Knowledge base

Deploy RC-Scanner on Microsoft Azure

Support Level: Tier 2 (Compatible Platform)
Microsoft Azure is categorized as a Tier 2 (Compatible) deployment platform under Outpost24's Supported Deployment Platforms for RC-Scanners.

  • Software Support: Outpost24 Support provides best-effort assistance for RC-Scanner software functionality once the VM has successfully booted and meets minimum requirements.

  • Infrastructure & Cloud Scope: Cloud-specific infrastructure configuration, disk image conversion, and Azure import processes remain the customer's responsibility.

Purpose

This article describes how to deploy RC-Scanner as a virtual appliance in Microsoft Azure. It covers preparation of the installation image in Hyper-V, upload of the fixed VHD to Azure, virtual machine creation, SSH access, and bootstrap registration in the OUTSCAN Portal.

Introduction

Azure does not boot the RC-Scanner ISO directly for this deployment method. First install the ISO in a Generation 2 Hyper-V virtual machine, then convert the resulting virtual disk to a fixed VHD. Upload the VHD as a managed disk and create an Azure virtual machine from that disk.

The deployment consists of five phases:

  1. Prepare the RC-Scanner VHD in Hyper-V.

  2. Upload the VHD as an Azure managed disk.

  3. Create and configure the Azure virtual machine.

  4. Connect to the VM over SSH and change the default password.

  5. Run the bootstrap command and verify registration in the OUTSCAN Portal.

Important: Use a Generation 2 VM throughout the preparation and Azure deployment process. Azure requires a fixed .vhd file for this workflow; do not upload the dynamic .vhdx file.

Prerequisites

  • Access to the latest RC-Scanner ISO from the OUTSCAN Portal, under Configurations → RC SCANNER.

  • Microsoft Hyper-V with permission to create and manage virtual machines.

  • A Microsoft Azure account with permission to create resource groups, managed disks, virtual machines, networking resources, and SSH access.

  • Microsoft Azure Storage Explorer installed and available. Download it from Microsoft Azure Storage Explorer.

  • PowerShell with permission to run Hyper-V disk-conversion commands, or access to the Hyper-V disk-editing interface.

  • An SSH client or terminal.

  • Network access that meets the RC-Scanner firewall requirements. Review Firewall Rules RC-Scanners.

  • RC-Scanner sizing information. Review the RC-Scanner Dimensioning Guide before selecting the Azure VM size.

Phase 1: Prepare the VHD in Hyper-V

This phase creates a Generation 2 Hyper-V VM, installs RC-Scanner from the ISO, and converts the disk to a fixed VHD that Azure can use.

Create the virtual machine

  1. Download the latest RC-Scanner ISO from the OUTSCAN Portal.

  2. Open Hyper-V Manager.

  3. Select New → Virtual Machine.

  4. Configure the wizard with the following settings:

Setting

Recommended value

Name

RC-Scanner-Prep, or another descriptive name

Generation

Generation 2

Memory

At least 2048 MB; 4096 MB recommended for preparation

Network

An active virtual switch with DHCP, such as Default Switch

Virtual disk

30 GB

Installation media

The downloaded RC-Scanner ISO

  1. Finish the wizard to create the VM.

Configure Secure Boot

  1. Right-click the new VM and select Settings.

  2. Select Security.

  3. Ensure Enable Secure Boot is selected.

  4. Set the template to Microsoft UEFI Certificate Authority.

  5. Select Apply, then OK.

The Microsoft UEFI Certificate Authority template is required for the Debian-based RC-Scanner installer to boot correctly in a Generation 2 VM.

Run the unattended installation

  1. Right-click the VM and select Start.

  2. Open the VM console by selecting Connect.

  3. Allow the installer to run. It installs the Debian base operating system and RC-Scanner packages automatically.

  4. Wait for the VM to shut down when installation is complete.

  5. Start the VM again and confirm that it reaches the login prompt.

  6. Shut down the VM before converting the disk.

Convert the disk to a fixed VHD

Azure requires a fixed VHD. Do not upload the dynamic .vhdx file.

PowerShell

Open PowerShell as Administrator and run:

PowerShell
Convert-VHD -Path "C:\Path\To\RC-Scanner-Prep.vhdx" -DestinationPath "C:\Path\To\RC-Scanner-Azure.vhd" -VHDType Fixed

Hyper-V Manager

  1. Select Edit Disk….

  2. Locate the Hyper-V .vhdx file.

  3. Select Convert.

  4. Choose VHD as the disk format.

  5. Choose Fixed size as the disk type.

  6. Select the destination path and complete the wizard.

Use the resulting RC-Scanner-Azure.vhd file in the next phase.

