Among the discovery mechanisms SDDM provides is the Azure Virtual Machine Discovery. This process will use a Service principal credential that you create to access and discover virtual machines inside of your Azure environment. As many companies may be broadly distributed across the world in their Azure environments, multiple credentials will need to be created to discover each of the regions or subscriptions inside the customer's Azure enterprise. Each one of these credentials will be required in an individual discovery job which will then discover the virtual machines in that region which are visible by the service principal credential created. We will provide in this document the steps needed to create the credentials, create the discovery jobs, and view the results in the SDDM environment.
Steps in Azure:
First, an Azure Service Principal will need to be created which can access specified subscriptions to view VM resources.
1. Log into your Azure portal.
2. Inside of Azure Active Directory select app registrations.
3. Click new registration and enter the name that you wish for this application.
4. The first option “Accounts in this organizational directory only” should be selected.
5. Click register.
Your results page will now be displayed:
It is important to copy down the Application (client) ID, and the Directory (tenant) ID values that are given on the results page.
6. From Azure portal home go to subscriptions, then click the subscription this credential is created for, then select the Access control (IAM) option.
7. Click on add role assignment and choose “Reader” role.
(Another role could be used here as long as it is able to view VM resources desired)
8. Click next.
9. Click select members.
0. . Find the new principal you created in the earlier step.
1 1. Click review and assign to make sure the user and the access row is correct
12. Accept using Review + Assign button.
13. From Azure portal home, click on Azure Active Directory.
14. Choose app registrations.
15. Select the application you just created
16. Click certificates and secrets.
17. Under client secrets click new client secret.
18. Add a description and an expiration or the client secret.
19. Click add.
It is now especially important to record the Value and Secret ID provided in the resulting page as this information again may not be displayed again and this step will have to be repeated.
20. Repeat as necessary for each region or subscription in Azure.
Steps in SDDM:
Now that one or many Service Principal credentials have been created. The next step is to add to SDDM.
1. Log into SDDM account.
2. In the left menu expand configuration, expand connection credentials, click create.
3. Select the edge device intend for this discovery.
Note that the edge does not have to be in Azure itself, but it will need to be allowed to access Azure from its location.
4. Select Microsoft Azure.
5. Use the Name and Description fields to provide proper naming.
6. Enter the application (client) ID, directory (tenant) ID, and the client Secret ID provided from the previous steps in Azure.
7. Verify all fields are correct and click save.
8. Repeat as necessary per credential created in the Azure steps above.
Now that Azure discovery credential(s) are created, SDDM Discovery jobs may be created (one per credential)
9. In the left menu expand configuration, expand discovery jobs, and click create.
10. Enter Name, select edge device from list, select Microsoft Azure from job type list, and toggle the Enable job in the upper right of the form.
11. Frequency and Timeout value are defaulted but are editable.
Frequency is how often this job will run from the time it finishes, and Timeout is how long to wait before the job will quit due to errors.
12. In the Microsoft Azure discovery settings section, click the pencil icon and choose from the list of credentials you have already created for this job.
13. In the Result Processing options, all the defaults are already toggled for you all you need to do at this point.
14. Click save.
After saving your discovery form, you will be taken to the discovery jobs list. Here, all discovery jobs are listed by category. In the Microsoft Azure section, you will see your job will be pending.
This pending state will continue for some time. Refresh the page using the refresh icon at the bottom right corner of the grid.
Eventually you will see that your job has run and completed.
You can then click on the ‘3 dots’ menu on the far right of the row and select view results to see what has been found.
Here, you’ll find a list of VMs found and data on each one.