Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
- Automatically import entities and track ownership of entities
- Create Scorecards to drive alignment and track progress on projects involving resources from Azure
Cortex conducts a background sync of Azure Resources every day at 00:00 a.m. UTC and an ownership sync every day at 6 a.m. UTC.
How to configure Azure Resources with Cortex
Prerequisites
Before getting started, you will need the following information. These can be found in the Enterprise applications section of Azure:- Azure tenant ID
- Azure client ID and client secret
- Azure subscription ID
- Ensure that the service principal for the subscription ID has a Reader role.
Configure the integration in Cortex
- In Cortex, navigate to the Azure Resources settings page.
- Click Integrations from the main nav. Search for and select Azure Resources.
- Click Add configuration.
- Configure the Azure Resources integration form:
- Account alias: Enter your Azure account alias. Account aliases are used to tie service registrations to different configuration accounts.
- Azure tenant ID: Enter your Azure tenant ID.
- Client ID and Client secret: Enter your Azure client ID and secret.
- Subscription ID: Enter your Azure subscription ID.
- Click Save.
- You will be redirected to the Azure Resources Settings page in Cortex, where you can optionally choose to include only specified Azure resource types for this integration. You can also enable automatic import for any discovered entities of known types.
How to connect Cortex Entities to Azure Resources
For Azure Resources, Cortex replaces non-alphanumeric characters in entity names with a space. For example,
resource_1 would become resource 1.For the Cortex tag, Cortex replaces non-alphanumeric characters with - and lowercases the letters. If multiple special characters appear together in a tag, Cortex replaces the group of characters with only one -. For example, mY_e%ntity#$_tag would become my-e-ntity-tag.Enable automatic discovery of Azure Resource entities
You can configure automatic import from Azure:- In Cortex, navigate to the Entities Settings page.
-
Next to Auto import from AWS, Azure, and/or Google Cloud, click the toggle to enable the import.
Discover ownership for Azure Resources
Cortex can automatically discover ownership for your Azure resources. To configure this:- Make sure that your Azure resources have a tag matching the
x-cortex-tagof the corresponding Cortex team - Enable the “Sync ownership from Azure” toggle in the Azure Resources Settings page in Cortex.
- By default, Cortex looks for the
ownertag. You can also customize the tag key name on the Settings page.
- By default, Cortex looks for the
Define a dependency
Cortex automatically discovers dependencies between your services and resources by scanning for resources with specific Azure Resources tags. By default, a service will have dependencies on any Cortex resource that has a corresponding Azure Resources resource with Azure Resources tag key = “service” and tag value = the service’s Cortex tag. On the Azure Resources settings page, you can customize the tag key names for dependencies. For more information on defining dependencies, please see the Dependencies documentation.Import entities from Azure Resources
See the Create services documentation for instructions on importing entities.Editing the entity descriptor
You can associate a Cortex entity with one or more Azure Resources entities. Cortex will display those Azure Resources entities’ metadata on the Cortex entity page. When the entity is connected to Azure, the entity YAML will look like the following:Using the Azure Resources integrations
Scorecards and CQL
With the Azure Resources integration, you can create Scorecard rules and write CQL queries based on Azure Resources details. See more examples in the CQL Explorer in Cortex.Get Azure Resource details for entity
Get Azure Resource details for entity
Get Azure Resource details for an entity.Definition: Make sure an entity has an environment tag:Make sure an entity has a health check:Make sure an entity has a tag with a certain key and value:
azureResource.details(): ObjectExamplesIn a Scorecard, you can write a rule to make sure an entity has Azure Resource details:Availability zones
Availability zones
Availability zone data (VM Scale Sets, Redis, Application Gateways) is a first-class
.zones field, sourced directly from Azure Resource Graph.
If you have existing “Resource Redundancy” rules for these resource types, update them to reference .zones instead of deriving zone data from the ARM export template.ExampleApp Service health-check path and minimum TLS version
App Service health-check path and minimum TLS version
Cortex reads App Service configuration data, including
healthCheckPath and minimum TLS version.
Existing “Health Check” and App Service Scorecard rules will continue to work as-is, no Scorecard rule changes needed.ExampleView integration logs
This feature is available in Cortex cloud.

Troubleshooting and FAQ
See frequently asked questions below.Why is the Azure resource type microsoft-resources-subscriptions-resourcegroups not pulling in Azure Resource details?
Why is the Azure resource type microsoft-resources-subscriptions-resourcegroups not pulling in Azure Resource details?
Cortex pulls from the Azure Resource API, but not from the Azure Resource Group API. If you would like to submit a feature request for support of Azure Resource Groups, please contact our customer engineering team.
Why is ARM template data sometimes missing or stale?
Why is ARM template data sometimes missing or stale?
Cortex uses the Azure ARM export template endpoint to ingest resource data for some resource types. This endpoint has known reliability limitations acknowledged in Microsoft’s documentation, which can cause intermittent failures that result in missing or outdated data.Cortex is actively migrating away from ARM template-based ingestion toward Azure Resource Graph and the resource metadata endpoint. In the interim, if you see empty or stale data for a resource, this is likely caused by an ARM export failure on the Microsoft side.