---
title: Azure Integration
description: How to setup your AgileBlue integration within Azure.
---

[Skip to content](https://help.agileblue.com/azure-integration#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)

# Azure Integration

## How to setup your AgileBlue integration within Azure.

### Setup Steps

1. Log into your [Azure Portal.](https://portal.azure.com/)
2. Click the menu in the top left
   
   ![](https://help.agileblue.com/hs-fs/hubfs/Picture1-png-Mar-09-2026-03-59-08-6407-PM.png?width=670&height=188&name=Picture1-png-Mar-09-2026-03-59-08-6407-PM.png)
3. Select **Resource groups
   
   ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2011-59-29%E2%80%AFAM-png.png?width=670&height=488&name=Screenshot%202026-03-09%20at%2011-59-29%E2%80%AFAM-png.png)**
4. Click **Create**
5. Choose your **Subscription** and name your **Resource group** as follows: 
     1. ab-eventhub-rg
6. Select **Review + create**
7. Navigate back to the top-left menu then select **All services
   
   ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-01-11%E2%80%AFPM-png.png?width=670&height=487&name=Screenshot%202026-03-09%20at%2012-01-11%E2%80%AFPM-png.png)**
8. Click **Analytics**
   
   ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-01-33%E2%80%AFPM-png.png?width=670&height=488&name=Screenshot%202026-03-09%20at%2012-01-33%E2%80%AFPM-png.png)
9. Under **Real-time analytics**, select **Event Hubs
   
   ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-02-06%E2%80%AFPM-png.png?width=670&height=487&name=Screenshot%202026-03-09%20at%2012-02-06%E2%80%AFPM-png.png)**
10. Click **Create**
11. Select **Create new or use existing Resource group**
12. Choose the Resource group created earlier in this guide (**ab-eventhub-rg)**
13. Under **Namespace name** type **ab-namespace**
14. Choose your region from the Azure locations group
15. Under **Pricing tier**, select **Basic**
16. Update **Throughput Units** to **2**
17. Click **Review + create
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-05-30%E2%80%AFPM-png.png?width=670&height=474&name=Screenshot%202026-03-09%20at%2012-05-30%E2%80%AFPM-png.png)**
18. Click **Go to resource**
19. Select **Entities** on the left-hand side
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-06-47%E2%80%AFPM-png.png?width=670&height=488&name=Screenshot%202026-03-09%20at%2012-06-47%E2%80%AFPM-png.png)
20. Click **Event Hubs**
21. Select **+ Event Hub
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-07-39%E2%80%AFPM-png.png?width=670&height=489&name=Screenshot%202026-03-09%20at%2012-07-39%E2%80%AFPM-png.png)**
22. Give the Event Hub the name **azure-logs**
23. Update the **Partition Count** to **2** and set **Retention time (hrs)** to **1**
24. Click **Review + create**
25. Navigate back to the top left-hand menu and select **Monitor**
26. Select **Activity Log**
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-10-07%E2%80%AFPM-png.png?width=670&height=487&name=Screenshot%202026-03-09%20at%2012-10-07%E2%80%AFPM-png.png)
27. Click **Export Activity Logs**
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-10-35%E2%80%AFPM-png.png?width=670&height=488&name=Screenshot%202026-03-09%20at%2012-10-35%E2%80%AFPM-png.png)
28. Select **+Add diagnostic setting**
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-11-09%E2%80%AFPM-png.png?width=670&height=492&name=Screenshot%202026-03-09%20at%2012-11-09%E2%80%AFPM-png.png)
29. Name the **Diagnostic setting** as follows: 
      1. Azure-Logs
30. Under **Logs**, select the following: 
      1. Administrative
      2. Security
      3. Alert
31. Under **Destination details** check off: 
      1. Stream to an event hub
32. Choose your **azure-logs** event hub under the **Event hub name dropdown
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-12-54%E2%80%AFPM-png.png?width=791&height=576&name=Screenshot%202026-03-09%20at%2012-12-54%E2%80%AFPM-png.png)**
33. Click **Save**
34. Navigate back to **ab-namespace
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-14-43%E2%80%AFPM-png.png?width=790&height=576&name=Screenshot%202026-03-09%20at%2012-14-43%E2%80%AFPM-png.png)**
35. In the left-hand menu under **Settings**, select **Shared access policies
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-15-21%E2%80%AFPM-png.png?width=794&height=580&name=Screenshot%202026-03-09%20at%2012-15-21%E2%80%AFPM-png.png)**
36. Select **RootManageSharedAccessKey
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-15-56%E2%80%AFPM-png.png?width=792&height=574&name=Screenshot%202026-03-09%20at%2012-15-56%E2%80%AFPM-png.png)**
37. Copy the value under **Primary key** and save securely – you'll need to provide this back to AgileBlue later
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-18-22%E2%80%AFPM-png.png?width=789&height=576&name=Screenshot%202026-03-09%20at%2012-18-22%E2%80%AFPM-png.png)
38. Next, copy and securely save the **Primary connection string**
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-18-53%E2%80%AFPM-png.png?width=791&height=578&name=Screenshot%202026-03-09%20at%2012-18-53%E2%80%AFPM-png.png)
39. In the search bar, search for and select **Storage accounts
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-19-23%E2%80%AFPM-png.png?width=793&height=578&name=Screenshot%202026-03-09%20at%2012-19-23%E2%80%AFPM-png.png)**
40. Click **Create
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-20-19%E2%80%AFPM-png.png?width=791&height=582&name=Screenshot%202026-03-09%20at%2012-20-19%E2%80%AFPM-png.png)**
41. Name the Storage account **abcollector**
42. Under preferred storage type, select **Azure Blob Storage or Azure Data Lake Storage Gen 2**
43. Under **Redundancy**, select **Geo-redundant storage (GRS)**
44. Once completed, the fields should look as follows (Note: Your subscription and Region name will be specific to your organization):
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-22-08%E2%80%AFPM-png.png?width=790&height=574&name=Screenshot%202026-03-09%20at%2012-22-08%E2%80%AFPM-png.png)
45. Click **Review + create**
46. Click **Create**
47. Select **Go to resource**
48. Select **Security + networking** in the left-hand menu
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-23-36%E2%80%AFPM-png.png?width=793&height=576&name=Screenshot%202026-03-09%20at%2012-23-36%E2%80%AFPM-png.png)
49. Click **Access keys**
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-24-20%E2%80%AFPM-png.png?width=791&height=577&name=Screenshot%202026-03-09%20at%2012-24-20%E2%80%AFPM-png.png)
50. Click **Show** then copy the **Key** and **Connection string** values, which will need to be provided to AgileBlue
51. Navigate to **Microsoft Entra ID**
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-25-24%E2%80%AFPM-png.png?width=790&height=576&name=Screenshot%202026-03-09%20at%2012-25-24%E2%80%AFPM-png.png)
52. Click **Monitoring** then **Diagnostic settings
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-26-07%E2%80%AFPM-png.png?width=793&height=581&name=Screenshot%202026-03-09%20at%2012-26-07%E2%80%AFPM-png.png)**
53. Select **+Add diagnostic setting**
54. Under **Logs,** check off: 
      1. **AuditLogs**
      2. **SignInLogs**
      3. **NonInteractiveUserSignInLogs**
      4. **ServicePrincipalSignInLogs**
      5. **ManagedIdentitySignInLogs**
      6. **ProvisioningLogs**
      7. **ADFSSignInLogs**
      8. **RiskyUsers**
      9. **UserRiskEvents**
      10. **RiskyServicePrincipals**
      11. **MicrosoftServicePrincipalSignInLogs**
      12. **MicrosoftGraphActivityLogs**
55. Under **Destination details** specify **Stream to an event hub**
56. Name the **Diagnostic setting** entra-logs
57. Under **Destination Details**, specify your previously-used Subscription, Event hub namespace, Event hub name, Event hub policy name:
    
    ![](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202026-03-09%20at%2012-31-49%E2%80%AFPM-png.png?width=793&height=580&name=Screenshot%202026-03-09%20at%2012-31-49%E2%80%AFPM-png.png)
58. Click **Save**
59. Securely send the following values back to AgileBlue Support (support@agileblue.com): 
      1. **Event Hub Name** (should be azure-logs)
      2. **Connection String**
      3. **Storage Account Name** (should be abcollector)
      4. **Storage Account Key**

*Questions? Contact AgileBlue Support.*

*Email: support@agileblue.com*  
*Phone: (216) 606-9400*

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue