    Need to check note with Ruth/Assaf
    Note: If you click Cancel instead of Done, then you get one of the following status messages:
    • No regions added, signifying that you have not added any regions. You can click Add regions in the status message or you can add the regions later.
    • Regions partially added, signifying that you have added a few of the regions. You can add the other regions later.
    • All steps completed, signifying that you have completed all the steps successfully and all your data is saved.

Results

While you connect IBM Guardium Exposure Manager subscriptions, the following principal and role are created:
App Registration with Service Principal
The service principal scans and monitors the metadata of the data assets that are discovered by IBM Guardium Exposure Manager. It is a read-only role with some create permissions mainly for IBM Guardium Exposure Manager resources that are used for classification of data.
Analyzer Role
The analyzer role is aAzure managed read-only (Role Based Access Control) RBAC that has permissions to read data inside the customer’s data stores. Only a IBM Guardium Exposure Manager analyzer can access the data stores and the stored data in your cloud account. A standard_d2s_v3 instance type is used as the analyzer by IBM Guardium Exposure Manager.

For more information about the scope of permissions about the service principal and role, see Roles and permissions for Microsoft Azure accounts.

Resources installed after Microsoft Azure connection
Table 1. Resources installed
Resource name Resource type Installation type
polar_discovery_service_role_{dspmRegion} role-definition Installed on a non-main account
polar_update_helper_role_{dspmRegion} role-definition Installed on a non-main account
polar_helper_service_role_{dspmRegion} role-definition Installed on the main-account
polar-resources-{region}-{dspmRegion} resource-group Installed during adding a region
polar-vmss-{dspmRegion} virtual-machine-scale-set Installed during adding a region
IBM GI SaaS DSPM for Azure enterprise-application/service-principal Installed on the main-account
polsc{customerId} {region} {accountId} storage account Installed during the data classification process, if required
polarcontainersensitivities container Installed during the data classification process, if required
polar-file-share file-share Installed during the data classification process, if required
polar-vnet vnet Installed during adding a region
helper-autoscale-{region} autoscale Installed during adding a region
polkv{customerId} {region} {accountId} keyvault Installed during the data classification process, if required