This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

How-to guides

Users can create the service by entering the required information for the Config Inspection service and selecting detailed options through the Samsung Cloud Platform Console.

Create Certificate

To create and use the Config Inspection service in the Samsung Cloud Platform Console, you must first generate an authentication key.

Authentication key creation is **My 메뉴 > My Info. > Authentication Key Management > Authentication Key Creation can be created. For more details, please refer to Authentication Key Management.

Reference
  • The expiration period of the authentication key is up to 365 days.
  • To create an authentication key without an expiration date, it must be generated permanently.

Create Config Inspection

You can create and use the Config Inspection service in the Samsung Cloud Platform Console.

Reference
Users must belong to the AdministratorGroup user group in order to use the services provided by the Config Inspection service properly.

To create a Config Inspection, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Create Config Inspection button. 2. Go to the Create Config Inspection page.
  3. Config Inspection Creation On the page, enter the inputs required to create the service, and select detailed options.
    • Enter or select the required information in the Service Information Input area.
      Category
      required status
      Detailed description
      Diagnosis Type-Automatic configuration via Console
      CloudRequiredSelect cloud to diagnose
      • SCP: Samsung Cloud Platform
      • AWS: Amazon Web Services
      • Azure: Microsoft Azure
      • Detailed input fields vary depending on the selected cloud type
      Diagnostic Target > Diagnosis NameRequiredName to distinguish the diagnostic target
      • Use the entered value as the resource name
      • Enter within 25 characters using English letters, numbers, and special characters (-, _)
      Diagnostic target > Diagnostic accountRequiredConsole information to be diagnosed
      • Select the Account ID to diagnose from the list
      • If the same Account ID is selected, duplicate requests will be made, resulting in additional charges
      • AWS is selected, enter the Account ID (12 digits) for the diagnostic account
      • Azure is selected, enter the Subscription ID (36 characters, including letters, numbers, and special characters) for the diagnostic account
      ChecklistRequiredSelect the checklist to apply during diagnosis
      versionRequiredSelect the checklist version to apply during diagnosis
      Diagnostic Schedule > Diagnostic CycleRequiredAfter selecting Use, choose the diagnostic interval
      • The diagnosis runs on the selected date according to the specified interval
      • If Monthly is selected, the diagnosis may not be performed on the selected date
        • Example) Selecting the 31st of each month – February has no such date, so the diagnosis is not performed
      Diagnostic Schedule > Start TimeRequiredSelect diagnostic start time
      • Set the hour and minute information for starting the diagnostic
      authentication keyRequiredSelect authentication key to use for Open API calls
      • Select button click and, in the Select authentication key popup, choose the appropriate key from the authentication key list
      • If no selectable authentication keys are available, click 인증키 관리 to create a new authentication key
      Pricing planSelectionSelect a plan
      • Standard: Charges are based on the number of diagnoses
      • Monthly subscription: Charges a fixed amount each month regardless of the number of diagnoses (up to 30 diagnoses per month)
      • The plan cannot be changed after service enrollment
      Table. Config Inspection service information input fields
    • Enter or select the required information in the Additional Information Input area.
      Category
      required status
      Detailed description
      tagSelectionAdd Tag
      • Up to 50 per resource can be added
      • After clicking the Add Tag button, input or select Key, Value values
      Table. Config Inspection additional information entry fields
  4. Summary Check the detailed information and estimated charges generated in the panel, and click the Create button.
    • When creation is complete, check the created resources on the Config Inspection List page.

View detailed information of Config Inspection

The Config Inspection service allows you to view and edit the full list of resources and detailed information. On the Config Inspection Details page, it consists of the Detailed Information, Tags, Operation History tabs.

To view detailed information of the Config Inspection service, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. 2. Go to the Config Inspection List page.
  3. Config Inspection List page, click the resource to view detailed information. 3. Config Inspection Details page.
    • Config Inspection Details page displays status information and additional feature information, and consists of Details, Tags, Activity Log tabs.
      CategoryDetailed description
      statusIndicates the status of Config Inspection
      • Ready: When there is no diagnostic request after the service is created (diagnostic request possible)
      • In Progress: When a diagnostic request is being executed (diagnostic request/service termination not allowed)
      • Error: When an error occurs in the diagnostic request (diagnostic request possible)
      • Completed: When the diagnostic request completes successfully (diagnostic request possible)
      Diagnosis requestButton to perform console diagnostics
      Service terminationCancel service button
      Table. Config Inspection status information and additional features

Detailed Information

Config Inspection List page lets you view detailed information of the selected resource and, if needed, modify the information.

Category상세 설명
서비스서비스명
자원 유형자원유형
SRNSamsung Cloud Platform에서의 고유 자원 ID
자원명자원 이름
자원 ID서비스에서의 고유 자원 ID
생성자서비스를 생성한 사용자
생성 일시서비스를 생성한 일시
수정자서비스 정보를 수정한 사용자
수정 일시서비스 정보를 수정한 일시
진단 유형서비스에서 제공하는 진단 유형
클라우드진단 대상 종류
진단 대상진단 대상이 되는 Console 정보
  • 진단 대상의 진단명진단 계정 정보 제공
  • 진단 대상이 AWS나 Azure인 경우 수정 아이콘을 클릭해 진단 계정을 수정할 수 있음
최근 진단 결과마지막으로 실행된 진단 요청 결과
  • 완료: 진단 요청이 정상적으로 완료된 상태
  • 오류: 진단 요청이 정상적으로 완료되지 않은 상태
    • UNAUTHORIZED: 진단 요청에 사용하는 Key 권한 확인 필요
    • INVALID_INPUT_VALUE: 진단 계정 등 입력값 확인 필요
    • CONNECTION_FAIL: 콘솔 접근 제어 설정 확인 필요
    • ETC: 진단 엔진 등 기타 오류로 서비스 데스크를 통해 문의 필요
※ 진단 결과는 Security > Config Insepction > Report 메뉴에서 확인 가능
최근 진단 일시마지막으로 실행된 진단 요청 일시
진단 스케줄선택한 진단 스케줄 정보 표시
  • 진단 대상이 SCP인 경우 수정 아이콘을 클릭해 진단 스케줄을 변경할 수 있음
인증키서비스 생성 시에 등록된 사용자의 인증키
  • Access Key, 사용자, 상태 정보 제공
  • Access Key 정보와 수정 아이콘는 해당 인증키를 생성한 사용자에게만 표시
    • 수정 아이콘을 클릭해 인증키를 변경할 수 있음
  • 인증키가 삭제된 경우에는 - 상태로 표시, 만료된 경우에는 만료로 표시
  • 다른 사용자가 생성한 자원의 인증키 정보(Access Key, 상태)는 -로 표시
체크 리스트선택한 진단 체크 리스트 종류
버전선택한 진단 체크 리스트 버전 정보
버전 상태선택한 진단 체크 리스트 버전 상태
요금제선택한 요금제 종류
Table. Config Inspection detailed information tab items

Tag

On the Config Inspection List page, you can view the tag information of the selected resource and add, modify, or delete it.

구분상세 설명
태그 목록태그 목록
  • 태그의 Key, Value 정보 확인 가능
  • 태그는 자원 당 최대 50개까지 추가 가능
  • 태그 입력 시 기존에 생성된 Key와 Value 목록을 검색하여 선택
Table. Config Inspection tag tab items

Job History

Config Inspection list On the page, you can view the operation history of the selected resource.

구분상세 설명
작업 이력 목록자원 변경 이력
  • 작업 일시, 자원 ID, 자원명, 작업 내역, 이벤트 토픽, 작업 결과, 작업자 정보 확인
Table. Config Inspection job history tab items

Config Inspection Resource Management

If you need to view the status of a Config Inspection resource and request a diagnosis, you can perform the task on the Config Inspection List or Config Inspection Details page.

Modify authentication key

You can select the authentication key to use for each diagnostic target.

To modify the service’s authentication key, follow these steps.

  1. All Services > Security > Config Inspection click the menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. 2. Go to the Config Inspection List page.
  3. On the Config Inspection List page, click the resource to edit the authentication key. 3. Navigate to the Config Inspection Details page.
  4. Check the authentication key and click the Edit icon. 4. Edit Authentication Key The popup window opens.
  5. Edit Authentication Key Select the authentication key to use in the popup window and click the Confirm button.
    구분상세 설명
    인증키인증키 상세 정보
    생성 일시인증키 생성 일자
    만료 일시인증키 만료 일자
    상태인증키의 상태
    • 사용: 사용 가능 상태
    • 만료: 사용 기간 만료 상태
    Table. Authentication key edit popup items
Reference
  • When the authentication key is deleted, it is displayed as - status.
  • The authentication key information (authentication key, status) of resources created by other users is displayed as -.

