Connecting Microsoft Azure subscriptions with IBM Guardium Exposure Manager
Connect one or more Microsoft™ Azure subscriptions with IBM® Guardium® Exposure Manager by running an Azure cloud shell script to discover sensitive data in the cloud accounts. The connection automatically creates the relevant service principals and Role-Based Access Control (RBAC) that are needed to facilitate the functioning of IBM Guardium Exposure Manager. For more information about the service principal, role, and resources created, see the Results section.
Before you begin
- List of the Azure subscriptions to be connected with IBM Guardium Exposure Manager
- An Azure user with the permission to create the relevant service principals
For more information about the service principals, see App Registration with Service Principal.
About this task
Use the following steps to connect IBM Guardium Exposure Manager with one or more Microsoft Azure subscriptions.
Procedure
Results
- App Registration with Service Principal
- The service principal scans and monitors the metadata of the data assets that are discovered by IBM Guardium Exposure Manager. It is a read-only role with some create permissions mainly for IBM Guardium Exposure Manager resources that are used for classification of data.
- Analyzer Role
- The analyzer role is aAzure managed read-only (Role Based Access Control) RBAC that has permissions to read data inside the customer’s data stores. Only a IBM Guardium Exposure Manager analyzer can access the data stores and the stored data in your cloud account. A standard_d2s_v3 instance type is used as the analyzer by IBM Guardium Exposure Manager.
For more information about the scope of permissions about the service principal and role, see Roles and permissions for Microsoft Azure accounts.
| Resource name | Resource type | Installation type |
|---|---|---|
| polar_discovery_service_role_{dspmRegion} | role-definition | Installed on a non-main account |
| polar_update_helper_role_{dspmRegion} | role-definition | Installed on a non-main account |
| polar_helper_service_role_{dspmRegion} | role-definition | Installed on the main-account |
| polar-resources-{region}-{dspmRegion} | resource-group | Installed during adding a region |
| polar-vmss-{dspmRegion} | virtual-machine-scale-set | Installed during adding a region |
| IBM GI SaaS DSPM for Azure | enterprise-application/service-principal | Installed on the main-account |
| polsc{customerId} {region} {accountId} | storage account | Installed during the data classification process, if required |
| polarcontainersensitivities | container | Installed during the data classification process, if required |
| polar-file-share | file-share | Installed during the data classification process, if required |
| polar-vnet | vnet | Installed during adding a region |
| helper-autoscale-{region} | autoscale | Installed during adding a region |
| polkv{customerId} {region} {accountId} | keyvault | Installed during the data classification process, if required |
Need to check note with Ruth/Assaf