Overview
Cato connects to Microsoft Foundry through a read-only Azure integration that gives CMA admins full visibility into managed agents built in Foundry.
Prerequisites
Before you start, confirm the following:
- You have a Microsoft Entra ID (Azure AD) account with the Application Administrator, Cloud Application Administrator, or Global Administrator role. Cato's application only requests a basic sign-in permission, so Application Administrator or Cloud Application Administrator is the least-privileged option and is sufficient
- You have the Owner or User Access Administrator role on each Azure subscription that contains the Microsoft Foundry resources you want Cato to monitor. This Azure RBAC role is separate from your Microsoft Entra ID role, and Global Administrator doesn't grant it by default
Setting up this integration is a three-step process, and the steps are often completed by different people. In step 1, an Entra ID admin adds the Cato application to the tenant. In step 2, each subscription owner grants the application access to that subscription. In step 3, a Cato admin finishes the integration in the CMA. Loop in all three roles rather than assuming one admin holds every permission.
Step 1: Connect Cato to Microsoft Entra ID
Cato registers a multi-tenant application in Microsoft Entra ID. To connect the integration, an Entra ID admin opens the Cato Networks admin consent link, which adds the application to your tenant as an Enterprise Application and grants it consent.
To connect Cato to Microsoft Entra ID:
- Open the Cato Networks admin consent link. Sign in with the administrator account described in the prerequisites when prompted. Microsoft displays a consent screen for the Cato Networks AI Security Integration application.
- Click Accept.
Step 2: Grant Cato Access to a Subscription
Cato requires the Cognitive Services User role on each Azure subscription that contains Foundry resources. This role provides read-only access and doesn't allow Cato to modify any resource. Assigning the role requires the Owner or User Access Administrator role on the subscription.
To grant Cato access to a subscription:
- In the Azure portal, go to Subscriptions.
- Select the subscription you want to connect.
- Select Access control (IAM), then select Add > Add role assignment.
- Search for the Cognitive Services User role and click Next.
- Under Assign access to, select User, group, or service principal.
- Click + Select members, search for Cato Networks AI Security Integration, select it, click Select, and click Next.
- Click Review + assign, then click Review + assign again to confirm.
Cato recommends repeating this procedure for every subscription that contains Foundry resources you want Cato to monitor.
Step 3: Finish the Integration in the CMA
To finish the integration, a Cato admin enters the Microsoft Entra ID tenant ID where the application was installed.
Get the Tenant ID
To get your Microsoft Entra ID tenant ID:
- In the Azure portal, go to Microsoft Entra ID.
- On the Overview page, under Basic Information, copy the Tenant ID.
Connect the Integration in the CMA
To connect the integration in the CMA:
- From the navigation menu, select AI Security > Integrations.
- On the Microsoft Foundry tile, click Connect.
- In the Azure AD Tenant ID field, enter the tenant ID you copied.
- Click Test Connection. You can save the integration only after the test succeeds.
- Click Save.
Data Refresh
After you connect the integration, Cato fetches data from Microsoft Foundry immediately, and then again every hour. Expect updated data in the CMA up to an hour after a change in your environment.
Review the Requested Permissions
| Role | Access |
|---|---|
| Cognitive Services User | Read-only access across Microsoft Cognitive Services, Insights, and Resources. This lets Cato view account details, models, diagnostics, metrics, usage data, and Responsible AI policies, and check availability statuses and list operations. |