---
sourceDocument: Brazil IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Discovery for Microsoft Azure

# Discovery for Microsoft Azure {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Discovery for Microsoft Azure

This content explains how ServiceNow Discovery integrates with Microsoft Azure to identify and map cloud resources.
It guides customers on setting up Azure credentials, managing subscriptions via management groups, and leveraging Service Mapping for service instance discovery.
Show full answer Show less  

## Key Features

* **Azure Service Principal Setup:** Create a service principal in Azure to grant the MID Server permissions for accessing Azure resources. Credentials such as Tenant ID, Client ID, Secret Key, and Account ID are sourced from Azure Active Directory and subscriptions.
* **Management Groups and Subscriptions:** Azure management groups organize subscriptions hierarchically. Discovery can dynamically retrieve sub-account subscriptions using credentials from the management group, eliminating the need for individual credential management per subscription.
* **Credential Handling:** Discovery automatically acquires temporary credentials for each subscription sub-account via Azure APIs, supporting both default and customized MID Server role assumptions for enhanced control and security.
* **Discovery Pattern Permissions:** Customers should download and review the Cloud Discovery patterns spreadsheet to ensure appropriate REST API permissions are granted for running discovery patterns and stay updated with quarterly pattern releases.
* **Service Mapping Integration:** Enables inclusion of discovered Azure components into service maps through tag-based discovery. Preconfigured CI relationships facilitate mapping of cloud resources such as logical datacenters, cloud service accounts, and hosted virtual machines.

## Key Outcomes

* Efficient discovery and inventory of Azure cloud resources, including virtual machines, storage volumes, networks, and load balancers.
* Automated credential management simplifies large-scale Azure environment discovery across multiple subscriptions.
* Improved visibility into cloud infrastructure through integration with Service Mapping's tag-based discovery, supporting service instance mapping and operational insights.
* Comprehensive mapping of Azure resources to ServiceNow Configuration Items (CIs) with detailed attribute alignment for accurate CMDB population.

## Practical Guidance for Customers

* Establish the Azure service principal and input credential values correctly within ServiceNow to enable MID Server access.
* Leverage management groups to manage subscription discovery efficiently and test account connectivity before scheduling discovery.
* Periodically update discovery patterns and permissions to maintain compatibility and coverage of new Azure features.
* Use Service Mapping's CI relationships to enhance service instance visibility by linking discovered Azure resources.  
If your cloud resources are in an Azure cloud, you must create a user identity
called a service principal that grants permissions to the MID Server to access selected
resources.

## Azure management groups and subscriptions {#azure-cloud-discovery__section_zsr_zbb_kmb}

An Azure management group contains other management groups and subscriptions. The management groups in an Azure Cloud environment form a hierarchy, but
don't contain volumes or virtual
machines. Subscriptions contain cloud resources, such as virtual machines. The subscriptions that belong to management groups are called sub-accounts.

The advantages of using management groups are:

Easy population of sub-accounts

After you configure the management group and supply the necessary credentials, you can test the account. If the test succeeds, Discovery returns a list of subscriptions in that management group. From this list, you can choose
one or more subscription sub-accounts to include in the Discovery schedule using the management group. For more information on
the hierarchy of management groups and subscriptions, see [Organize your resources with Azure management groups](https://docs.microsoft.com/en-us/azure/governance/management-groups/overview)

Discovery of sub-account resources using dynamically acquired credentials

When you run Discovery on your subscriptions, you do not need separate credentials for each sub-account. Discovery finds the credentials for the management group and maps them to all of the subscription sub-accounts. The Cloud
Discovery process handles credentials automatically by acquiring a temporary credential for each sub-account via an Azure API. You can elect to use the default configuration or customize the MID Server to assume other roles for
additional controls and security. In addition, Discovery can automatically refresh the list of sub-accounts and datacenters
covered in a discovery schedule. For more information, see the KB article [Retrieve newer accounts/sub-accounts automatically via Cloud Discovery.](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0961449)
A service principal for Azure cloud services is similar to a Microsoft
Windows service account that enables Windows processes to communicate with each other within an Active Directory domain.  
To create the Azure service principal in your ServiceNow instance, copy the service principal credential values from the Azure portal into a text editor, and then transfer those values into the instance. Figure 1. The text file that you generate during this procedure  
This table shows you the Azure Service Principal value and the location in Azure where you can find the values you need for the credentials.{#azure-cloud-discovery__table_kpc_svh_wjb__entry__3}

