Adding cloud accounts to be scanned
Azure
Azure
Adding an Azure account/management group is done by installing the Cye CSPM Enterprise Application in the Azure tenant and granting it the Monitoring Reader role.
When a new Cye platform company is created, a company-specific Azure installer URL (valid for 1 week) is provided. This URL will be used to install the Cye CSPM Enterprise Application for each of the Azure tenants to be added to this specific CYE Platform company.
The Cye CSPM Enterprise Application installer URL is company-specific and adds the Azure account it is installed in to the specific Cye-Platform company it was generated for.
Be careful not to re-use installer URLs across different assessments (as it will result with adding the Azure account to the wrong Cye-Platform company.
install the Cye CSPM Enterprise Application
install the Cye CSPM Enterprise Application
Installing the Cye CSPM Enterprise Application requires the Azure tenant Global Admin role
Login to the Azure Account to be added
navigate to the installer URL
Provide consent
Connect an Azure subscription
Connect an Azure subscription
Assign the Monitoring Reader role to the application:
Choose the appropriate scope — either a subscription or a management group.
Open Azure Subscriptions
Select the subscription you want to connect.
Open Access control (IAM)
In the left menu of the selected subscription, select “Access control (IAM)”.
Click “Add” ➜ “Add role assignment”.
Choose the role
Role: Monitoring Reader (Built-in)
Click “Next”.
Select the Hyver application
Assign access to: User, group, or service principal.
Click “Select members” and search for the application you authorized during the OAuth flow (for example, “CYE – Hyver”).
Select it and click “Select”, then “Next”.
Review + assign
Review the settings and click “Assign”.
installation confirmation
The new Azure account is added to Cye CSPM
The new Azure account is added to Cye CSPM
After Cye Enterprise application was successfully installed the account is automatically added to Cye CSPM.
Approximately within 1 hr, Cye CSPM will start analyzing the account
CYE CSPM data becomes available in Cye-Platform within 48 hrs.
AWS
AWS
Adding an AWS account to Cye-CSPM is done by launching a CloudFormation stack in the relevant AWS account.
When a new Cye platform company is created, a company-specific AWS CloudFormation stack launcher URL is provided (with no expiration date). This URL will be used to launch the CloudFormation stack for each of the AWS tenants to be added to this specific CYE Platform company.
The Cye CSPM CloudFormation launcher URL is company-specific and adds the AWS account it is created in to the specific Cye-Platform company it was generated for.
Be careful not to re-use launcher URLs across different assessments (as it will result with adding the AWS account to the wrong Cye-Platform company.
The new AWS account is added to Cye CSPM
The new AWS account is added to Cye CSPM
After Cye Enterprise CloudFormation stack was successfully created the account is automatically added to Cye CSPM
Approximately within 1 hr, Cye CSPM will start analyzing the account
CYE CSPM data becomes available in Cye-Platform within 48 hrs