Phase 2: Upload the VHD to Azure

Create or select a resource group

  1. Sign in to the Azure Portal https://portal.azure.com/.

  2. Create a resource group if one does not already exist, or select an existing resource group approved for the deployment.

    image-20260922-071933.png
  3. Record the resource group and Azure region. Use the same region for the managed disk and virtual machine.

Upload the VHD as a managed disk

  1. Open Microsoft Azure Storage Explorer.

  2. Navigate to Disks.

  3. Select Upload.

  4. For Source VHD, select the fixed RC-Scanner-Azure.vhd file.

  5. Set OS Type to Linux.

  6. Select the required Azure Location.

  7. Set Hyper-V generation to V2.

  8. Start the upload and wait for it to complete.

    image-20260922-071949.png


    image-20260928-112737.png


    image-20260928-112119.png

Upload duration depends on the VHD size and available bandwidth. Do not close Storage Explorer or modify the source file while the upload is running.

Phase 3: Create the Azure virtual machine

Locate the uploaded disk

  1. Open the selected resource group in the Azure Portal.

  2. Locate and open the newly created managed disk.

  3. Select Create VM.

    image-20260922-072026.png

Configure the virtual machine

  1. Enter a descriptive Virtual machine name, such as RCSA001.

  2. For Availability options, select No infrastructure redundancy required, unless the deployment design requires another option.

  3. If infrastructure redundancy is required, confirm that the disk and selected VM configuration support the required availability zone or set.

  4. For Licensing, select Other.

  5. Select a VM size that meets the approved RC-Scanner Dimensioning Guide.

  6. Configure the virtual network, subnet, IP addressing, and security rules according to the approved network design.

  7. Allow SSH access only from approved administration networks. Review Firewall Rules RC-Scanners.

Review and create

  1. Select Review + create.

  2. Review the validation results and configuration summary.

  3. Select Create.

  4. When deployment completes, select Go to resource.

    image-20260922-072107.png

Phase 4: Connect over SSH

Record the VM IP address

  1. Open the VM resource overview in the Azure Portal.

  2. Select Connect.

  3. Record the destination VM IP address appropriate for your network design.

Connect and change the default password

Use an SSH client or terminal to connect:

Bash
ssh rcscanner@<destination-vm-ip>
  • Username: rcscanner

  • Initial password: outpost24

At first login, change the initial password immediately. Enter the initial password when prompted, then provide and confirm a new password. Store the new credential according to your organization's password-management policy.

Please note that when you have changed your password you will be disconnected and need to reconnect using the new credentials.

Never leave the initial password active on a deployed scanner. Do not include passwords, tokens, private keys, or other credentials in documentation, tickets, scripts committed to source control, or chat messages.

Phase 5: Complete bootstrap registration

Retrieve the one-time token

  1. Sign in to the OUTSCAN Portal.

  2. Open Configurations → RC SCANNER.

  3. Select the green + button.

  4. Select Continue.

  5. Copy the displayed one-time token.

    image-20260922-072125.png

Run the bootstrap command

In the SSH session, run:

Bash
rc-scanner-bootstrap --token <your-token>

For unattended setup, run:

Bash
rc-scanner-bootstrap --token <your-token> --headless

During an interactive installation, follow the prompts and press F3 when requested.

Verify registration

  1. Return to Configurations → RC SCANNER in the OUTSCAN Portal.

  2. Locate the new scanner.

  3. Confirm that its status changes from Initializing to Connected.

  4. Begin scanning only after the scanner shows as connected.

Troubleshooting

The Hyper-V VM does not boot from the ISO

Confirm that the VM is Generation 2, the ISO is attached, and Secure Boot uses the Microsoft UEFI Certificate Authority template. If the installer still does not boot, verify that the ISO is complete and current.

The Azure upload fails

Confirm that the source file is a fixed .vhd, the selected operating system type is Linux, the Hyper-V generation is V2, and the Azure region is correct. Check available permissions and review the Storage Explorer transfer log.

The VM cannot be reached over SSH

Confirm that the VM is running and that Azure boot diagnostics and health checks show no errors. Verify the current IP address, network security group rules, route configuration, subnet, and TCP port 22 access from the source network. Use an approved network test tool to isolate reachability issues.

The scanner remains in Initializing

Confirm that the bootstrap token was copied correctly and has not expired or already been used. Verify outbound network access required by RC-Scanner and confirm that the VM clock, DNS resolution, and firewall rules are correct. If the issue persists after these checks, collect the relevant bootstrap output and escalate through the approved support process without sharing credentials or tokens.