elastic / elastic/integrations

[cloud_asset_inventory] Agentless deployment shows as healthy when Azure secret has expired

Open
#17,292 0 comments 0 reactions 0 assignees View on GitHub
Integration:cloud_asset_inventory needs:triage Team:security-siem-conduit
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Cloud Asset Discovery [cloud_asset_inventory]

### Dataset Name

_No response_

### Integration Version

1.4.0

### Agent Version

Agentless

### Agent Output Type

elasticsearch

### Elasticsearch Version

9.3.0

### OS Version and Architecture

Agentless

### Software/API Version

_No response_

### Error Message

There is no error message. The status simply reports as "healthy".

This also applies to at least Cloud Security Posture Management (3.4.0)

### Event Original

_No response_

### What did you do?

The client secret used for these integration expired on 2026.01.26
The integrations (eg M365 Defender XDR, Microsoft 365 Audit) using Elastic Agent correctly showed as "unhealthy" when this happened. Agentless did not.

### What did you see?

- Healthy Status for the two named agentless integrations
- The "Findings" page would try to load misconfigurations but never complete. It immediately worked after updating the secret.

### What did you expect to see?

An "unhealthy" status indicating that the integration can't pull data.

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.