Connectivity error while configuring Attack Surface Analyzer for Azure

Connectivity error while configuring Attack Surface Analyzer for Azure

In this article:  

  • Issue description

  • Prerequisites

  • Possible causes

  • Resolution

  • Related topics and articles

  • How to reach support

Issue description  

When configuring Attack Surface Analyzer for Azure AD in ADAudit Plus, an error occurs while attempting to connect to Azure AD to fetch subscription details. This issue may arise due to incomplete configurations, firewall restrictions, or missing permissions.

Prerequisites  

Before troubleshooting, ensure the following:

  • The ADAudit Plus server has a working internet connection.

  • The outbound HTTPS port 443 is open on the ADAudit Plus server to allow communication with the Azure platform.

  • Access to the Azure Portal and required subscriptions is available for configuration in ADAudit Plus.

Possible causes  

  • The ADAudit Plus server lacks internet connectivity or outbound HTTPS port 443 is blocked.

  • Required permissions are not assigned to the subscription in Azure AD.

  • Firewall restrictions prevent access to necessary Azure endpoints.


Resolution  

Step 1: Ensure internet connectivity  

Ensure the ADAudit Plus server has a stable internet connection to communicate with Azure AD.

Step 2: Open outbound HTTPS Port 443  

Verify that the outbound HTTPS port 443 is open on the ADAudit Plus server to allow secure communication with Azure.

Step 3: Assign required permissions to the subscription  

  1. Log in to the Azure AD portal.

  2. Navigate to Subscriptions.

  3. Go to Access Control (IAM) > + Add > Add Role Assignment.

  4. In the Role tab, search for and select:

    • Reader Role

    • Storage Account Contributor Role

  1. Click Next.

  2. In the Members tab, click + Select Members.

  3. Search for the name of the application created for ADAudit Plus.

  4. Select the application and click Review + Assign twice to complete the process.

Step 4: Ensure accessibility to required azure URLs  

Ensure that the following URLs are accessible from the ADAudit Plus server:

Related topics and articles:  

How to reach support:  

If the issue persists, contact our support team here

                  New to ADSelfService Plus?