Home › Install guides › Cloud monitoring (AWS, Azure, Microsoft 365)
Install guide · IT teams and MSPsCloud monitoring (AWS, Azure, Microsoft 365)
Connect AWS, Azure and Microsoft 365 with read-only access and watch cloud resources next to everything else. Included in Core; load balancers and VPN gateways come with Network Pro.
Uplivra Technologies LLC · Guide for Uplivra 26.10 · Updated 1 October 2026 · Latest version: https://uplivra.com/guides/cloud-monitoring.html
What's included, and in which plan
Cloud monitoring is not a separate module. It is part of the plans you already have:
| What | Plan | How it counts |
|---|---|---|
| Microsoft 365 service health (Exchange Online, Teams, SharePoint and the rest) | Core, including the free tier | Doesn't count as a device |
| AWS Health and Azure Service Health incidents for your accounts | Core | Doesn't count as a device |
| AWS: EC2 instances, RDS databases, Lambda functions | Core | 1 Core device each |
| Azure: virtual machines, SQL, PostgreSQL, MySQL and Redis databases, App Service and container apps, storage accounts, Kubernetes (AKS) | Core | 1 Core device each |
| AWS application and network load balancers | Network Pro | 1 Core device each, no extra Network Pro charge |
| Azure load balancers, application gateways, VPN gateways and Azure Firewall | Network Pro | 1 Core device each, no extra Network Pro charge |
Without Network Pro, load balancers and gateways are still listed on the account page, marked Network Pro, so you can see them; they just can't be ticked for monitoring.
Uplivra only reads. It uses a read-only key or app registration, never changes anything in your accounts, and you can revoke it at any time in your provider's console.
Connect an account
- Open Cloud in the menu and pick Amazon Web Services, Microsoft Azure or Microsoft 365 service health.
- Follow the steps on that page. They walk you through creating: - AWS: an IAM policy named
UplivraReadOnly(the page shows the exact text to paste), a user with no console access, and an access key. For several AWS accounts, use a role with the external ID the page shows. - Azure: an app registration with a client secret, given the Reader and Monitoring Reader roles on each subscription. - Microsoft 365: an app registration with the ServiceHealth.Read.All Microsoft Graph application permission and admin consent. - Paste the IDs and secret, pick the regions or subscriptions, and press Connect and test. The secret is encrypted on your server and never shown again.
Pick what to watch
The first read runs within a minute and lists what it finds. Tick the resources to monitor and press Monitor the ticked resources. Each one becomes a device on a site called Cloud, with the same checks, charts, alert rules, maintenance windows and reports as your on-site devices.
Reads run every 5 minutes by default. On AWS, each read uses CloudWatch, which Amazon charges for (about $0.01 per 1,000 metrics). The account page shows an estimate for what you monitor.
Network Pro: cloud load balancers and VPN gateways
With Network Pro on the license, load balancers, application gateways, VPN gateways and Azure Firewall can be ticked like anything else. Uplivra reads availability, backend and host health, requests, server errors, response time, active flows and VPN tunnel traffic, so your cloud edge sits next to your on-site routers and firewalls.
If Network Pro is removed from a license later, those resources stay on the device list but stop being read until it's back. Nothing is deleted.
Other providers
Google Cloud, Oracle Cloud, DigitalOcean, Linode, Vultr, Hetzner, Cloudflare and others can be added on request for a one-time setup fee of $1,000 per provider. After that, each resource is a normal Core device.
Licenses from before October 2026
Cloud Monitoring used to be a separate module. If your license still lists it, nothing changes for you: the old entry is ignored, everything it covered is now in Core (and Network Pro for load balancers and gateways), and it is no longer billed.