For the complete documentation index, see llms.txt. This page is also available as Markdown.

Offboarding Azure

This article describes how to off-board Data Security Posture Management (DSPM) and remove associated roles, ensuring that DSPM no longer has access or the ability to perform actions within the environment after completion.

NOTE: To temporarily stop DSPM, without offboarding the account, refer to Monitoring an Account.

Do the following for each subscription in the tenant, meaning the subscriptions onboarded to the Prisma Cloud platform.

  1. Navigate to the Subscription’s Access Control (IAM) and click the Role assignments tab. Enter dig-security in the search bar. Ensure that the signed-in user has permissions to view and edit role assignments.

    NOTE: If the resource group was deleted before the role assignments, you may see “Null” values in the Name/Role fields. Be sure to locate and delete these assignments.

  2. Select all relevant assignments and click Remove.

  3. Go to the Roles tab, find and select all dig-security roles, and click Remove.

  4. In the Subscription Resource section, search for dig-security.

  5. If any resource groups are locked, access the lock and delete it (if applicable).

  6. Return to the Resource group Overview page, and delete the resource group.

  7. Click Activity log, and select Export Activity Log for the relevant subscription.

  8. Choose the DSPM setting stream_to_dig_eventhub, and click Edit setting.

  9. In the Diagnostic settings, page, click Delete, and when prompted click Yes.

Last updated

Was this helpful?