Full Azure Security Visibility Across Every Subscription and Tenant
Azure's nested hierarchy of management groups, subscriptions, and resource groups makes consistent security posture nearly impossible to maintain manually. Onam maps your entire Azure estate — from Entra ID conditional access policies to NSG rules on every VM NIC — and flags drift the moment it occurs.
Services we monitor on Azure
Every service below is scanned continuously — no agents, no network changes, read-only.
Plus: Azure Firewall, API Management, Container Registry, Data Factory, Synapse, Service Bus, Event Hubs, and more.
Compliance frameworks
Onam maps every Azure finding to the frameworks your auditors care about.
Connect in 3 steps
From consent to first finding in under five minutes.
Register an Azure app for Onam
Create a single-tenant app registration and assign it the built-in Reader and Security Reader roles at the management-group scope. No custom roles, no elevated permissions.
Grant tenant-wide read consent
One admin consent covers every subscription under the management group. Onam traverses the hierarchy automatically and inherits access to any new subscription without re-onboarding.
First findings in under 5 minutes
Onam authenticates via workload identity federation — no client secrets to rotate — and scans every subscription, region, and Entra ID tenant in scope.
Azure in the real console.
Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.
What makes Onam different on Azure
Management-group hierarchy traversal
Onboard at the root management group and Onam scans every descendant subscription — inherited policies, Azure Policy assignments, and lock hierarchies included. No missed subscriptions.
Entra ID conditional access analysis
Onam parses every conditional access policy, named location, and identity-protection rule. It surfaces gaps — MFA-exempted accounts, legacy-auth allowances, and privileged roles without CA coverage.
NIC-level network exposure mapping
NSG effective-rules resolution across subnet and NIC scopes, application security groups, and Azure Firewall policy — evaluated together so you see the actual path an attacker can take.
Questions we get a lot
Ready to secure your Azure environment?
Connect a read-only role in three minutes. Your first findings surface in under five.