Azure Management Group Discovery

Satya5
Tera Contributor

Hi Folks,

Greetings.

we are on a Journey of Implementing Cloud discovery in our Organisation.

I need clarity on the below queries

1.WE have a couple of Azure  Management Groups which consists of 1000 of subscription, need advice on how to segregate and run discovery on this cloud sub-account will be much appreciated any automation can be used to track all account discovery status or please suggest the ways you have followed in your organization (We are not targeting ip based discovery at this moment).

2. We get a lead time of 24 hours in a week to run all our discoveries so we want to manage the discovery of all cloud resources in that time. server resources or of no concern we can build multiple mid server.

3.Is there a way to automatically update the changes in cloud data back to CMDB on-demand basis.

4. Any folks who have implemented the cloud discovery please provide your experiences, do's, do not's and lessons learned which will help us.

Thanks all for your support.

Regards

Satya

 

 

 

17 REPLIES 17

Pritesh-TechM
Tera Contributor

Hello @Ram Devanathan1 ,

 

We are having requirement of azure cloud discovery and there are 100+ subscriptions present in customer network.

So, instead of configuring each subscription ID in servicenow Service accounts we are trying to configure the single "Management group ID''.

So, can you please specify how will it proceed ?

Do we needed anything else to discover the all subscription IDs ?

no nothing more is needed, add the subscriptions into your mgmt group and setup discovery schedule as detailed above. you need to do this within the cloud discovery workspace ui. the app is in store, free for all discovery entitled customers.

@Ram Devanathan1 ,

 

Please confirm my understanding, when management group ID is configured instead of subscription ID in Service Account, will it directly discover the subscription IDs contained in that management group & then DataCenters and then VMs  ?

Where it can be visible ?

hi Pritesh - yes this is the approach to have discovery run en masse for all subscriptions. this is not a new feature, it has been around a while. all discovered resources are stored in cmdb as normal.

 

Thank you @Ram Devanathan1 

 

Just last doubt, please have a look.

As per docs, it mentioned that "To manage multiple subscriptions, we must assign "Reader" role to each subscription". We just want to know can we assign "Reader" role to management group at azure end or we have to follow the steps which mentioned in ServiceNow Docs for subscription IDs ?