AppServiceCertificateOrders API Client is the Azure Resource Manager surface for managing App Service Certificates — the Azure-managed TLS certificate offering for App Service Web Apps. It covers the full certificate order lifecycle: placing orders, validating registration data, retrieving and reissuing certificates, renewing before expiry, and resending email or domain verification. Certificates issued through the API can be deployed directly to App Service apps and Key Vault.
20 endpointsAttestationClient is the per-tenant Azure Attestation Service API used to verify the integrity of trusted execution environments such as Intel SGX enclaves and TPM-backed workloads. It exposes the OpenID Connect discovery document, the signing certificate set used to verify attestation tokens, and the policy management endpoints that govern how attestation requests are evaluated. Use this client to validate confidential compute workloads or to maintain attestation policy.
6 endpointsThe Azure CDN Web Application Firewall Management API configures WAF policies and managed rule sets attached to Azure CDN endpoints. It exposes operations to list, create, update, and delete CdnWebApplicationFirewallPolicies under Microsoft.Cdn, plus a discovery endpoint for the managed rule sets that ship with the service. Each policy bundles custom rules, managed rule sets, and rate-limit rules that Azure CDN evaluates on incoming HTTP requests.
6 endpointsThe Azure Dedicated HSM Resource Provider API manages single-tenant Hardware Security Module appliances (Microsoft.HardwareSecurityModules/dedicatedHSMs) provisioned into a customer's virtual network. It exposes operations to list, create, update, and delete HSM resources scoped to a subscription or resource group. Dedicated HSMs are FIPS 140-2 Level 3 validated and intended for workloads that need direct, exclusive control of cryptographic hardware rather than the multi-tenant Key Vault service.
6 endpointsJentic publishes the only available OpenAPI specification for Azure SQL Database Datamasking Policies and Rules, keeping it validated and agent-ready. The API manages dynamic data masking on Azure SQL databases under Microsoft.Sql, exposing the per-database dataMaskingPolicies resource and its child rules. Through 4 endpoints it supports reading and updating the masking policy and creating, listing, and deleting per-column rules so non-privileged users see masked values for sensitive fields.
4 endpointsJentic publishes the only available OpenAPI specification for CertificateRegistrationProvider API Client, keeping it validated and agent-ready. The Microsoft.CertificateRegistration resource provider exposes its operations metadata so callers can enumerate the App Service certificate registration capabilities available in their subscription. It is the discovery surface for the App Service Certificate flow used to purchase, validate, and renew SSL certificates managed by Azure.
1 endpointsJentic publishes the only available OpenAPI specification for Certificates API Client, keeping it validated and agent-ready. The Azure App Service Certificates management API administers certificate resources stored under Microsoft.Web. It supports listing certificates by subscription or resource group, retrieving a specific certificate by name, and creating, updating, or deleting certificates that App Service apps consume for SSL binding.
6 endpointsJentic publishes the only available OpenAPI specification for Customer Lockbox, keeping it validated and agent-ready. The Azure Customer Lockbox API exposes 4 operations across 4 paths to review and respond to Microsoft engineer access requests against your subscription's data. When a Microsoft support engineer requires data-plane access during a support case, a Lockbox request is generated and must be approved or denied by an authorised customer. This API lets agents and automation systems list pending requests, fetch a specific request, and update its approval status without manual portal use.
4 endpointsJentic publishes the only available OpenAPI specification for GuestConfiguration, keeping it validated and agent-ready. The Azure Guest Configuration API assigns and audits in-guest configuration policies on Azure VMs through the Microsoft.GuestConfiguration resource provider. It lets operators apply DSC-based configuration packages, read compliance reports per VM, and enumerate the operations the resource provider supports. The API is delivered as part of Azure Resource Manager and authenticated via Azure AD OAuth2 against management.azure.com.
7 endpointsJentic publishes the only available OpenAPI specification for IntuneResourceManagementClient, keeping it validated and agent-ready. The Microsoft.Intune resource provider API manages mobile application management (MAM) policies for iOS and Android applications under an Azure tenant. It exposes 33 ARM endpoints to define platform-specific app protection policies, attach them to managed apps and AAD groups, and surface flagged users whose devices have triggered policy violations.
33 endpointsJentic publishes the only available OpenAPI specification for the Azure Key Vault data plane (7.0-preview), keeping it validated and agent-ready. The KeyVaultClient performs cryptographic key operations and secret, certificate, and storage account credential operations against a vault host such as https://myvault.vault.azure.net. It exposes 78 endpoints to manage keys, secrets, certificates and their policies, soft-deleted resources and recovery, certificate issuers and contacts, and storage account access definitions.
