{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition","img"]},"type":"markdown"},"seo":{"title":"AI Asset Discovery for Azure [Early Access]","siteUrl":"https://docs.hiddenlayer.ai","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"ai-asset-discovery-for-azure-early-access","__idx":0},"children":["AI Asset Discovery for Azure [Early Access]"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["AI Asset Discovery automates discovery and inventory of cloud providers. This provides a centralized inventory and dashboard of AI assets, including in production and in development models, applications, datasets, and dependencies. This ensures end-to-end visibility of the AI pipeline across teams."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Early Access"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Discovery for Azure is currently in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Early Access"]},"."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Please contact your customer success representative for access."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"discoverable-assets","__idx":1},"children":["Discoverable Assets"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Foundry"]},":"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Models"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Endpoints"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Agents"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Azure ML"]},":"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Models"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Registries"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Workspaces"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Endpoints"]}]}]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":2},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access to Microsoft Foundry with the following permissions."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Owner role assigned for target Subscription",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Cloud Application Administrator in Entra ID"]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"setup-azure-asset-discovery","__idx":3},"children":["Setup Azure Asset Discovery"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The HiddenLayer Azure Asset Discovery integration allows you to connect HiddenLayer to your Azure instance and have HiddenLayer discover assets such as models, endpoints, and agents."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the HiddenLayer Console, go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Integrations"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AI Platform Providers"]},", for ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Azure Asset Discovery"]},", click the menu (three dots), then select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configure Integration"]},"."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/asset-discovery-azure-configuration.7cffc990f74af967d3381eaba57d1e6cfcde95ac72c0c844f89a5a972ede9e61.7451bfb6.png","alt":"Azure Integration Configuration","framed":false,"withLightbox":true,"width":"500px","align":"center"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorize Azure"]},"."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/asset-discovery-azure-authorize.4055e09ce67c3309b72d5bf2a82bf6a3c97131a14ad9caf97980be11fb7fed94.7451bfb6.png","alt":"Azure Integration Authorization","framed":false,"withLightbox":true,"width":"500px","align":"center"},"children":[]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["You will then be re-directed to login to your Microsoft account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["After logging in to your Microsoft account, you will be redirected back to the Integrations page."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Azure Tenant"]}," to use for the integration and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Continue"]},"."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/asset-discovery-azure-tenant.c47b2c07e789f0751a99a9fa44b6e295e7a473e8c267d05ebeb3cd19c48eb3dd.7451bfb6.png","alt":"Azure Integration Tenant Selection","framed":false,"withLightbox":true,"width":"500px","align":"center"},"children":[]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["You will then be re-directed to login to your Microsoft account."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Accept the Permissions requested modal."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/asset-discovery-azure-permission.73767ad87faf5a19cd0dae4b874c6953133e329fa66f2a67abd978cc74a76937.7451bfb6.png","alt":"Azure Integration Permissions","framed":false,"withLightbox":true,"width":"500px","align":"center"},"children":[]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["After accepting the permissions, you will be redirected back to the Integrations page."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Azure Subscription"]}," to use for this integration and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Grant Access"]},"."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/asset-discovery-azure-subscription.5a958f82f291069aef94bfbe94b5c9c182a4abed4e5f38f86abd6b87debbb480.7451bfb6.png","alt":"Azure Integration Authorization","framed":false,"withLightbox":true,"width":"500px","align":"center"},"children":[]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The integration setup is now complete."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Ensure the integration has been enabled."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click the menu (three dots), then select Configure Integration."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Check the Enabled box if it isn’t already checked, and save."]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"faq","__idx":4},"children":["FAQ"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Is this a GA ready feature?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["No. This integration is still in Early Access and is being actively developed."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["It is not recommended to use this in a production environment. Usage in a production environment is at your own discretion."]}]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["What scenarios or environments are currently supported with Asset Discovery for Azure?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Azure Foundry"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Azure Machine Learning"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["How does the Azure Asset Discovery integration setup and discovery process work?