---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Azure DNS zones and record sets

# Azure
DNS zones and record sets discovery using Patterns {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Azure DNS zones and record sets discovery using Patterns

The Discovery and Service Mapping Patterns application in ServiceNow uses specific patterns---Azure - DNS Zones (LP) and Azure - DNS Zone Recordsets (LP)---to discover Azure DNS zones and their record sets.
This discovery process populates the ServiceNow Configuration Management Database (CMDB) with detailed DNS information from your Azure environment, enabling enhanced visibility and management of DNS resources.
Show full answer Show less  
To leverage these patterns effectively, customers may need to update to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store. Regular updates ensure access to new patterns and the most current discovery capabilities.

## Prerequisites

* **Verify privileges:** Assign a user the API Management Service Reader role in the Microsoft Azure Console to enable read access.
* **Create Azure Service Principal credentials:** These credentials authenticate ServiceNow to Azure; instructions are available for creating them.
* **Configure Azure service account:** Set up a cloud account in ServiceNow for Azure integration.
* **Create discovery schedule:** Schedule discovery runs for the configured Azure service accounts within the Cloud Discovery Workspace.
* **Verify REST API permissions:** Use the downloadable Cloud Discovery patterns spreadsheet to ensure required user permissions are granted for running discovery patterns.

## Discovered Data and CMDB Population

When running the Azure DNS discovery patterns, ServiceNow populates the CMDB with DNS zones and record sets information:

* **DNS Zones \[cmdbcidnszone\]:** Includes attributes such as the DNS zone name, number of record sets, operational status, state, install status, and comments.
* **DNS Alias Records \[cmdbcidnsalias\]:** Captures alias names, associated IP addresses, operational status, comments, and unique identifiers combining service account ID and DNS zone info.
* **DNS Name Records \[cmdbcidnsname\]:** Contains DNS record names, operational status, comments, and unique identifiers.

## Configuration Item (CI) Relationships

To reflect the relationships within Azure DNS resources, the following CI relationships are established in the CMDB:

* Resource Group contains DNS Zone
* DNS Zone contains DNS Name records
* DNS Zone contains DNS Alias records
* DNS Name record uses DNS Alias record

These relationships help model the hierarchical and usage dependencies of DNS resources, supporting better impact analysis and service mapping.  
The Discovery and Service Mapping Patterns application uses the Azure - DNS Zones (LP) and Azure - DNS Zone Recordsets (LP) Patterns to discover Azure
Domain Name System (DNS) definitions (zones and their respective record sets). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.

## Request apps on the Store {#azure-dns-discovery__id_u4x_vzt_hxb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#azure-dns-discovery__inline-send-to-store}
To learn about Azure DNS zones and record sets and their version that you can discovery, refer to [Detailed information on products discovered by ITOM Visibility](https://www.servicenow.com/docs/AB0jKyDtjf78iS3uAPUKpg "Discovery and Service Mapping can discover a wide range of operating systems and applications.").

For more information on Azure cloud discovery, see [Discovery for Microsoft Azure Cloud](https://www.servicenow.com/docs/iMXKXsU7K2dnNRjDU4ObTg "If your cloud resources are in an Azure cloud, you must create a user identity called a service principal that grants permissions to the MID Server to access selected resources.").

## Prerequisites {#azure-dns-discovery__section_z1j_mmt_jxb}

Verify privileges
:   On the Microsoft Azure Console, provide a user with the API Management Service Reader role.

Create Azure Service Principal credentials
:   For more information see: [Create Azure cloud credentials](https://www.servicenow.com/docs/S0rTUg4IoSKTvPVjSkCBwQ "If your cloud resources are in an Azure cloud, create credentials that can access the Azure account. This procedure requires configuration in your Azure account.").

Configure Azure service account
:   For more information, see [Set up a cloud account for Azure](https://www.servicenow.com/docs/dbJrnEUHQ3w9HlUwdr3z8w "A cloud account is the logical representation in Cloud Provisioning and Governance of all or part of your managed cloud infrastructure. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.").

