Cloud posture assessment — setup
This grants Zybim read-only visibility into your cloud security posture via Microsoft Defender for Cloud. It takes about two minutes, requires an Azure Owner or User Access Administrator on the subscription, and can be removed just as easily at any time.
— two short steps below, then press “I've completed the setup” at the bottom and we'll take it from there.
What you're granting
The built-in Azure role Security Reader, assigned to the Zybim assessment app on the subscription(s) you want assessed. This allows reading security scores and findings — it cannot read your data, change resources, or see billing.
Step 1 — register the Zybim app in your tenant
If you arrived here without running our Microsoft 365 assessment first, our app doesn't exist in your tenant yet. One command creates its (permissionless) entry so the role in Step 2 has something to attach to — open shell.azure.com (Bash) and run:
loading…
If it replies that the service principal already exists, that's fine — it means this step was already done (e.g. via the M365 assessment consent) and you can move on.
Step 2, Option 1 — Azure Cloud Shell (fastest)
Open shell.azure.com, choose Bash, and run:
loading…
Replace <SUBSCRIPTION_ID> with the subscription to assess (find it under Subscriptions in the Azure portal). Repeat per subscription.
Step 2, Option 2 — Azure portal
Subscriptions → select your subscription → Access control (IAM) → Add → Add role assignment → role Security Reader → Members → select Zybim assessment app (search by the app ID shown below) → Review + assign.
Covering AWS and GCP too
Defender for Cloud assesses AWS and GCP accounts once they're connected: Defender for Cloud → Environment settings → Add environment. If they aren't connected yet, we'll flag that in your report and can set the connectors up as part of the engagement.
Removing access later
Same IAM screen → Role assignments → remove the Zybim entry. Access ends immediately.
Once done, tell your Zybim contact — we'll run the assessment and bring the consolidated report to your review session.