Azure Activity
  • 14 Jan 2025
  • 1 Minute to read
  • Contributors
  • Dark
    Light

Azure Activity

  • Dark
    Light

Article summary

Azure Activity Logs provide a comprehensive record of actions capturing operations that impact resources, such as creating, updating, or deleting. They cover various categories, including administrative actions, service health events, alert triggers, and policy compliance checks.

Integration Method: API
Tables: Detection, Compliance, Entity Management
Events: Administrative, Alerts, Policy changes, Security

Azure Configuration

Step 1. Create an App registration

Step 2. Register the application

A screenshot of a computer  Description automatically generated

Step 3. Add a client Secret

Step 4. Locate the Tenant ID - Find the Tenant ID on the application’s Overview page.

A screenshot of a computer  Description automatically generated

Step 5. Configure Permissions - Set up the following permissions:

Permission Name

Type

AccessReview.Read.All

Delegated

AccessReview.Read.All

Application

AuditLog.Read.All

Delegated

AuditLog.Read.All

Application

User.Read

Delegated

Assign a Reader Role to the Subscription

  • Navigate to Home > Subscriptions and select the appropriate subscription the application should be given access to. In this example, it is the CDS_R15_Sub1 subscription

  • Select Access Control (IAM), click on Add and select “Add role assignment


  • Select Reader role and click on Next

  • Click on Select members and add the “Test Application” created earlier, click on Next

  • Under Assignment type tab, choose the assignment duration. Selecting permanent will ensure data will flow into your DataBee tenant without interruption. Click on Review + assign.

DataBee Configuration

  1. Login to the DataBee console and navigate to the Data > Data Sources tab

A screenshot of a computer  Description automatically generated

  1. Click on Add New Source

A screenshot of a computer  Description automatically generated

  1. Search for Azure Activity and select it

A screenshot of a computer  Description automatically generated

  1. Select API Ingest

  2. Enter basic contact information in the dialog box and click Next

  3. In the detailed configuration boxes, ensure the following fields are filled

    • Authorization Method: OAuth2

    • Client Key: Paste the client key generated in the Microsoft console

    • Secret Key: Paste the client secret generated in the Microsoft console

    • API URL: https://management.azure.com/subscriptions/<subscriptionId>/providers/Microsoft.Insights/eventtypes/management/values?&api-version=2015-04-01

    • Token URL:  https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/token

Replace the <tenant_id> and <subscriptionId> placeholders with your tenant information

A screenshot of a computer  Description automatically generated

  1. Click Submit


Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Eddy AI, facilitating knowledge discovery through conversational intelligence