Overview
Discovery lets you find certificates across cloud providers, network appliances, and internal servers on a scheduled basis.
Supported providers
| Provider | Discovers certificates | Creates Stores automatically |
|---|---|---|
| Amazon AWS (ACM) | ✅ | ❌ |
| Microsoft Azure (Key Vault) | ✅ | ✅ |
| Microsoft Azure (Enterprise Apps) | ✅ | ❌ |
| Microsoft AD CS | ✅ | ❌ |
| Microsoft IIS | ✅ | ✅ |
| F5 BIG-IP | ✅ | ✅ |
| Citrix NetScaler | ✅ | ✅ |
| DigiCert | ✅ | ❌ |
How to create a Discovery Job
Go to Discovery → Scans and click + Create Discovery Job to open the Discovery Wizard.
The wizard guides you through 4 to 6 steps depending on the provider. The steps common to all providers are:
Provider → Integration → Schedule → Review
Providers with more granular scope control add extra steps between Integration and Schedule.
Select the guide for the provider you want to configure:
Advanced scheduling options
Available for all providers:
| Option | Description |
|---|---|
| Run on first save | Runs the discovery immediately after saving the job |
| Send email notification on completion | Sends an email when the discovery completes successfully |
| Send alert on discovery failure | Sends an alert when the job fails (enabled by default) |
| Auto-import new certificates | Automatically imports discovered certificates into the inventory |
Tracking runs
In the Scans list, each job displays the status of its last run, the number of certificates found, and the next scheduled run. Click the job to see the full history and detailed results.