How to Run an Azure Security Assessment with Codlytic LENS
Learn how to connect your Microsoft Azure environment, choose the subscriptions you want Lens to assess, run an audit, and review the security and cost findings that matter most.
Prepare your Azure access.
Lens uses authorized Azure access to discover resources and evaluate configuration, security posture, governance, and cost signals. Use a dedicated application/service principal and grant only the access needed for assessment.
Grant the Lens service principal the Azure Reader role on each subscription you want assessed. If cost information is required, additional cost-management visibility may also be needed depending on your Azure billing configuration.
- An active Microsoft Azure tenant
- One or more Azure subscriptions to assess
- Permission to create or use an Azure application/service principal
- Reader access on the target subscriptions
Connect Azure
Open Lens and choose the Azure connection option. Enter the credentials for the application/service principal created for the assessment.
Tenant ID
The Microsoft Entra tenant/directory containing the Azure subscriptions you want to assess.
Client ID
The Application (client) ID for the service principal Lens will use to authenticate.
Client secret
The secret associated with the application. Treat this value as sensitive and do not place it in source code.
Validate connection
Use Lens to verify authentication before continuing to subscription selection.
If authentication succeeds but Lens cannot see subscriptions, verify that the service principal has the Reader role assigned on each subscription you want audited.
Select subscriptions
After the Azure connection is validated, Lens discovers the subscriptions available to the service principal. Select the subscriptions that should be included in the assessment.
- Confirm the subscription name and ID
- Select only subscriptions that are in scope
- Verify expected production and non-production subscriptions are visible
- Resolve missing Reader assignments before starting the audit
The resources Lens can assess are determined by the permissions assigned to the Azure identity. Keeping scope explicit makes the resulting report easier to understand and act on.
Run your first audit
Start the assessment after confirming your subscription scope. Lens inventories supported Azure resources and evaluates them across security, cost, governance, reliability, monitoring, and backup-related checks.
Security
Review risky configurations, exposure, missing controls, and other security findings.
Cost
Identify potential waste, underused resources, and opportunities to optimize Azure spend.
Operations
Surface monitoring, reliability, and backup gaps that can affect workload operations.
Governance
Review resource-level controls and areas where standards may be missing or inconsistent.
Your first assessment establishes a baseline. Avoid changing Azure resources while the audit is running so the results represent a consistent point in time.
Review your assessment
Start with the dashboard for a high-level view, then work into individual findings. Focus first on items with the greatest security impact or exposure before moving into operational and cost optimization work.
- Review the overall posture and category scores
- Investigate Critical and High severity findings first
- Review internet-exposed resources
- Check monitoring, backup, and governance gaps
- Review estimated cost savings and optimization opportunities
- Open individual findings for affected resources and remediation guidance
Use the initial audit as your baseline. After remediation work is complete, run Lens again to verify improvements and identify anything new.
Turn findings into an improvement plan.
Your first assessment is the starting point. Group findings by urgency and owner, address the highest-risk issues, capture savings opportunities, and repeat the assessment to measure progress.
Explore Lens features
See the assessment capabilities available across security, cost, reliability, monitoring, backup, and governance.
Need help?
Contact Codlytic with questions about Azure connectivity, subscription scope, or interpreting your assessment.
Use this quick start to connect Azure, define scope, run an assessment, and prioritize remediation.
Before running LENS, confirm the Azure tenant, application credentials, subscription visibility, and Reader permissions required for the intended assessment scope.
After the first audit, treat the results as a baseline. Review Critical and High findings, internet exposure, operational gaps, governance issues, and cost optimization opportunities, then reassess after remediation to verify improvement.
Explore all LENS features · Understand assessment reports · Open documentation
Ready to run your first assessment?
Connect Azure, select your scope, and let Lens bring security and spend into focus.
Request a demo →