How to Configure Azure Container Registry (ACR) for Scanning using Service Key as Authentication method in Prisma Cloud?

How to Configure Azure Container Registry (ACR) for Scanning using Service Key as Authentication method in Prisma Cloud?

23249
Created On 01/24/23 03:29 AM - Last Modified 04/07/23 08:28 AM


Objective


  • How to Configure Azure Container Registry (ACR) for Scanning using Service Key as Authentication method in Prisma Cloud?


Environment


  • Prisma Cloud
  • Azure Container Registry


Procedure


Step 1 : Under Compute section, Go to Manage > Cloud Accounts > Add account
Step 2 : Select Cloud Provider as Azure.
Step 3 : Select Authentication method as Service key.
Step 4 : Enter the Azure Service Key Principle under 'Service Key'. Ensure it is entered in correct JSON format.

Screenshot 2023-01-24 at 11.18.36 AM.png

NOTE : If the Service Key is not entered correctly, you may run into the following Error 'Azure credentials should be in JSON format'.

Screenshot 2023-01-24 at 11.23.48 AM.png
  • To avoid this Error, copy the output of Service Key Principle (including the brackets) and save it to a text file.
  • Then, copy the contents of the text file and enter it in Step 4.
Example of Service Key Principle:

Screenshot 2023-01-24 at 11.18.04 AM.png

Reference : AZURE CREDENTIALS SHOULD BE IN JSON FORMAT

NOTE : Ensure the User --role that created the Service Key on Azure is either
contributor = Cloud Discovery + Azure Container Registry Scanning + Azure Function Apps Scanning
reader = Cloud Discovery + Azure Container Registry Scanning


Screenshot 2023-01-24 at 11.28.51 AM.png

Step 5 : Once done, proceed to Defend > Vulnerabilities > Images > Registry Settings > Add Registry.
Step 6 : 
Select version as 'Azure Container Registry', add the Registry Address (ends with azurecr.io) and select the Credential created in Steps 1 - 4. Once done, click on Add.

Screenshot 2023-01-24 at 11.33.39 AM.png
Note : Other fields are optional and can be configured as per your business needs and requirement. Once done, you can initiate a Manual Scan.


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kGTlCAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language