we have a requirement to monitor only dB servers in azure environment  i need help what are the data's  to be collected and configuration to be done  from azure end , i have referred this doc  few things like, they are not ready to give Tenant ID,Client ID ,the other option is to use credential profile, so i need what are the permissions to be given for that user ?  document says global administrator is it necessary to give global admin?  and any ports to be opened from that db server?

ours is sitescope 2022.05 in windows environment