Request Diagnosis

You can request a diagnosis from the Console based on the configured checklist.

To request a console diagnosis, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.

  2. On the Service Home page, click the Config Inspection menu. 2. Go to the Config Inspection List page.

  3. Config Inspection List page, click the resource for which you want to request a diagnosis. 3. Go to the Config Inspection Details page.

  4. On the Config Inspection Details page, click the Diagnostic Request button. 4. Diagnostic Request The popup window opens.

  5. Diagnosis Request In the popup window, enter the information required for the diagnosis and click the Confirm button.

    • Diagnostic Request popup window items vary depending on the selected Console.
      구분상세 설명
      콘솔 접근방식Console을 접근하는 방식으로 인증키 방식 고정
      인증키SCP를 선택한 경우 사전에 생성한 인증키 선택
      Access KeyAWS를 선택한 경우 Access Key 입력
      Secret KeyAWS를 선택한 경우 Secret Key 입력
      Client IDAzure를 선택한 경우 Client ID 입력
      Client SecretAzure를 선택한 경우 Client Secret 입력
      Tenant IDAzure를 선택한 경우 Tenant ID 입력
      Table. Diagnosis request popup items
  6. On the Config Inspection List page, check the status value.

    • When the diagnostic request is completed, the status value is displayed as Completed or Error.
    • In the case of Completed, you can view the diagnostic request results in the diagnostic results menu. * For more details, please refer to Diagnostic Result Management.
Reference
For detailed information on the prerequisite settings required to run diagnostics for each console, refer to Preconfigure.

Terminate Config Inspection

You can cancel the Config Inspection service you are not using. Note that if you disable Config Inspection, all stored diagnostic data will be deleted.

Caution
  • If you terminate the resource, all diagnostic data will be deleted, and you will not be able to view diagnostic results in the Report.
  • If the status of the Config Inspection service is In Progress, the service cannot be terminated.

To disable Config Inspection, follow these steps.

  1. All Services > Security > Config Inspection Click the menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. 2. Navigate to the Config Inspection List page.
  3. On the Config Inspection List page, click the resource to be terminated. 3. Navigate to the Config Inspection Details page.
  4. On the Config Inspection Details page, click the Service Termination button.
  5. When termination is complete, check on the Config Inspection List page whether the resource has been terminated.

1 - Check dashboard

Users can view the diagnostic results of the Config Inspection service at a glance on the dashboard through the Samsung Cloud Platform Console.

Check the dashboard

On the dashboard page, you can view the status of Config Inspection’s diagnostic targets, diagnostic history, and more.

To view the dashboard, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Dashboard menu. 2. Go to the Dashboard page.
  3. View the diagnostic result summary on the Dashboard page.
    • Dashboard page at the top allows you to view dashboard information based on period or diagnosis name.
      • Period: You can set a period within six months from the current month to view a summary of the diagnostic results.
      • Diagnosis Name: If you select All, you can view a summary of the entire diagnostic results, and if you select a diagnostic account, you can view the detailed information of that diagnostic result.
    • When you click the Download button, you can download the information displayed on the dashboard page as a PDF file.
      CategoryDetailed description
      Security level (overall)Display the average of the latest diagnostic results for all subjects
      • The recent diagnostic results are displayed in the list
      • Diagnostic score calculation formula = Total – (Fail + Error + Check)) / Total x 100
      Diagnosis status by periodDisplay diagnostic status by target during the search period
      • Diagnosis Completed: Show recent completed diagnosis records
        • Diagnosis Error: Show recent diagnosis error records, and when a diagnosis name is selected, navigate to the detailed diagnosis result page
        Summary of diagnostic results by period (overall)Display summary of diagnostic results (overall) for the search period
        • Selecting a diagnosis name from the list navigates to the detailed diagnostic result page
        Table. Detailed description of dashboard items for overall diagnostic results
        CategoryDetailed description
        Security levelDisplay the last diagnostic result score of the selected diagnostic account
        • Recent diagnostic results are displayed in the list
        Summary of Diagnostic Results by PeriodDisplay summary of the diagnostic results for the last diagnostic account within the search period
        Vulnerability status by periodDisplay the vulnerability assessment results of the diagnostic account as a graph during the search period
        • When a graph is selected, display detailed information of the vulnerable item in the assessment results
        Table. Detailed description of dashboard items for diagnostic results by diagnostic account

    2 - Diagnostic Result Management

    You can view the Config Inspection diagnostic request results on the diagnostic results page and modify the diagnostic results.

