Documentation Videos View Site

# CMDB-360 Azure Satellite — Frequently Asked Questions


# General

What is the CMDB-360 Azure Satellite?

The CMDB-360 Azure Satellite is a software component that provides visibility into cloud resources provisioned within an Azure Cloud Subscription. It regularly discovers and sends resource rosters to the CMDB-360 Base Station to aid in managing customer cloud assets.


Is any sensitive or proprietary asset data stored on the CMDB-360 Base Station?

No. Only simple, non-sensitive rosters of discovered cloud resources are recorded on the Base Station. Detailed asset information is streamed on-demand from the Azure Satellite to the Base Station and is never stored there permanently.


What are the core functions of the Azure Satellite?

The Azure Satellite performs three primary functions:

  1. Asset Discovery — Regularly discovers cloud resources within an Azure subscription or designated resource group and sends non-sensitive resource details to the CMDB-360 Base Station.
  2. Metrics Collection — Collects and stores Azure resource metrics locally for up to one year, which can be displayed as charts and graphs in the CMDB-360 portal on demand.
  3. On-Demand Access — Provides the Base Station with on-demand access to detailed asset information without storing sensitive data outside the Azure cloud.

What Azure resource types does the Satellite discover and manage?

The Azure Satellite manages the following resource types:

  • Virtual Machines — Including Disks, Backups, and VNICs
  • Networking — Virtual Networks and Load Balancers
  • Compute Images
  • Disks and Backups
  • Blob and File System Storage
  • SQL Databases
  • Metrics
  • Cost & Usage
  • Recommendations
  • Announcements
  • Support Tickets
  • App Registration Expirations

Note: Discovery and access for any of these resource types can be disabled from the Satellite scheduler.


How frequently does the Satellite perform asset discovery?

By default, the Azure Satellite performs asset discovery hourly. This interval is configurable. You may also manually trigger a discovery at any time using the Run Discovery action in the Satellite Connection section of the CMDB-360 portal.


# Security & Permissions

What level of Azure permissions does the Satellite require?

The Azure Satellite only requires read-only permissions, typically fulfilled by Azure’s built-in RBAC Reader role assigned to the subscription being monitored. You can also customize access to limit the Satellite to specific resource groups using Azure custom roles.


Can I restrict the Satellite to only certain resource groups?

Yes. Rather than granting full subscription-level read access, you can configure custom RBAC roles to limit the Satellite’s access to specific resource groups within the subscription.


Are there any known permission issues with Azure Storage Accounts?

Yes. Due to a known issue with Microsoft’s Azure SDK, the RBAC Reader role alone is insufficient to list files in Blob Containers and File Shares. To enable Storage Account visibility in CMDB-360, two additional roles must be added to the Service Principal: Storage Blob Data Contributor and Storage File Data Privileged Contributor. The CMDB-360 Azure Authorization Tool will add these roles automatically. If you do not need Storage Account information in CMDB-360, these additional roles are not required.


What are the firewall requirements for the Azure Satellite?

The Satellite only requires outbound HTTPS connectivity — no inbound ports need to be opened. Specifically:

  • Inbound: None required. CMDB-360 and other systems never connect to the Azure Satellite.
  • Outbound: HTTPS via TCP port 443 (may vary based on your Base Station configuration) to two destinations:
    • The update/control server (typically control.cmdb360.com:443)
    • Your CMDB-360 Base Station

# Deployment & Installation

What steps are required before deploying the Azure Satellite?

Regardless of the deployment method chosen, a CMDB-360 entry for the satellite must be created first. Log in to the CMDB-360 portal, select the appropriate Account, navigate to the Integrations tab, and click + Add in the Satellites section. Provide a meaningful name and select Microsoft Azure as the Satellite Type.


What are the available deployment methods?

There are three ways to deploy the Azure Satellite:

  1. Azure Marketplace (Recommended) — Deploy a pre-configured Oracle Linux 9.7+ AMD (x86_64) virtual machine directly from the Azure Marketplace by searching for “CMDB360.” This is the simplest method and has been validated by Microsoft. During deployment, supply the Base Station URL and API Access Token via the Custom Data field on the Advanced tab to automatically connect the Satellite.