Create discovery schedule
:   Create a schedule for the relevant Azure service accounts. For more information, see [Create a discovery schedule in Cloud Discovery Workspace](https://www.servicenow.com/docs/4egAp8rafm6~FSeRVUzHTg "Create schedules for discovering cloud resources based on the discovery method that you choose: service accounts or IP ranges. The discovery schedule defines the various settings for the cloud discovery.").

## Verify the REST API Permissions {#azure-dns-discovery__id_fcs_mcq_rfc}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available
quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#azure-dns-discovery__cloud-discovery-api-paragraph}

## Data collected by Discovery during horizontal discovery {#azure-dns-discovery__section_yjz_lmt_jxb}

Discovery populates the data in the CMDB when running the Azure - DNS Zones (LP) and Azure - DNS Zone Recordsets (LP) Patterns.

Resources discovered by the Azure - DNS Zones (LP) pattern
:
    {#azure-dns-discovery__table_mbk_lmt_jxb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the DNS Zone. |
    | Number Of RecordSets \[number_of_recordsets\] | The number of the recordsets defined within the DNS Zone. |
    | Operational status \[operational_status\] | The operational status of the DNS Zone. |
    | State \[state\] | The state of the DNS Zone. |
    | Install Status \[install_status\] | The install status of the DNS Zone. |
    | Comments \[comments\] | The field for general comments. |
    [Table 1. DNS Zone \[cmdb_ci_dns_zone\]]

    {#azure-dns-discovery__table_mbk_lmt_jxb}

Resources discovered by the Azure - DNS Zone Recordsets (LP) pattern
:
    {#azure-dns-discovery__table_ymc_vzp_cdb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the DNS alias record. |
    | IP Address \[ip_address\] | IP address of the DNS alias record. |
    | Comments \[comments\] | Unique identifier for an Azure DNS zone combining service account ID, DNS zone name, and a fixed hash suffix. |
    | Operational status \[operational_status\] | The operational status of the DNS alias record. |
    [Table 2. DNS Alias \[cmdb_ci_dns_alias\]]

    {#azure-dns-discovery__table_ymc_vzp_cdb}

    {#azure-dns-discovery__table_uyq_jnt_jxb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the DNS Name record. |
    | Operational status \[operational_status\] | The operational status of the DNS record. |
    | Comments \[comments\] | Unique identifier for an Azure DNS zone combining service account ID, DNS zone name, and a fixed hash suffix. |
    [Table 3. DNS Name \[cmdb_ci_dns_name\]]

    {#azure-dns-discovery__table_uyq_jnt_jxb}

## CI relationships {#azure-dns-discovery__section_ebj_zmt_jxb}

These relationships are created to support Azure DNS zone discovery.{#azure-dns-discovery__table_ysf_fpq_f987b__entry__3}

| CI | Relationship | CI |
|-|-|-|
| Resource Group \[cmdb_ci_resource_group\] | Contains::Contained by | DNS Zone \[cmdb_ci_dns_zone\] |
[ ]

{#azure-dns-discovery__table_ysf_fpq_f987b}  
These relationships are created to support Azure DNS zone record set discovery.{#azure-dns-discovery__table_z4q_rnt_jxb__entry__3}

| CI | Relationship | CI |
|-|-|-|
| DNS Zone \[cmdb_ci_dns_zone\] | Contains::Contained by | DNS Name \[cmdb_ci_dns_name\] |
| DNS Zone \[cmdb_ci_dns_zone\] | Contains::Contained by | DNS Alias \[cmdb_ci_dns_alias\] |
| DNS Name \[cmdb_ci_dns_name\] | Used by::Uses | DNS Alias \[cmdb_ci_dns_alias\] |
[ ]

{#azure-dns-discovery__table_z4q_rnt_jxb}