    Reference

    The diagnostic results are generated when a diagnostic request is made in the Config Inspection service, and they are deleted when the service is terminated.

    Check diagnostic results

    On the diagnosis results page, you can view the results of the diagnosis request.

    Check diagnostic result list

    To view the list of diagnostic results, follow these steps.

    1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.
    2. On the Service Home page, click the Diagnostic Results menu. 2. Diagnostic Results List navigate to the page.
    3. On the Diagnostic Results List page, check the summary information of diagnostic results.
      CategoryDetailed description
      Diagnosis nameResource name
      diagnostic accountConsole information subject to diagnosis
      ChecklistCollection of diagnostic items that serve as the basis for diagnostic results
      VersionVersion information of the diagnostic checklist used as the basis for diagnosis results
      Version statusDiagnostic checklist version status used as the basis for diagnosis results
      PASSNumber of checklist items with a diagnosis result of PASS (normal)
      FAILNumber of checklist items with a diagnosis result of FAIL (vulnerable)
      CHECKNumber of checklist items with a diagnosis result of CHECK (verification needed)
      ERRORNumber of checklist items with a diagnosis result of ERROR (diagnosis not possible)
      N/ANumber of checklist items with a diagnosis result of N/A (not applicable)
      AllTotal number of checklist items
      Diagnostic ResultDiagnosis request result
      • Completed: The diagnosis request has been successfully completed, clicking Completed moves to the detail page
      • Error: The diagnosis request was not completed successfully, error items cannot view detailed information
      Diagnosis date and timeDiagnosis request date and time
      Table. Diagnosis result list items

    View detailed diagnostic result information

    To view detailed information of the diagnostic results, follow these steps.

    1. All Services > Security > Config Inspection Click the menu. 1. Navigate to the Service Home page of Config Inspection.

    2. Click the Diagnostic Results menu on the Service Home page. 2. Go to the Diagnostic Results List page.

      • Diagnosis Result List You can search by entering a diagnosis name in the page’s search area or by clicking the Detailed Search button.
    3. On the Diagnosis Result List page, click the item whose diagnosis result is Completed. 3. Go to the detailed diagnosis result page.

      • Items with a diagnostic result in error status do not display detailed information.
    4. On the Detailed Diagnosis Result page, view the detailed diagnosis results.

      CategoryDetailed description
      Excel downloadDownload the detailed list of diagnostic results as an Excel file
      More > Diagnosis Result ManagementGo to the diagnostic results management page
      ChecklistCollection of diagnostic items that serve as the basis for diagnostic results
      versionVersion of the diagnostic checklist that serves as the basis for the diagnosis results
      areaDiagnostic scope (services of Samsung Cloud Platform)
      Diagnostic ItemsRecommended security standards for service-specific configurations
      ResultDiagnostic Item Standard Inspection Results
      Table. Detailed diagnosis result items

    5. Click the diagnostic item to view detailed information. 5. Diagnosis Item Details The popup window opens.

      • Diagnosis Item Details In the popup window, you can view the following information.
        CategoryDetailed description
        areaDiagnostic scope (services of Samsung Cloud Platform)
        Diagnostic ItemsRecommended security standards for service-specific configurations
        ResultDiagnostic Item Standard Inspection Results
        Diagnostic criteriaResult Evaluation Criteria
        Diagnostic methodHow to check the current settings
        Action GuideConfiguration method that complies with security standards
        Detailed resultsResource information and settings for the diagnostic item
        Change diagnostic resultButton to change the diagnosis result
        • When the diagnosis result is changed, the Check Result button is displayed, and you can delete the changed result by clicking the Delete button
        Table. Config Inspection diagnostic item details

    Manage Diagnostic Results

    On the diagnosis results page, you can modify the results of items whose diagnosis result is in the CHECK state.

    Change diagnostic result

    To change the diagnostic result, follow the steps below.

    1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.

    2. On the Service Home page, click the Diagnostic Results menu. 2. Go to the Diagnosis Result List page.

    3. On the Diagnosis Result List page, click the item whose diagnosis result is Completed. 3. Go to the Diagnosis Result Details page.