  2. CMDB-360 LaunchPad — If you have an active CMDB-360 LaunchPad, you can deploy the Azure Satellite directly from the satellite’s Overview page by clicking the Deploy Now button. LaunchPad deployments automatically connect the Satellite to the Base Station. See the LaunchPad documentation for setup details.

  3. Manual Virtual Machine — Install on any Linux virtual machine running Red Hat 9, Oracle Linux 9, Ubuntu 20.04, or Ubuntu 22.04 (ARM or x86_64) using the graphical Installer or AutoInstaller utility. Minimum requirements are 1 vCPU, 6 GB RAM, and 20 GB disk. See the Satellite Installer documentation for details.

For full installation documentation, visit: https://docs.cmdb360.com/docs/Satellites/Azure-satellite/Installation/Installation


Where should the Azure Satellite be deployed?

CMDB-360 recommends deploying the Azure Satellite within the target customer’s Azure Tenant to keep all sensitive data inside the tenant boundary. However, it can be deployed in any Azure Tenant or other location (such as an on-premises datacenter or another cloud), provided outbound internet access is available. No inbound access is required. See the deployment options documentation for details on limitations.


How are updates delivered to the Azure Satellite?

Updates are delivered automatically through the internal Satellite update mechanism, regardless of the original deployment method. You may also redeploy from the Azure Marketplace to get the latest version, though re-configuration will be required in that case.


# Configuration

What is involved in configuring the Azure Satellite?

Configuration is a two-step process (note: LaunchPad deployments and Marketplace deployments using the Custom Data field skip Step 1):

  1. Base Station Connection — Configure the Satellite to communicate with your CMDB-360 Base Station using the URL and API Access Token. This is managed via the AdminTool utility using the encrypted config.yml file. Your token can be found on the satellite’s Overview page in the Satellite & API Access Token section.

  2. Azure REST API Access — Create an Azure Service Principal with the RBAC Reader role and configure the Satellite to use it. See the Configure Azure Access documentation for full details.


What is an Azure Service Principal and why is it needed?

A Service Principal is an Azure identity used by automated tools and applications to access Azure services with restricted permissions. Rather than signing in as a full user, the Azure Satellite uses a Service Principal with read-only access (RBAC Reader role) to query the Azure REST API on behalf of your subscription — a more secure and auditable approach.


How do I create the required Azure Service Principal?

There are two methods:

  • Manually via the Azure Portal (Recommended) — Register a new application in Azure App Registrations, generate a client secret, and assign the RBAC Reader role to the App Registration on the target subscription via Access Control (IAM). Full step-by-step instructions are in the Configure Azure Access documentation.

  • Using the CMDB-360 Azure Authorization Tool — Download and run the azAuthTool utility from Azure Cloud Shell. It will create and verify the Service Principal automatically, display the required credentials (Tenant ID, Subscription ID, Client ID, and Client Secret), and save them to a file. This tool also automatically adds the additional storage roles if needed.

Important: Copy and securely store the Client Secret value immediately after creation — it is only displayed once. If lost, a new secret must be generated and the Satellite reconfigured.


Can I validate the Service Principal before configuring the Satellite?

Yes. You can test the Service Principal from Azure Cloud Shell using the Azure CLI:

az login --service-principal -u <CLIENT_ID> -p <CLIENT_SECRET> --tenant <TENANT_ID>

If successful, you will be logged in as the Service Principal and can verify access by running commands against the subscription, such as listing available VM sizes for a region.


# Metrics & Monitoring

What metrics does the Azure Satellite collect?

The Azure Satellite collects over 60 metrics from the Azure Metrics Service, available on demand for the past 90 days. Metrics are available for the following resource types:

  • Virtual Machines — CPU utilization, memory, disk I/O (read/write bytes and IOPS), network traffic (in/out), VM availability, burst credits, OS disk performance, and more.
  • Networking (VNets/Public IPs) — DDoS-related metrics including bytes and packets dropped, forwarded, and received; ping round-trip times; and failed ping percentages.
  • VNICs — Bytes and packets received and sent per network interface.

How far back can metric data be retrieved?

Metrics can be retrieved on demand for any period within the past 90 days via the Azure Metrics API.


*For additional documentation and support, visit https://docs.cmdb360.com