Skip to content
Notifications
Clear all

Anyone else having issues with the Azure integration missing entire subscriptions?

2 Posts
2 Users
0 Reactions
9 Views
(@annab)
Reputable Member
Joined: 3 months ago
Posts: 349
Topic starter   [#26160]

Hi everyone, I’m fairly new to Lacework and have been tasked with getting our Azure environment fully onboarded over the last couple of weeks. I’m hitting a consistent issue and wanted to see if others have experienced this.

We have multiple Azure subscriptions under a single tenant. I followed the integration guide using the ARM template, and the connection itself shows as healthy in the Lacework console. The problem is, it’s only discovering and monitoring about half of our subscriptions. The missing ones aren’t small or inactive—they contain production workloads that really need visibility. I’ve double-checked the app registration permissions and resource provider registrations, and everything seems correct on the Azure side.

Has anyone else run into this? I’m wondering if there’s a known limit on subscriptions per integration, or if there’s a specific step I might have missed for subscription discovery. The support docs aren’t very clear on troubleshooting this kind of partial discovery. Any pointers would be really appreciated.



   
Quote
(@integration_ian_2)
Honorable Member
Joined: 4 months ago
Posts: 525
 

Yeah, we definitely ran into something similar last quarter. The integration showed as healthy, but it was silently failing to poll certain subscriptions due to a resource provider API throttle on Microsoft's side. Even though your app registration has the right tenant-wide permissions, each subscription still needs to have the `Microsoft.Security` and `Microsoft.PolicyInsights` providers fully registered and responsive.

What worked for us was going into each missing subscription in the Azure portal, navigating to Subscriptions -> Resource providers, and manually hitting 'Re-register' for those two. It's a tedious process if you have a lot of subs, but you can script it with Azure CLI. After a re-register, we had to wait about 30 minutes and then manually trigger a new Lacework compliance scan for the Azure integration. The missing subscriptions started showing up after that.

There isn't a documented subscription limit that I'm aware of, but the discovery seems to choke if any single subscription in the list times out or returns an authorization error during the initial enumeration. I'd start by checking the activity logs for your Lacework app registration in Azure to see if requests are even being made against those specific subscription IDs.


api first


   
ReplyQuote