# Deploy in Azure

Learn how to deploy your first TrapEye instance in Microsoft Azure. This guide focuses on the manual deployment through the Azure portal, but the same workflow applies when using IaC tools such as **Terraform** or the [Azure CLI](https://docs.microsoft.com/en-us/cli/azure/).

:::note
Azure deployment is based on a **Bring Your Own License (BYOL)** model. You can deploy instances for free, but you need a valid account in the TrapEye console to retrieve events and manage your devices.

If you don't have an account yet, you can [request a free trial](https://anantis.io/request-free-trial).
:::

--- 

## Create a New Virtual Machine

1. Navigate to **Network foundation -> Virtual networks** and select the private network where your TrapEye agent will be deployed.

   Write down the `Name` and `Location` of the private network, you will need this information during the vm creation process.

    ![Choose Private Network Image](~/assets/images/docs/installation/azure/priv_network.webp)

1. From the **Virtual Machine** section, click on `Create -> Virtual machine` to start the virtual machine creation process.

   ![Create VM](~/assets/images/docs/installation/azure/create-vm.webp)

2. Choose a `Resource Group`, `Name`, `Region` according to the Virtual network identified in the earlier steps.

   Set the `Security type` to **Standard** and click on **See all images**.

    ![Configure VM](~/assets/images/docs/installation/azure/vm-config.webp)

2. In the **Marketplace Search Menu**, search for `TrapEye` and select the image from the list.

   ![Select TrapEye Image](~/assets/images/docs/installation/azure/marketplace.webp)

2. Choose the `Size` for your virtual machine using the recommended values below:

   | Resource | Minimum Value | Recommended Value |
    |-----------|-------------------| -------------------|
    | **CPU**   | 1 vCPUs           | 1 vCPUs           |
    | **Memory**| 1024 MiB (1 GB)   | 2048 MiB (2 GB)   |
    | **Disk**  | 10GB              | 10GB              |

    
2. You can let the default **Administrator Account** settings, it will be not be used since the TrapEye image does not support direct access to the virtual machine.

   On the **Inbound port rules**, select `None` to ensure that no ports are exposed to the internet.

    ![Select TrapEye Image](~/assets/images/docs/installation/azure/default-settings.webp)

3. In the `Networking` tab, select the **Virtual network** identified in the earlier steps. Choose a **Subnet**.

   For the `Public IP` setting:
    - Set it to `None` **only if** your virtual network already has outbound internet access configured via a **NAT Gateway** or a **Load Balancer** with outbound rules.
    - Otherwise, **assign a Public IP** to ensure the TrapEye instance can reach the ingestion endpoint.

    ![Configure VM network](~/assets/images/docs/installation/azure/create_vm_networking.webp)

    :::note
    TrapEye agents support only **one** network interface per instance. 
    This design ensures attackers cannot use a trap to pivot or move laterally within your environment.
    
    If multiple interfaces are present (e.g. one private and one public), the agent will default to using the **private IP**.
    :::

    :::caution
    Since **March 31, 2026**, Azure no longer provides default outbound internet access for VMs without a public IP. If your virtual network does not have a NAT Gateway or a Load Balancer with outbound rules, the TrapEye instance will not be able to connect to the ingestion endpoint and will not appear in the platform.

    See [Azure default outbound access](https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/default-outbound-access) for more details.
    :::

6. From the TrapEye Platform, go to **Management → Installation** and copy the values for `entity_uuid`, `auth_token` and `url`.

7. **Replace** the placeholder values in the template below with your TrapEye configuration parameters, then paste the final result into the **Custom Data** field in the `Advanced` tab.

   ```
    #cloud-config
    write_files:
      - path: /etc/trapeye/auth-config.toml
        permissions: '0600'
        content: |
          entity_uuid = "ENTITY-UUID-HERE"
          auth_token = "ENTITY-TOKEN-HERE"
          url = "INGESTION-URL-HERE"
    ```

    **Example:**

    ![Config Menu](~/assets/images/docs/installation/azure/custom-data.webp)

8.  Click **Review + create** to build the virtual machine.

## Setup complete

Your TrapEye virtual machine has been successfully deployed in **Azure**. 

It will now appear in the **Devices** section of the TrapEye Deception Platform, and you will begin receiving real-time alerts as soon as any activity is detected.