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When setting up the integration, you will be asked to log into your Azure account."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["This account does not need a Service Principal."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This Azure account does need to have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Owner role assigned for target Subscription"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Cloud Application Administrator in Entra ID"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After logging in, the onboarding process will install HiddenLayer’s enterprise application into your Entra which will set up a Service Principal."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The Cloud Application Administrator role in Entra ID is needed because the onboarding process registers our application into Azure which creates the Service Principal for that tenant."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["This Service Principal is used by Discovery to discover assets after onboarding is complete."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["See what role definition is applied to the Service Principal below."]}]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Which permissions are needed?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["\"Microsoft.Storage/storageAccounts/read\""]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["\"Microsoft.Storage/storageAccounts/blobServices/read\""]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["\"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read\""]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Reason: some Azure AI services store models in the storage accounts"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Is the authentication certificate or secret based?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["It is federated identity based."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["What scenarios or environments are not currently supported?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Azure Copilot Studio"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Third party models (Ex: HuggingFace):"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Models that are downloaded and embedded into a docker image and run as a container in Azure Container Apps Container instance, or Kubernetes Service."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Models that are baked into a service and deployed via App Services."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Models that are baked into a service and then run in a virtual machine."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Models that are pulled via an Azure Function."]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"onboarding-process-in-detail","__idx":5},"children":["Onboarding Process in Detail"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["HiddenLayer owns the App Registration, which is essentially a template. During onboarding, the administrator in the user tenant will instantiate the App Registration into their tenant which becomes an Azure Enterprise Application within the user's tenant. An Enterprise Application has a Service Principal ID associated with it at creation time. The onboarding process will then use the delegated permission from the administrator to create a HiddenLayer Asset Discovery Reader Role IAM role within the target subscription. Lastly, the delegated access is used to grant the Enterprise Application the HiddenLayer Reader Role."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["HiddenLayer's App Registration has a unique ID (CLIENT_ID) that all the instantiations inherit. The user's Azure tenant ID is gathered during onboarding, enabling HiddenLayer to assume the Service Principal associated to the Enterprise Application in the user's instance. This enables HiddenLayer to \"AssumeRole\"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["HiddenLayer uses the Federated Identity pattern to grant our service the credentials needed to perform the authentication into Azure and through to the customer's tenant."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Only our service is granted these credentials."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["There are no long-lived credentials. Our platform creates and rotates a JWT for the service."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Only our service has the internal identity allowed to use the JWT."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"role-definition-for-service-principal","__idx":6},"children":["Role Definition for Service Principal"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The below is the role definition that is applied to the Service Principal during integration setup."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"name\": \"HiddenLayer Asset Discovery Reader Role\",\n  \"description\": \"Read-Only access to AI and ML Resources\",\n  \"actions\": [\n    \"Microsoft.MachineLearningServices/*/read\",\n    \"Microsoft.MachineLearningServices/registries/*/read\",\n    \"Microsoft.MachineLearningServices/workspaces/*/read\",\n    \"Microsoft.MachineLearningServices/workspaces/models/*/read\",\n    \"Microsoft.MachineLearningServices/workspaces/datastores/read\",\n    \"Microsoft.Storage/storageAccounts/read\",\n    \"Microsoft.Storage/storageAccounts/blobServices/read\",\n    \"Microsoft.CognitiveServices/accounts/read\",\n    \"Microsoft.CognitiveServices/accounts/deployments/read\",\n    \"Microsoft.CognitiveServices/accounts/projects/read\"\n  ],\n  \"dataActions\": [\n    \"Microsoft.CognitiveServices/accounts/AIServices/agents/read\",\n    \"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read\"\n  ],\n  \"notActions\": [],\n  \"roleID\": \"da26728f-0c33-4fc8-9c9f-5a04910a4a3c\"\n}\n","lang":"json"},"children":[]}]},"headings":[{"value":"AI Asset Discovery for Azure [Early Access]","id":"ai-asset-discovery-for-azure-early-access","depth":1},{"value":"Discoverable Assets","id":"discoverable-assets","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Setup Azure Asset Discovery","id":"setup-azure-asset-discovery","depth":2},{"value":"FAQ","id":"faq","depth":2},{"value":"Onboarding Process in Detail","id":"onboarding-process-in-detail","depth":2},{"value":"Role Definition for Service Principal","id":"role-definition-for-service-principal","depth":2}],"frontmatter":{"seo":{"title":"AI Asset Discovery for Azure [Early Access]"}},"lastModified":"2026-07-01T19:56:25.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/products/console/asset_discovery_azure","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}