Solutions · Microsoft Azure

Full Azure Security Visibility Across Every Subscription and Tenant

Azure's nested hierarchy of management groups, subscriptions, and resource groups makes consistent security posture nearly impossible to maintain manually. Onam maps your entire Azure estate — from Entra ID conditional access policies to NSG rules on every VM NIC — and flags drift the moment it occurs.

350+
Azure security rules
35+
Azure services monitored
Multi-tenant
Entra ID support
100%
agentless deployment
Coverage

Services we monitor on Azure

Every service below is scanned continuously — no agents, no network changes, read-only.

Entra ID (Azure AD)
Management Groups & Subscriptions
Virtual Machines & NSGs
Storage Accounts & Blob
Azure SQL & Cosmos DB
Key Vault
AKS Clusters
App Service & Functions
Azure Monitor & Log Analytics
Network Security Groups
Load Balancers & Front Door
Defender for Cloud

Plus: Azure Firewall, API Management, Container Registry, Data Factory, Synapse, Service Bus, Event Hubs, and more.

Compliance

Compliance frameworks

Onam maps every Azure finding to the frameworks your auditors care about.

CIS Microsoft Azure Foundations BenchmarkISO 27001:2022NIST 800-53 Rev 5GDPRSOC 2 Type II
Onboarding

Connect in 3 steps

From consent to first finding in under five minutes.

1

Register an Azure app for Onam

Create a single-tenant app registration and assign it the built-in Reader and Security Reader roles at the management-group scope. No custom roles, no elevated permissions.

2

Grant tenant-wide read consent

One admin consent covers every subscription under the management group. Onam traverses the hierarchy automatically and inherits access to any new subscription without re-onboarding.

3

First findings in under 5 minutes

Onam authenticates via workload identity federation — no client secrets to rotate — and scans every subscription, region, and Entra ID tenant in scope.

See it live

Azure in the real console.

Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
Differentiators

What makes Onam different on Azure

Management-group hierarchy traversal

Onboard at the root management group and Onam scans every descendant subscription — inherited policies, Azure Policy assignments, and lock hierarchies included. No missed subscriptions.

Entra ID conditional access analysis

Onam parses every conditional access policy, named location, and identity-protection rule. It surfaces gaps — MFA-exempted accounts, legacy-auth allowances, and privileged roles without CA coverage.

NIC-level network exposure mapping

NSG effective-rules resolution across subnet and NIC scopes, application security groups, and Azure Firewall policy — evaluated together so you see the actual path an attacker can take.

FAQ

Questions we get a lot

Via workload identity federation — no long-lived client secrets. Onam's service principal is granted Reader and Security Reader at the management-group scope, and every API call is signed with a short-lived federated token.

Ready to secure your Azure environment?

Connect a read-only role in three minutes. Your first findings surface in under five.