      • Items with a diagnostic result in error status do not display detailed information.
    4. On the Diagnosis Result Details page, click the More > Diagnosis Result Management button at the top. 4. Navigate to the Diagnostic Result Management page.

    5. On the Diagnosis Result Management page, click the Change Result button for the item whose diagnosis result you want to modify. 5. Result Change A popup window opens.

    6. Result Change In the popup window, select or enter the information required to change the result.

      CategoryRequired or notDetailed description
      Registrant-Diagnostic result change registrant email
      Validity periodRequiredSet the diagnostic result validity period
      Result changeRequiredSelect the diagnostic result to change among Pass, Check, Fail
      Detailed reasonRequiredEnter the detailed reason for changing the result.
      AttachmentSelection결과 변경 확인 시 필요한 파일을 업로드
      • 파일첨부 버튼을 클릭해 파일 업로드, 최대 5개까지 등록 가능
      점검결과-상세 점검 결과 표시
      Table. Detailed items of diagnostic result changes

    7. Review the entered information and click the Register button. 7. Diagnostic Result Management list, verify whether the diagnostic results have been changed.

    Delete diagnostic result change history

    To delete the diagnostic result change log, follow these steps.

    1. All Services > Security > Config Inspection click the menu. 1. Navigate to the Service Home page of Config Inspection.
    2. On the Service Home page, click the Diagnostic Results menu. 2. Go to the Diagnostic Results List page.
    3. On the Diagnosis Result List page, click the item whose diagnosis result is completed. 3. Navigate to the Diagnostic Result Details page.
      • Items with a diagnostic result in error status do not display detailed information.
    4. On the Diagnosis Result Details page, click the Diagnosis Result Management button at the top. 4. Go to the Diagnosis Result Management page.
    5. On the Diagnosis Result Management page, click the Result Check button for the item whose diagnosis result you want to change. 5. Result Confirmation A popup window opens.
    6. Check Result in the popup window, click the Delete button.

    3 - Preconfigure

    Users must perform pre‑cloud configuration, such as creating authentication keys and adding access‑control IPs, through the Samsung Cloud Platform Console to use the Config Inspection service.

    Reference
    The configuration items differ depending on the type of cloud you use. Refer to the relevant chapter and configure the required items for each cloud.

    Setting up Samsung Cloud Platform Console

    To diagnose Samsung Cloud Platform and external clouds in the Config Inspection service, configure the items below.

    Check policies attached to the user group

    information
    • In Config Inspection, you can diagnose the Samsung Cloud Platform or external clouds. * You can assign appropriate policy requirements to user groups based on the diagnostic target and use them.
      • Verify that a user group policy appropriate for the desired diagnostic target is configured.
      • If policy creation is required, please contact the Account administrator.

    To check the policy of the user group to which the user belongs, follow the steps below.

    1. All Services > Management > IAM Click the menu. 1. Navigate to the Service Home page of IAM.
    2. On the Service Home page, click the User Group menu. 2. Navigate to the User Group List page.
    3. On the User Group List page, click the user group you want to view. 3. Navigate to the User Group Details page.
    4. On the User Group Details page, click the Policy tab. 4. Navigate to the Policy tab page.
    5. Policy tab page, click the policy you want to view. 5. Navigate to the Policy Details page.
    6. Policy Details page, view detailed information.
      • Verify that the policy information in the table below is set. * If necessary, contact the administrator to add a policy.
        ItemPolicy Requirement 1Policy Requirement 2
        actionList, ReadCreate, Delete, List, Read, Update
        Applied resourceAll resourcesIndividual Resource (Config Inspection)
        Authentication TypeAll authenticationTemporary key authentication, Console login
        Applied IP123.37.11.42, custom IP
        • the IP 123.37.11.42 for diagnostics, and the IP for the user to access the console must each be added
        Custom IP
        Table: Detailed policy setting items for all cloud diagnostics

    Authentication key generation

    You can view and generate the authentication key for the Config Inspection service.

    Information
    • You can create up to two authentication keys.
    • After generating a new authentication key, you must apply the updated API authentication key to the service you are using.

    To generate an authentication key in the Samsung Cloud Platform Console, follow these steps.

