InsightVM Azure Discovery Integration

Hello Everyone,

I’ve successfully integrated InsightVM with Azure, and the status of the connection shows as “Connected” on the Discovery Connections page. However, when I attempt to create a new site and choose “Discovery” as the method to populate the site with assets, the dropdown only shows “Sonar” as an option. The newly created Azure discovery connection does not appear.

Has anyone encountered this issue before? Is there a specific configuration step I might be missing to make the Azure connection available during site creation?

Any guidance or suggestions would be greatly appreciated!

1 Like

I’ve created an Azure site for scanning. I understand where you’re coming from.

You actually want to make the Site as a Static site, and then you point your discovery connection to that site, you don’t manage it from the site perspective like you would with a vsphere or AWS discovery site.

After you make a site that you want the assets to be updated in from Azure, you go to the Discovery Connection for Azure where you’ve selected “Microsoft Azure” as the connection, filled out the appropriate information for your Azure Application, and then make sure under the “consumption settings” you select the Rapid7 Site you want the assets to be updated into.

Hopefully this helps.

Hello @KrisRosson ,

Thank you so much for your reply. I tried that option that as well, but it didn’t work.

  1. Created a new static site, select the populate asset method type as IP or host name.
    2)In the discovery connection for Azure section, I manually selected the newly created static site.

Still, the count of virtual machines discovered is 0 in the Discovery Events page.

I don’t think they will show up under Discovery Events. Mine don’t.

Are you scanning into Azure from on-prem scanners by chance? That’s how my setup is.

In the Azure Discovery Connection settings, did you happen to check “Scan Engine is inside Azure”?

I know that when I didn’t check that box, I wasn’t getting assets imported into the scan site I had set up.

The scan site that you have the Azure connection pointed to will auto-append IP addresses on a regular basis. Have you checked the “assets” section of the scan site to see if there is anything in there by chance?

Just trying to share my experience and the quirks I’ve run into to hopefully help you move forward on this.

Thanks,

Kris