SaaS Overview
Azure CloudScanner SaaS is a deployment model in which Upwind manages the CloudScanner infrastructure on your behalf. Upwind runs the scanning infrastructure in isolated, Upwind-managed Azure subscriptions dedicated to your scanning operations.
During onboarding, you grant Upwind access to your Azure environment by provisioning Upwind service principals in your Microsoft Entra tenant and assigning them scoped Azure roles. These identities allow Upwind to discover your subscriptions, fetch resource information, identify eligible resources, and execute the scan workflow through secure cross-tenant access. No scanner compute, virtual machine scale sets, or Key Vaults are deployed inside your environment.
This allows you to get full value from Upwind with minimal setup on your side.
What's in This Section
- Architecture: covers the identities, tenants, and subscriptions involved in the SaaS architecture, and explains how they interact during scanning.
- Prerequisites: lists the requirements that must be in place before starting the onboarding process.
- Onboarding Flow: step-by-step instructions for connecting your Azure environment to Upwind using the SaaS deployment model.
- Glossary: defines the key terms, parameters, and resources you encounter during onboarding.
- Troubleshooting: covers common issues that may occur during onboarding, with guidance on how to identify and resolve them.