    1. Click the My menu > My info. menu in the Console. 1. My info. Go to the detail page.
    2. My info. Click the Authentication Key Management tab on the detail page. 2. Navigate to the Authentication Key Management tab page.
    3. On the Authentication Key Management tab page, click the Create Authentication Key button. 3. Navigate to the Create Authentication Key page.
      • You can view the list of authentication keys on the authentication key management page.
    4. On the Create Auth Key page, after entering the expiration period, click the Confirm button.
    5. Verify that the generated authentication key is displayed in the authentication key list.

    Add allowed IP

    You can add allowed IP addresses in the Samsung Cloud Platform Console.

    To add an allowed IP for the Console, follow these steps.

    1. Click the My menu > My info. menu in the Console. 1. My info. Go to the detail page.
    2. My info. On the detail page, click the Authentication Key Management tab. 2. Navigate to the Authentication Key Management tab page.
    3. On the Authentication Key Management tab page, click the Edit icon of the Security Settings item. 3. Edit Authentication Key Security Settings The popup window opens.
    4. Edit Authentication Key Security Settings Enter the authentication method and allowed IP addresses in the popup window.
      • Select the authentication method authentication key.
      • Set the allowed access IP to Use, enter the IP address, and click the Add button.
    5. When the allowed IP addition is complete, click the Confirm button. 5. Check that the Security Settings item has been updated with the entered information.

    Configure AWS

    To diagnose the AWS (Amazone Web Services) cloud in the Config Inspection service, set the items below.

    Add permission policy

    You can add permission policies for users or user groups in the AWS Console.

    Add user permission

    To add a user access policy in the AWS Console, follow these steps.

    1. Click IAM > Users in the AWS Console.
    2. Select the diagnostic user name from the user list.
    3. On the user information page, click the Permissions tab.
    4. Select Add Permission in the permission policy.
      • When adding permissions, select ReadOnlyAccess, ViewOnlyAccess.

    Add user group permission

    To add a user group access permission policy in the AWS Console, follow these steps.

    1. Click IAM > User Groups in the AWS Console.
    2. Select the group that the user belongs to from the list of user groups.
    3. On the user group page, click the Permissions tab.
    4. Select Add Permission in the permission policy.
      • When adding permissions, select ReadOnlyAccess, ViewOnlyAccess.

    Add access control IP

    When using an IP access control policy, you must add the exception IP for blocking to the policy.

    Add user access control IP

    To add a user access control IP in the AWS Console, follow these steps.

    1. Click IAM > Users in the AWS Console.
    2. Select the diagnostic user name from the user list.
    3. On the user information page, click the Permissions tab.
    4. Click Edit for the IP Access Control Policy in the permission policy section.
      • Add 123.37.24.82 to the block exception IP.

    Add user group access control IP

    To add a user group access control IP in the AWS Console, follow these steps.

    1. Click IAM > User Groups in the AWS Console.
    2. Select the group that the user belongs to from the list of user groups.
    3. On the user group page, click the Permissions tab.
    4. In the permission policy item, click Edit of IP Access Control Policy.
      • Add 123.37.24.82 to the block exception IP.

    Create Access Key

    To create an Access Key in the AWS Console, follow these steps.

    1. Click IAM > Users in the AWS Console.
    2. Select the diagnostic user name from the user list.
    3. On the user information page, click the Security Credentials tab.
    4. On the Security credentials page, click Access keys.
    5. On the Create Access Key page, generate an access key for third‑party services.
      • Be sure to save the generated access key information.
    Caution

    Secret Key can be downloaded as a CSV file or saved separately.

    • Secret key information can only be viewed when creating an access key and cannot be recovered later.

    Configure Azure

    To diagnose Azure cloud in the Config Inspection service, set the items below.

    Entra ID Application registration

    To register an Entra ID application in the Azure Console, follow these steps.

    1. Click Microsoft Entra ID > App registrations in the Azure Console.
    2. On the App Registration page, click New Registration.
    3. Register the application (client) ID.
    4. After the app registration is complete, check the app name, application (client) ID, directory (tenant) ID on the overview page.

    Add API usage permission

    Reference
    To use the Config Inspection service, you must preconfigure it from an account that has the Global Administrator role among Azure AD roles.

    To add API permissions in Azure Console, follow these steps.

