This article walks you through connecting an Azure account to Cye Cloud Posture Solution with the recommended OAuth flow, then assigning the Monitoring Reader role at the subscription or management group scope.
Overview
Cye Cloud Posture Solution, the Cloud Security Posture Management (CSPM) component of the Cye platform, connects to Azure through a read-only application installed in your tenant, so it can scan identities, resources, and configuration without elevated privileges. The recommended way to install that application is the OAuth flow: you accept a consent request in the Azure portal, then grant the application the Monitoring Reader role on the subscriptions or management groups you want scanned.
Install & Authorize: From Cloud Accounts > Connect account, choose Connect Azure account, click Install, and accept the consent request for the CYE – Hyver application in the Azure portal.
Assign Scope & Role: Grant the application the Monitoring Reader role on a subscription or a management group. Assigning it at the root management group covers the entire directory.
Verify & Scan: Refresh the subscriptions list on the onboarding page. Connected subscriptions appear within 5 minutes, and your cloud assets are available for inspection within an hour.
Prerequisites
Prerequisites
Before you start, make sure you have:
An account with Azure tenant admin permissions.
Access to the Azure Portal.
1. Start a new connection in the console
1. Start a new connection in the console
Every Azure connection starts from the Cloud Accounts page in the Cye Cloud Posture Solution console.
Sign in at console.solvo.cloud and go to Cloud Accounts.
Click Connect account.
Select Connect Azure account.
2. Install the application with OAuth
2. Install the application with OAuth
The OAuth flow installs the CYE – Hyver application in your Azure tenant and asks you, as a tenant admin, to consent to its read-only permissions.
Install the application
On the onboarding page, keep Recommended: via OAuth selected.
Click Install. The Azure portal opens in a new window.
Optional: retry with a tenant ID
Azure may not detect your tenant automatically. If Azure opens an error page:
On the onboarding page, expand Installation didn't work? Try with tenant ID.
In the Azure Portal, go to Microsoft Entra ID > Overview and copy the Tenant ID value.
Return to the onboarding page, paste the tenant ID, and click Retry install.
When the consent page opens, continue with the consent request below.
Accept the consent request
Review the permissions requested for the CYE – Hyver application.
Click Accept to authorize the application for your organization.
Finish the OAuth flow
Wait for the Azure confirmation page that says the application was installed successfully.
Close the window, return to the Cye Cloud Posture Solution console, and click Next.
Note: If you cannot use OAuth, follow Connecting Your Azure Account with a Registered App instead.
3. Assign the Monitoring Reader role
3. Assign the Monitoring Reader role
The authorized CYE – Hyver application needs the Monitoring Reader role on every scope you want scanned. Choose the scope that fits your environment: a subscription or a management group.
Tip: For full visibility across your organization, assign the role at the root management group level, which grants access to the entire directory.
Connect an Azure subscription
Go to Subscriptions in the Azure Portal and select the subscription you want to connect.
In the left menu of the selected subscription, select Access control (IAM).
Click Add > Add role assignment.
For Role, select Monitoring Reader (Built-in) and click Next.
For Assign access to, select User, group, or service principal.
Click Select members and search for the application you authorized during the OAuth flow (for example, CYE – Hyver). Select it, click Select, then Next.
Review the settings and click Assign.
Return to the onboarding page in Cye Cloud Posture Solution and refresh the subscriptions list.
Newly connected subscriptions may take up to 5 minutes to appear.
Connect an Azure management group
Go to Management groups in the Azure Portal and select the management group you want to connect.
In the left menu of the selected management group, select Access control (IAM).
Click Add > Add role assignment.
For Role, select Monitoring Reader (Built-in) and click Next.
For Assign access to, select User, group, or service principal.
Click Select members and search for the application you authorized during the OAuth flow (for example, CYE – Hyver). Select it, click Select, then Next.
Review the settings and click Assign.
Return to the onboarding page in Cye Cloud Posture Solution and refresh the subscriptions list.
Newly connected subscriptions under that management group may take up to 5 minutes to appear.
Repeat these steps for each subscription or management group you want to connect.
If you cannot find the application, confirm that the OAuth flow completed successfully and that you are in the correct Azure tenant.
Troubleshoot install errors
Troubleshoot install errors
If Azure shows an error right after you click Install, use the message on the Microsoft sign-in or consent screen to identify the issue.
You need admin approval or don't have enough permissions
A Need admin approval message means the account you used cannot approve the application.
Sign out of the Microsoft sign-in window.
Sign in again with a Global Administrator user in the target Azure tenant.
Click Install again on the onboarding page.
You signed in with an external user
A message that the selected user account does not exist in the tenant and must be added as an external user first means you are signing in with an external user account.
Return to the onboarding page.
Expand Installation didn't work? Try with tenant ID.
In the Azure Portal, copy the Tenant ID from Microsoft Entra ID > Overview.
Paste the tenant ID into the onboarding page and click Retry install.
Complete the installation flow with a user from that tenant.
Wrap-up / Next Steps
Wrap-up / Next Steps
Wait for the first scan: Your cloud assets become available for inspection within an hour after onboarding.
Connect more scopes: Repeat Add role assignment in Access control (IAM) for each additional subscription or management group.
Review what the application can access: See How Cye Cloud Posture Solution Connects to Your Azure Environment for the full list of Microsoft Graph API permissions and the Monitoring Reader role.
Use a registered app instead: If OAuth is not available in your tenant, follow Connecting Your Azure Account with a Registered App.











