Azure Active Directory
Overview
Azure Active Directory, now known as Microsoft Entra ID, is an identity service that provides SSO and authentication. Integrate Cortex with Azure AD to drive insights into ownership of entities.
For information on configuring Entra ID SSO for logging in to Cortex, see the Microsoft Entra ID SSO documentation.
How to configure Azure AD with Cortex
If you do not see the settings page you're looking for, you may not have permission to access that page. Please contact your admin for assistance.
Step 1: Register and configure a new Active Directory application
- Follow Microsoft's documentation to register a new single tenant AD application.
- In AD, navigate to your new application, and then to API Permissions. Add the following permissions:
- Microsoft APIs > Microsoft Graph > Application permissions > User >
User.Read.All
- Microsoft APIs > Microsoft Graph > Application permissions > Group >
Group.Read.All
- Microsoft APIs > Microsoft Graph > Application permissions > User >
- Click Grant Admin Consent to grant permissions for all accounts in the directory.
- Navigate to Certificates & secrets and click New client secret.
- Note that you will need to rotate the secret before the expiration date you set for it.
- Navigate to the application's Overview page and copy the client ID. You will need the client ID and secret in the next steps.
Step 2: Configure the integration in Cortex
- In Cortex, navigate to the Azure Active Directory settings page:
- In Cortex, click your avatar in the lower left corner, then click Settings.
- Under "Integrations", click Azure Active Directory.
- Configure the Azure AD integration form:
- Tenant ID: Enter your Azure AD tenant ID.
- Client ID and Client secret: Enter the client ID and secret you generated in the previous steps.
- Click Save.
- You will be redirected to the Azure Active Directory settings page in Cortex, where you can optionally set a group filter to limit which groups are pulled in from Azure AD.
How to connect Cortex entities to Azure AD
Import entities from Azure AD
To import teams and team memberships:
- In the main nav of Cortex, click Catalogs > Teams.
- On the right side of the Teams page, click Add team.
- On the "Import entities" page, select Azure Active Directory.
- A list of discovered entities will appear. Click the team you want to add.
- If your expected teams do not appear, click Sync teams in the upper left corner of the "Import teams" page.
- When you click a team, you will be redirected to the "Team details" page where you can configure basic details, Slack channels, parent and children teams, on-call, and links. When you are finished, click Save team at the bottom of the page.
Editing the entity descriptor
You can define the following block in your Cortex entity descriptor to add your Azure Active Directory group as an owner.x-cortex-owners:
- type: group
name: Engineering # group name in Azure Active Directory
provider: ACTIVE_DIRECTORY
The group name is case-sensitive and should be exactly the same as in Azure Active Directory.
Expected results
Teams page
Under Catalogs > Teams, you will see teams and team members pulled in from Azure AD.
Entity pages
If you have ownership of entities set up, then Azure AD teams and users will be listed in the Owners page for an entity.
Background sync
Cortex conducts an ownership sync every day at 6 a.m. UTC.
Scorecards and CQL
With the Azure AD integration, you can create Scorecard rules and write CQL queries based on Azure AD teams.
See more examples in the CQL Explorer in Cortex.
All ownership details
A special built-in type that supports a null check or a count check, used to enforce ownership of entities.
Definition: ownership: Ownership | Null
Example
You can create a Scorecard with a rule that checks if an entity has at least one team as an owner.
ownership.teams().length > 0
FAQ and Troubleshooting
Why were all my Azure AD users unexpectedly deleted after rotating my client secret?
Updating your configuration can cause a temporary deletion of users. When you delete the old secret from your Azure AD configuration in Cortex, a sync is triggered to delete the users. The addition of the new secret to your configuration will trigger a sync to add the users. There may be a delay before seeing the users re-added.
Still need help?
The following are all the ways to get assistance from our customer engineering team. Please use the option that is best for your users:
- Email: help@cortex.io, or open a support ticket in the in app Resource Center
- Chat: Available in the Resource Center
- Slack: Users with a connected Slack channel will have a workflow added to their account. From here, you can either @CortexTechnicalSupport or add a
:ticket:
reaction to a question in Slack, and the team will respond directly.
Don’t have a Slack channel? Talk with your customer success manager.