Cloud posture assessment — setup
This grants Zybim read-only visibility into your cloud security posture via Microsoft Defender for Cloud. It takes about two minutes, requires an Azure Owner or User Access Administrator on the subscription, and can be removed just as easily at any time.
What you're granting
The built-in Azure role Security Reader, assigned to the Zybim assessment app on the subscription(s) you want assessed. This allows reading security scores and findings — it cannot read your data, change resources, or see billing.
Option 1 — Azure Cloud Shell (fastest)
Open shell.azure.com, choose Bash, and run:
loading…
Replace <SUBSCRIPTION_ID> with the subscription to assess (find it under Subscriptions in the Azure portal). Repeat per subscription.
Option 2 — Azure portal
Subscriptions → select your subscription → Access control (IAM) → Add → Add role assignment → role Security Reader → Members → select Zybim assessment app (search by the app ID shown below) → Review + assign.
Covering AWS and GCP too
Defender for Cloud assesses AWS and GCP accounts once they're connected: Defender for Cloud → Environment settings → Add environment. If they aren't connected yet, we'll flag that in your report and can set the connectors up as part of the engagement.
Removing access later
Same IAM screen → Role assignments → remove the Zybim entry. Access ends immediately.
Once done, tell your Zybim contact — we'll run the assessment and bring the consolidated report to your review session.