78 endpointsJentic publishes the only available OpenAPI specification for KeyVaultManagementClient, keeping it validated and agent-ready. KeyVaultManagementClient is the Azure Stack admin control-plane API for the Microsoft.KeyVault.Admin resource provider. It exposes the operations catalog used by Azure Stack Hub administrators to inspect what management actions the local Key Vault provider supports. The surface is intentionally narrow and is designed for hub-level introspection rather than vault, key, or secret data operations.
1 endpointsJentic publishes the only available OpenAPI specification for PolicyClient, keeping it validated and agent-ready. The Azure Policy management API exposes 13 operations under Microsoft.Authorization for managing policy definitions and policy assignments. Use it to author custom policy definitions, assign built-in or custom policies at subscription, resource group, or individual resource scope, and remove assignments when a control is no longer required. This is the foundational governance plane that enforces tagging, naming, location, and SKU rules across an Azure estate.
13 endpointsJentic publishes the only available OpenAPI specification for PolicyEventsClient, keeping it validated and agent-ready. The Azure Policy Insights events API exposes 9 query endpoints under Microsoft.PolicyInsights for retrieving the historical stream of policy evaluation events. Use it to query events at management group, subscription, resource group, individual resource, policy assignment, policy definition, or policy set definition scope, with OData filters for time range, compliance state, and policy identifiers — the audit log behind every Azure Policy compliance state change.
9 endpointsJentic publishes the only available OpenAPI specification for PolicyMetadataClient, keeping it validated and agent-ready. The Azure Policy Insights metadata API exposes 2 read endpoints under Microsoft.PolicyInsights for retrieving regulatory and descriptive metadata about policy definitions and initiatives. Use it to look up the regulatory standards a built-in policy maps to (CIS, ISO 27001, NIST, PCI DSS, HIPAA), the rationale behind a policy, and additional context that helps governance teams justify and document policy choices in audits.
2 endpointsJentic publishes the only available OpenAPI specification for PolicyStatesClient, keeping it validated and agent-ready. The Azure Policy Insights states API exposes 18 query and summary endpoints under Microsoft.PolicyInsights for retrieving the current compliance state of resources against assigned policies. Use it to query compliance state at management group, subscription, resource group, individual resource, policy assignment, policy definition, or policy set definition scope, and to retrieve aggregated compliance summaries that power compliance dashboards and alerting.
18 endpointsJentic publishes the only available OpenAPI specification for PolicyTrackedResourcesClient, keeping it validated and agent-ready. The Azure Policy Insights tracked resources API exposes 4 query endpoints under Microsoft.PolicyInsights for retrieving the inventory of resources that deployIfNotExists and modify policy effects have created or altered. Use it to verify that remediation actions actually ran, list the resources spawned by an initiative, or audit which deployments are owned by policy rather than direct user action — at management group, subscription, resource group, or individual resource scope.
4 endpointsJentic publishes the only available OpenAPI specification for Security Center, keeping it validated and agent-ready. The Azure Security Center API exposes the Microsoft.Security resource provider so agents can configure cloud security posture, manage pricing tiers for Defender plans, set security contacts, and inspect compliance state across an Azure subscription. It covers auto-provisioning settings, workspace settings, advanced threat protection, and compliance results that map to regulatory frameworks. The API is scoped at the subscription, resource group, or resource level and is used to read and tune the controls that protect Azure workloads.
29 endpointsJentic publishes the only available OpenAPI specification for Security Insights, keeping it validated and agent-ready. The Azure Security Insights API exposes the Microsoft.SecurityInsights resource provider that powers Microsoft Sentinel, the Azure-native SIEM. It lets agents manage scheduled and Microsoft-source alert rules, attach automated actions to those rules, and connect telemetry data sources such as Office 365, AAD, AWS CloudTrail, and threat intelligence feeds into a Log Analytics workspace. The API is workspace-scoped and is the same control plane the Microsoft Sentinel portal uses under the hood.
13 endpointsThe Azure WebApplicationFirewallManagement API manages Azure Front Door Web Application Firewall (WAF) policies and inspects the managed rule sets that Microsoft maintains for blocking common web exploits. It exposes five management plane operations across three resource paths under Microsoft.Network, covering policy create-or-update, policy retrieval and deletion, listing policies in a resource group, and listing managed rule sets globally for a subscription. Use it to script WAF policy lifecycle, attach policies to Front Door endpoints, and audit which managed rule set versions are available before assigning them.
5 endpointsThe Azure WindowsESU API manages Multiple Activation Keys (MAK) that enable Windows Extended Security Updates for end-of-support Windows versions such as Windows Server 2008 and Windows 7. It exposes 7 operations across 4 resource paths under the Microsoft.WindowsESU provider, covering MAK creation, retrieval, listing per resource group or subscription, and deletion. Use it to script ESU key issuance, audit existing keys, and decommission keys that are no longer needed for compliance reporting.
7 endpointsStep 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.