Microsoft Azure logo

Microsoft Azure

AccessVulnerabilities
Cloud Provider

Mycroft tests your Azure subscriptions daily for RBAC assignments, encryption, network exposure, Key Vault configuration and log retention.

Azure estates spread across subscriptions faster than they are documented, and the control that fails is rarely the one being watched. Mycroft reads configuration at subscription or management group scope and ingests Defender for Cloud findings into the vulnerability queue.

How Mycroft connects to Microsoft Azure

How it connects
You register an application in Entra ID, grant it read access to the subscriptions you want covered, and give Mycroft the application (client) ID, directory (tenant) ID and a credential you issue.
What Mycroft can access
Read-only. Mycroft reads subscription configuration and role assignments through that application, and does not write back.

Which controls Microsoft Azure evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Microsoft Azure to satisfy it. Collection runs on a schedule and every result is timestamped.

Microsoft Azure compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Microsoft Azure
SOC 2CC6.1Logical access controls restrict access to information assets.Azure RBAC role assignments by scope, with Owner and Contributor holders enumerated and reconciled to current employees.
SOC 2CC6.6Access measures protect against threats from outside the system boundary.Network security group rules flagged for unrestricted inbound access; storage accounts allowing public blob access; public network access settings on SQL and Cosmos DB.
SOC 2CC7.1Monitoring detects configuration changes and vulnerabilities.Activity log diagnostic settings and retention; Microsoft Defender for Cloud enablement and its secure score findings with severity and age.
SOC 2CC7.2System components are monitored for anomalies indicative of security events.Defender for Cloud alert history with triage state, plus diagnostic settings proving log flow to a retained workspace.
ISO 27001A.5.23Information security for the use of cloud services is managed.Per-subscription configuration baseline covering encryption, logging, network exposure and privileged role assignment, re-tested daily.
ISO 27001A.8.24Cryptography is used effectively to protect information.Storage account and managed disk encryption state, TLS minimum version enforcement, and Key Vault soft-delete, purge protection and key expiry configuration.
ISO 27001A.8.8Technical vulnerabilities are identified and remediated.Defender for Cloud recommendations and vulnerability assessment findings, deduplicated with owner and time-to-remediate.
HIPAA§164.312(a)(1)Technical policies limit ePHI access to authorized persons.RBAC assignment inventory at every scope holding regulated workloads, with privileged role holders identified.
HIPAA§164.312(b)Audit controls record activity in systems containing ePHI.Activity log and resource diagnostic settings shown as enabled with retention meeting your documented period.

What Mycroft collects automatically

Gathered from Microsoft Azure on a schedule, dated and stored against the controls above.

  • Azure RBAC role assignments across subscriptions, resource groups and resources
  • Storage account encryption, secure-transfer enforcement, TLS minimum version and public blob access settings
  • Managed disk and SQL database encryption state, including transparent data encryption
  • Network security group rules with unrestricted inbound exposure highlighted
  • Key Vault configuration: soft delete, purge protection, key rotation and expiry
  • Activity log diagnostic settings and retention period
  • Microsoft Defender for Cloud enablement, secure score and open findings with age

Manual work this removes

The tasks that disappear from someone's quarter once Microsoft Azure is connected.

  • Screenshotting RBAC assignments subscription by subscription before each review
  • Maintaining a spreadsheet of which storage accounts allow public blob access
  • Exporting Defender for Cloud recommendations to show they were triaged
  • Reconciling role assignments against the leaver list each quarter
  • Identifying subscriptions that were never added to the review scope

Microsoft Azure and Mycroft: frequently asked questions

An Entra ID application registration. Mycroft stores the application (client) ID and directory (tenant) ID alongside a credential you issue, and you grant it read access to the subscriptions you want covered. It reads configuration and role assignments and does not write back.
Azure and Entra ID are connected separately, because they answer different questions. This integration covers subscription-level infrastructure: encryption, networking, logging and RBAC. The Entra ID integration covers identity: users, groups, MFA enforcement, conditional access and the workforce roster behind access reviews. Most teams connect both.
Read access granted at management group scope covers every subscription beneath it, including ones created later. Evidence is attributed per subscription so production and non-production estates stay distinguishable in your report.
Defender remains your detection engine; Mycroft consumes its output. Findings are ingested, deduplicated across subscriptions, given an owner and tracked to closure against your remediation SLA, turning a live recommendation list into the evidence that ISO 27001 A.8.8 and SOC 2 CC7.1 require.

We turn the compliance nightmare into a dream

Talk to us