> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/mashinsukyan/azure/setup-configuration-in-azure.md).

# Azure VMアクセス設定

このページでは、Azure仮想マシンをスキャンするためにAikidoにアクセス権を付与する方法を説明します。

## Entra ID のアプリ登録

次のアカウントにログインしてください [**Azure ポータル**](https://portal.azure.com/) に移動し、 **Microsoft Entra ID サービス**.

をクリックします **Add** をクリックして、次を選択します： **アプリの登録**

![Azure ポータル: Default Directory に新しいユーザー、グループ、エンタープライズ アプリ、またはアプリ登録を追加します。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-53332ba9e377b1992be07aa2b26515a9012923f8%2Fucarecdn-7272798b-6ece-4bc5-9e40-df364a5e7a1f.png?alt=media)

アプリケーションに意味のある名前を付けてください。この名前は後で必要になります。

次の項目はそのままにしてください **サポートされているアカウントの種類** 既定値： **この組織ディレクトリのアカウントのみ**.

をクリックします **登録**.

![アカウントの種類を選択して「AikidoSecurity」という新しいアプリケーションを登録する Azure ポータル画面。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-c57ebacda5c9c707705a273faf0d6cc031e393bc%2Fucarecdn-4690d5db-e42d-4d8d-93a0-b978333c1364.png?alt=media)

新しく作成されたアプリケーションの詳細ページにリダイレクトされます。ここで次の項目を見つけてコピーできます。 **アプリケーション（クライアント）ID** と **ディレクトリ（テナント）ID**

![AikidoSecurity アプリケーションのクライアント ID と基本的な概要の詳細を表示する Azure ポータル。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-5568f22ce6811e7894c5b9d23ee50f41c8f45189%2Fucarecdn-4ce56e1e-0436-430e-8492-e4e85120a1d3.png?alt=media)

クライアント資格情報のフィールドで、「証明書またはシークレットの追加」をクリックします

![AikidoSecurity アプリの概要とクライアント資格情報の構成オプションを表示する Azure ポータル。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-cdec5321abc1ef9cce6200cab6701be1b8fdcece%2Fucarecdn-5d15f5a3-597a-473f-87d0-733e9859afaa.png?alt=media)

「新しいクライアント シークレット」をクリックし、シークレットの説明を入力して、有効期限を 2 年（730 日 / 24 か月）に設定します

![Azure AD でアプリケーション認証用の新しいクライアント シークレットを作成します。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-ae12a8e94b9a2412d5f0212702fb9c70fb08ee53%2Fucarecdn-121cb5f1-e88a-4223-b42d-a4c8333dc37c.png?alt=media)

コピーします: **シークレットの値**

![シークレットの説明、有効期限、コピー オプションを表示する Azure ポータルのクライアント シークレット管理画面。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-3bfeac6592f6a43974cbf9f88e3d1abf6fbc803a%2Fucarecdn-04e75758-4d58-4f1f-bacd-bac394368b76.png?alt=media)

Azure ポータルでアプリケーションのセットアップが完了すると、Public API を介して Azure Cloud を追加するために必要な値がすべてそろいます。

## Azure RBAC のロール割り当て

サブスクリプションの詳細ページに移動します。次に、必要なロールへのアクセス権を付与する必要があります。

次へ移動 **サブスクリプション**、仮想マシンに対応する関連サブスクリプションを見つけます

をクリックします **"アクセス制御 (IAM)"**.

![サブスクリプション内のロールとアクセス許可を管理する Azure IAM アクセス制御パネル。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-b2955c99d638edfc1240484f19e0fd6b4d896a48%2Fucarecdn-1c719e05-4e24-4386-b2dd-8f82e0bbf7a9.png?alt=media)

ロール割り当てタブに移動し、次をクリックします **"追加"**、その後 **"ロールの割り当ての追加"**.

![ロールの割り当てを追加し、クラシック管理者を管理する Azure ポータルのインターフェース。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-eca053ca98613bc874214d294250d7470f8e62fd%2Fucarecdn-4feba3fe-538d-4b7e-b1f7-615bda664244.png?alt=media)

の **"ロール"** タブ、検索して選択 **「VM Scanner Operator」** をクリック **"次へ"**.

![Azure でディスク スナップショットのセキュリティ分析のために「VM Scanner Operator」ロールを割り当てます。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-ef0aa96fda730d735d3e08b2cc521330582283c1%2Fucarecdn-891c0d87-d666-4c75-8199-ed8d65d7bbf2.png?alt=media)

次の項目はそのままにしてください **「アクセス権の割り当て先**「既定値。

をクリックします **"メンバーの選択"**&#x3067;、作成したアプリ登録（例: "AikidoSecurity"）の名前を検索して選択します。

クリック **"選択"**

クリック **"確認 + 割り当て"** 2 回

![Access Control (IAM) 設定を使用して Azure サブスクリプションのメンバーにロールを割り当てます。](https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-9c873c11e84698003abd7f45eabc3a7b7283b079%2Fucarecdn-4ee31542-c6c9-40da-a557-b264660a458d.png?alt=media)

次のロールについて、ロールの割り当て手順を繰り返します **「Disk Snapshot Contributor」**.

アプリ登録には、仮想マシンをスキャンするために必要なロールが付与されました。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/mashinsukyan/azure/setup-configuration-in-azure.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
