Monitor your Microsoft Entra ID activity on the AgileBlue Security Operations Platform. This integration supports sign-in logs, audit logs, identity protection logs, and provisioning logs.
Setup Guide
Create a Resource Group
- Log into your Azure Portal
- Select Resource Group from the menu then click + Create
- Designate the Subscription in which the resource group should be created
- Assign a unique name to the group (Ex. AgileBlue-Resource-Group)
- Select the Region
- Click Review + Create
Create an Event Hubs Namespace
- Navigate to All Services in the left-hand menu and click Event Hubs under Analytics
- Click + Create in the top left-hand corner
- Select the subscription in which you want to create the namespace
- Choose the Resource Group created in the prior section
- Input name for the Event Hubs Namespace
- Select a Location
- Ensure the pricing tier is set to Basic and leave the Throughput Units setting as is (1)
- NOTE: Do not enable auto-inflate unless you would like the Event Hubs to automatically increase the number of throughput units to meet usage needs in the event of an overage. This setting will prevent possibly delays or loss of data but could lead to increased costs.
- Click Review + Create
- Review the settings then click Create and wait for the deployment to complete
- Once on the Deployment page, click Go to resource
- Verify that you see the Event Hubs namespace page with the name provided earlier in this section
Create an Event Hub
- While on the Event Hubs namespace Overview page, click +Event Hub
- Give a name for the event hub (all lower case, no special characters other than -)
- Leave all other settings as default
- Click Review + create
- On the following page, select Create if all settings look accurate
- Once the Event Hub is created, you will see it under the list of Event Hubs in the Event Hubs Namespace
Enable Microsoft Entra ID Logging
- From the Azure Portal homepage, click Microsoft Entra ID
- Under the left-hand menu, navigate to Monitoring and click Sign-in logs
- Select Export Data Settings at the top of the page
- Click + Add diagnostic setting
- Add a name for the Diagnostic Setting
- Select all desired Log categories – for this integration we recommend a minimum of the following:
- AuditLogs
- SignInLogs
- NonInteractiveUserSignInLogs
- ServicePrincipalSignInLogs
- ManagedIdentitySignInLogs
- ProvisioningLogs
- Risky Users
- UserRiskEvents
- Under Destination details select Stream to an event hub
- Select the Subscription, Event hub namespace, Event hub name, and Event hub policy name corresponding to the information created int he previous sections
- Click Save
Gather Required Information
- Event Hub Connection string-primary key
- Navigate to the Event Hubs namespace and select Shared Access Policies
- Click RootManageSharedAccessKey and copy the connection string-primary key, which will need to be provided to AgileBlue
- Storage Account
- Navigate to All Services > Storage > Storage Accounts
- Click Create Storage Account and complete the settings based on the information created so far in this guide
- Note the Storage account name which will need to be provided to AgileBlue
- Click Review + create
- On the review page, copy the Storage Account Name and the values under Key 1 (Key and Connection string)
Send Required Information to AgileBlue
Once all prior steps have been completed, send the following information back to AgileBlue Support via a secure communication method:
- Event Hub Name (NOTE: This is the name of the event hub, NOT the name of the Event Hubs namespace)
- Connection String
- Storage Account Name
- Storage Account Key
Questions? Contact AgileBlue Support.
Email: support@agileblue.com
Phone: (216) 606-9400