    1. In the Azure Console, click Microsoft Entra ID > App registrations(App registrations) > Entra ID Application registration > App name > API permissions(App permissions) > Add a permission(Add a permission).
    2. API permissions From the list, select the Microsoft Graph to which you want to add permissions.
    3. On the API Permission Request page, click Application Permissions.
      • Select Application.Read.All, Device.Read.All, Group.Read.All, User.Read.All, DeviceManagementManagedDevices.Read.All, AuditLog.Read.All, Directory.Read.All, Domain.Read.All, GroupMember.Read.All, Policy.Read.All, Reports.Read.All from the permission list.
    4. In App API permission registration, after adding a permission, click Grant admin consent (Grant admin consent for account name).
      • Check whether it has been changed to the Allowed (Granted for account name) status for the account name.

    Create Client Secret

    To create a Client Secret in the Azure Console, follow these steps.

    1. Click the App name > Certificates & secrets that you created in the Azure Console’s Microsoft Entra ID > App registrations > Entra ID Application registration.
    2. Click New client password in the Certificates and passwords list.
    3. When the client secret is generated, check the Client Secret in the Value column of the list.
      • Be sure to store the Client Secret value.
    Caution
    The Client Secret value (Value) can only be viewed at creation. Be sure to record or save it separately.

    Add subscription access permission in Azure Console

    Subscription access permissions in the Azure Console can be added from the tenant root group or an individual subscription. Select the desired method to add subscription access permissions.

    Add permissions in Tenant Root Group

    To add subscription access permissions in the Azure Console from the Tenant Root Group, follow these steps.

    1. Click Management groups (Management groups) > Overview (Overview) in the Azure Console.
    2. Tenant Root Group > Access Control (IAM) Click.
      • If you cannot access the Tenant Root Group menu, change the settings below.
        • Microsoft Entra ID > Properties > ‘Account name’ can manage access to all Azure subscriptions and management groups in this tenant. * Change to yes(yes)**
      • After adding the permission, you must change it to No.
    3. On the Access Control page, click Add(Add) > Add role assignment(Add role assignment).
    4. On the Add role assignment page, after entering the detailed information, click Save (Review+assign).
      • When entering role assignment information, select the information below in the Role and Member tabs to add the app created in Entra ID Application registration. * All three permissions below must be added.
        CategoryPermission
        Reader(Reader)User, group, or service principal(Users, group, or service principal)
        Key Vault read permission (Key Vault Reader)User, group, or service principal(Users, group, or service principal)
        Reader and Data Access (Reader and Data Access)User, group, or service principal(Users, group, or service principal)
        Table. Additional permission items when entering role assignment information

    Add permission in individual Subscription

    To add subscription access permissions in the Azure Console for an individual subscription, follow these steps.

    1. Click Subscription > Overview in the Azure Console.
      • Check the Subscription ID (Subscription ID) in the basic information on the Overview page.
    2. Click Subscription (Subscription) > Access Control (IAM).
    3. On the Access Control page, click Add(Add) > Add role assignment(Add role assignment).
    4. On the Add Role Assignment page, after entering the details, click Save (Review+assign).
      • When entering role assignment information, select the information below in the Role and Member tabs to add the App created in Entra ID Application registration. * All three permissions below must be added.
        CategoryPermission
        Reader(Reader)User, group, or service principal(Users, group, or service principal)
        Key Vault Reader (Key Vault Reader)User, group, or service principal(Users, group, or service principal)
        Reader and Data Access (Reader and Data Access)User, group, or service principal(Users, group, or service principal)
        Table. Additional permission items when entering role assignment information

    Adding access permissions via PowerShell

    To add subscription access permissions in the Azure Console using PowerShell, follow these steps.

    1. Run the following command in Cloud shell > PowerShell of Azure Console.
      • New-AzRoleAssignment -ObjectId “App’s Object ID as seen in Enterprise Application” -Scope “/providers/Microsoft.aadiam” -RoleDefinitionName ‘Reader’ -ObjectType ‘ServicePrincipal’
      • If the command does not execute, change the settings below.
        • Microsoft Entra ID > Properties > ‘account name’ can manage access to all Azure subscriptions and management groups in this tenant. * > Change to yes
        • After adding the permission, you must change it to No (no).
    2. Execute the following command to verify whether the configuration is complete.
      • Get-AzRoleAssignment –ObjectId "App Object ID found in Enterprise Application" –Scope "/providers/Microsoft.aadiam"
      • If you need to delete permissions, run the command below.
        • Remove-AzRoleAssignment -ObjectId “App’s Object ID found in Enterprise Application” -Scope “/providers/Microsoft.aadiam” -RoleDefinitionName ‘Reader’