As a Tanzu Platform hub organization owner or administrator, you can run the Microsoft Azure account workflow to create the roles and connections required for this account
To configure the event monitoring:
Create a Tanzu Platform cloud services token.
In the Define Scope section, select the following roles.
You must have the following roles assigned to you in your organization before you can configure the token.
Use this workflow to add a single account. If you are new to Tanzu Platform hub, it is useful way to explore how Tanzu Platform hub can help you manage your resources.
If you want to add multiple accounts, repeat the process for each account.
Click Microsoft Azure, select Single Subscription, and click Continue.
In the Account Information section, enter useful account information.
You can use Environment to add descriptive metadata to subscriptions that are used by some features in Tanzu Platform hub.
For example, if you add and select environments such as prod, dev, and test, you can then apply governance policies to a particular environment. You can then search based on environment and even apply a policy to the resources in your production environment but not development or testing.
Enter the owner name and email address.
Register VMware Tanzu Platform hub as an application in the Azure portal and add the Application ID and Shared secret key to this Create App form in Tanzu Platform hub.
The steps that are provided in the UI are repeated in this procedure for you convenience.
Click Login to the Azure portal on the form.
The Microsoft Azure portal opens in a new tab.
In Microsoft Azure, open your Azure Active Directory.
In Azure Active Directory, configure the reader role to use with Tanzu Platform hub and enter the tenant ID.
The steps that are provided in the UI are repeated in this procedure for you convenience.
In the Account Onboarding section, enable event monitoring cost collection.
To configure event monitoring, which provides updates about security findings for this cloud account, you must configure Microsoft Azure so that you can run a connection script. See the prerequisites at the beginning of this procedure.
The steps that are provided in the UI are repeated in this procedure for you convenience.
Use either the Azure Cloud Shell or Azure CLI to run the script provided in the following step in the event monitoring configuration UI.
This procedure is based on Azure Cloud Shell.
To download the script, click Connect Event Stream.
In Cloud Shell, run export CSP_REFRESH_TOKEN={CSP token}
to set the token variable.
The {CSP token}
is the Tanzu Platform cloud services token that you created as part of the prerequisites for this procedure.
Copy and paste the bash command from Tanzu Platform hub into Cloud Shell and run it.
If you have multiple Microsoft Azure accounts to add, you can add them using the Multiple Subscriptions options rather than adding then one at a time.
You can onboard subscriptions in groups of 100 accounts at a time.
When using the following procedure, you can refer to the images and details in the single subscription procedure.
Be sure the use the scripts on the pages in this procedure. They are customized each time you onboard the resources. Do not reuse a script from previous onboarding actions.
Click Microsoft Azure, select Multiple subscriptions, and click Continue.
To add subscriptions, click Start in the Add Subscriptions step.
On the General Information page, select the Account Type.
The other values are optional. Click Next.
On the Create App page, register Tanzu Platform hub as an application in the Azure portal and add the Application ID and Shared secret key to this Create App form in Tanzu Platform hub, and then click Next.
Details about this process are available in the single account instructions.
On the Assign Role page, configure the reader role to use with Tanzu Platform hub and enter the tenant ID, and then click Next.
Details about this process are available in the single account section.
On the Select Subscriptions page, select the subscriptions that you want to add to Tanzu Platform hub by click Add Subscriptions.
You can only onboard 100 subscription per process. To add additional subscriptions, you can repeat this workflow.
When the curated list is ready, click Next.
On the Edit Properties page, modify the properties for various subscriptions as needed.
The subscriptions inherit the values that you defined on General Information page. If you want to change the properties for various subscriptions, select them and then click Edit Settings.
When the settings are defined to you satisfaction, click Next.
On the Onboard Accounts page, click Onboard Accounts.
When the subscriptions are onboarded, click Close.
In the Configure Event Monitoring step, activate event monitoring cost collection.
On the Configure Event Monitoring page, follow the on-screen instructions.
Details about this process are available in the single account section.
Click Finish.
Parent topic:Setting up data connections in VMware Tanzu Platform hub