| Cloud Provisioning and Governance setting | Azure Service Principal value | Location of the Azure value |
|-|-|-|
| Tenant ID | Azure Directory ID value from the text file. | Azure Active DirectoryPropertiesDirectory ID |
| Client ID | Azure Application ID value from the text file. | Azure Active DirectoryApp registrationsRegistered App.Application ID |
| Secret Key | Azure Application key value from the text file. | Azure Active DirectoryApp registrationsRegistered AppSettingsKeys (hidden) |
| Account ID | Azure Subscription ID associated with the Tenant ID. | Azure Active DirectorySubscriptionsSubscription ID |
[ ]

{#azure-cloud-discovery__table_kpc_svh_wjb}

## Verify the REST API permissions {#azure-cloud-discovery__id_ppz_r33_ydc}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#azure-cloud-discovery__cloud-discovery-api-ph-short-prereq}

## Data collected by Service Mapping during top-down discovery {#azure-cloud-discovery__section_mtq_nbg_ppb}

To include discovered components into service instances, enable CI relationships used in tag-based discovery by Service Mapping. These CI relationships are available from the 1.0.68 release on the ServiceNow Store. For operational steps, see [Tag-based discovery configuration](https://www.servicenow.com/docs/eIOd7ZdFc8jWAKQKu1dUoQ "You can refine the default configuration to control which CIs Service Mapping includes in application services during the tag-based discovery process.").  
Service Mapping uses tag-based discovery to create service instance maps including the Cloud components. The Service Mapping application comes with the following preconfigured CI relationships used for tag-based discovery. These CI relationships are available from the 1.0.68 release on the ServiceNow Store. {#azure-cloud-discovery__id_yqp_xhy_qpb__entry__3}

| CI | Relationship | CI |
|-|-|-|
| Configuration Item \[cmdb_ci\] | Hosted on::Hosts | Logical Datacenter \[cmdb_ci_logical_datacenter\] |
| Logical Datacenter \[cmdb_ci_logical_datacenter\] | Hosted on::Hosts | Cloud Service Account \[cmdb_ci_cloud_service_account\] |
[ ]

{#azure-cloud-discovery__id_yqp_xhy_qpb}

## Azure Cloud Discovery API list {#azure-cloud-discovery__section_zbd_ypm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | response.name |
| name | response.name |
| region | response.displayName |
| status | Installed |
[Table 1. Logical Datacenter (cmdb_ci_logical_datacenter)]

{#azure-cloud-discovery__table_mr2_1qm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | response.id |
| name | response.name |
| status | Installed/ Retired |
| state |   |
[Table 2. Availability Zone (cmdb_ci_availability_zone)]

{#azure-cloud-discovery__table_md1_hqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | id |
| name | name |
| state | available |
| status | Installed/ Retired |
[Table 3. Resource Group (cmdb_ci_resource_group)]

{#azure-cloud-discovery__table_q1s_3qm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | id |
| state |   |
| name | name |
| cidr | properties.addressSpace.addressPrefixes |
[Table 4. Network (cmdb_ci_network)]

{#azure-cloud-discovery__table_c5j_jqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| subnetName | response.name |
| subnetId | response.id |
| resourceGroup | response.properties.resourceGuid |
| networkId | response.id.split('/subnets/') |
| networkName | getNetwork(networkId) |
| cidrBlock | response.properties.addressSpace.addressPrefixes |
[Table 5. Subnet (cmdb_ci_cloud_subnet)]

{#azure-cloud-discovery__table_nfw_jqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| state | properties.provisioningState |
| storage_type | properties.BlobType |
| volume_id | id |
| name | name |
| size_bytes | properties.diskSizeGB \* 1024 \* 1024 \* 1024 |
| object_id | id |
| size | response.properties.diskSizeGB |
| "volume_container" | containerName |
| status | Installed/ Retired |
[Table 6. Storage Volume (cmdb_ci_storage_volume)]

{#azure-cloud-discovery__table_i3l_kqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | id |
| name | name |
| state | properties.provisioningState |
[Table 7. Security Groups (cmdb_ci_compute_security_group)]

