Long Arrow Right External Link angle-right Search Send Times Loader chevron-down thumb-up thumb-down Spinner angle-left
Go to ThreatLocker

Azure Integration

Note: This integration requires the use of ThreatLocker Agent Version 8.0 or above.

How to Configure the Azure Integration

To begin, navigate to the ThreatLocker portal.

From the left-hand navigation menu, click ‘Integrations’ and click ‘New Integration’.

undefined

Click ‘Setup’ next to the Azure icon.

undefined

Enter a valid Tenant ID from your Azure Directory and click ‘Open Consent Screen’.

undefined

Note: This next step requires a Microsoft administrator account.

Login as an administrator and accept the permissions requested.

undefined

If done correctly, the Admin Consent will now state ‘Granted’ and the Configuration tab will become visible.

undefined

Click ‘Configuration’, select the Azure groups you’d like to sync from the drop-down menu, and click ‘Add’.

undefined

Once you have your Azure groups added, click ‘Save’.

undefined

A bar will pop-up to confirm you have successfully saved the Azure integration and you will see the Azure Integration listed on your Integrations page.

undefined

undefined

How to Apply the Azure Integration to Your Policies

To begin, navigate to the ThreatLocker portal, expand the Application Control menu on the left hand side, and click ‘Application Policies’.

undefined

Add a new application policy or edit an existing policy. In the popup window, scroll down to the section asking ‘Which users and groups should this policy apply to?’, choose ‘Let me select users and groups’, select the Azure group(s) this policy should apply to from the drop down menu, and click ‘Add’. 

undefined

Please note: It is recommended to select the group name from the drop-down menu to avoid any type-os. The Azure group name must match exactly.

Click ‘Save’.

undefined

Note: Our enterprise application used for the integration requires specific pieces of information from the Azure groups and their members in order to function properly. The permissions required for this integration are necessary. ThreatLocker will not read any information other than what is truly required and will not be writing any data. 

Did this answer your question?
Thanks so much for your feedback!
%s of people found this helpful.