You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Azure Functions中为Microsoft Sentinel使用托管标识

在Azure Functions中为Sentinel Python SDK配置托管标识

完全可以在Azure Functions中使用托管标识替代AZ CLI凭据,调用Sentinel的Python SDK(azure-mgmt-securityinsight),以下是实操步骤和注意事项:

1. 为Azure Functions启用托管标识

你可以选择两种托管标识类型:

  • 系统分配标识:直接在Function App的「身份」面板中开启,系统会自动为该应用生成一个唯一标识,删除Function App时标识也会被同步删除。
  • 用户分配标识:先在Azure门户创建独立的托管标识资源,再在Function App的「身份」面板中关联该标识,适合跨应用共享标识的场景。

2. 为托管标识配置Sentinel权限

Sentinel依赖Log Analytics工作区,需要给托管标识分配对应的RBAC角色:

  • 若需读写操作:分配Security Insights Contributor角色
  • 若仅需只读访问:分配Security Insights Reader角色

操作路径:在目标Log Analytics工作区(或Sentinel资源)的「访问控制(IAM)」面板中,添加角色分配,选择对应的托管标识作为主体。

3. Python代码实现

使用azure-identity库中的ManagedIdentityCredential获取凭据,无需依赖本地AZ CLI,示例代码如下:

from azure.mgmt.securityinsight import SecurityInsights
from azure.identity import ManagedIdentityCredential
import os

def main(req):
    # 初始化托管标识凭据
    credential = ManagedIdentityCredential()
    
    # 从环境变量读取配置(推荐在Function App的应用设置中配置)
    subscription_id = os.environ["SUBSCRIPTION_ID"]
    resource_group_name = os.environ["RESOURCE_GROUP_NAME"]
    workspace_name = os.environ["WORKSPACE_NAME"]

    # 初始化Sentinel客户端
    sentinel_client = SecurityInsights(credential, subscription_id)

    # 示例:获取所有Sentinel告警规则
    alert_rules = sentinel_client.alert_rules.list(resource_group_name, workspace_name)
    rule_names = [rule.name for rule in alert_rules]
    
    return f"Found {len(rule_names)} alert rules: {', '.join(rule_names)}"

4. 关键注意事项

  • 本地测试:若要在本地模拟托管标识,可设置环境变量AZURE_CLIENT_ID为托管标识的客户端ID,同时确保本地已通过AZ CLI登录(需有足够权限)。
  • 权限范围:如果Sentinel资源和Function App不在同一订阅,需在目标订阅的IAM中也为托管标识分配对应角色。
  • 版本兼容:确保azure-mgmt-securityinsight和azure-identity使用最新稳定版本,避免出现凭据认证或API调用的兼容性问题。

内容的提问来源于stack exchange,提问作者Fares

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 02:31:15