{#azure-cloud-discovery__table_wdg_lqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| memory | properties.hardwareProfile.vmSize |
| state | The instance statuses: * succeeded: on * running: succeeded/stopping * deallocating: stopping/stopped * deallocated: off * terminated: error {#azure-cloud-discovery__ul_x51_b5m_jyb} |
| object_id | id |
| cpus | properties.hardwareProfile.vmSize |
| disks | properties.storageProfile.dataDisks |
| nics | properties.networkProfile.networkInterfaces\[\].size |
| vm_inst_id | properties.vmId |
| name | name |
| status | Installed/ Retired |
[Table 8. Virtual Server (cmdb_ci_vm_instance)]

{#azure-cloud-discovery__table_flf_mqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| name | name |
| object_id | name |
| vcpus | numberOfCores |
| memory_mb | memoryInMB |
| local_storage_gb | resourceDiskSizeInMB |
| cores | numberOfCores |
[Table 9. Hardware Template (cmdb_ci_compute_template)]

{#azure-cloud-discovery__table_g25_mqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | response.id |
| name | response.name |
| public_dns | properties.dnsSettings.fqdn |
| public_ip_address | properties.ipAddress |
[Table 10. Cloud Public IP Address (cmdb_ci_cloud_public_ipaddress)]

{#azure-cloud-discovery__table_udj_nqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | "properties.frontendIPConfigurations.properties.privateIPAddress OR properties.frontendIPConfigurations.properties.publicIPAddress, then call Public IP Address API" |
| name | "properties.frontendIPConfigurations.properties.privateIPAddress OR properties.frontendIPConfigurations.properties.publicIPAddress, then call Public IP Address API" |
| ipaddress_type | "properties.frontendIPConfigurations.properties.privateIPAddress ==\> Private IP Address OR properties.frontendIPConfigurations.properties.publicIPAddress ==\> Public IP Address" |
| status | Installed |
[Table 11. Cloud LB IP Address (cmdb_ci_cloud_lb_ipaddress)]

{#azure-cloud-discovery__table_jkz_rqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | id |
| name | name |
| private_ip | properties.ipConfigurations |
| public_dns | call public ip address api - properties.dnsSettings.fqdn |
| state | properties.provisioningState |
| is_static | properties.ipConfigurations |
| mac_address | properties.macAddress |
| public_ip | call public ip address api - |
[Table 12. Cloud Network Interfaces \[cmdb_ci_nic\]]

{#azure-cloud-discovery__table_jrd_tqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| name | response.id |
| object_id | response.name |
| guest_os | properties.storageProfile.osDisk.osType |
| image_source | id |
| status | Installed/ Retired |
[Table 13. Image (cmdb_ci_os_template)]

{#azure-cloud-discovery__table_irp_wqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| name | name |
| object_id | id |
| sku_name | sku.name |
| state | properties.provisioningState |
[Table 14. Cloud Storage Account cmdb_ci_cloud_storage_account]

{#azure-cloud-discovery__table_sf4_yqm_qmb}

|-|-|
| CI Attributes | Azure Attributes |
| object_id | response.id |
| name | response.name |
| state |   |
| dns_name | properties. |
| fqdn |   |
| canonical_hosted_zone_name |   |
[Table 15. Load Balancer (cmdb_ci_cloud_load_balancer)]

{#azure-cloud-discovery__table_kcf_zqm_qmb}

## Useful information {#azure-cloud-discovery__section_b2f_2y4_chc}

* [Microsoft Azure discovery solutions comparison](https://www.servicenow.com/docs/~QhZYkobhx_F5YLI33R90A "ITOM Visibility applications discover a variety of Microsoft Azure resources and populate the relevant configuration item (CI) classes in the Configuration Management Database (CMDB) with their attributes.")
* [Set up Azure service accounts](https://www.servicenow.com/docs/_5QfXcWcH8tWf~lcyLEaIg "Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Microsoft Azure accounts.")
* [Install and configure MID Servers to access cloud environments](https://www.servicenow.com/docs/DZ1qVBl~rfTV9JTZFLlAkg "Install and configure the MID Servers correctly to enable ITOM products to access to the cloud resources.")
* [Microsoft Azure Cloud discovery using patterns](https://www.servicenow.com/docs/s9SHZxzsnOR4TZKkvmJG9A "Discovery uses multiple patterns to discover components of the Microsoft Azure Cloud deployment during horizontal discovery. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.")
{#azure-cloud-discovery__ul_hbn_gy4_chc}

*[\>]: and then


