M ManySignal
MS
AZ
Integration

Microsoft Azure Integration

Unified Azure security telemetry across subscriptions and tenants.

What this integration does

Microsoft Azure meets agentic SOC

ManySignal connects to Microsoft Azure via the Azure Monitor Diagnostic Settings API, Event Hub streaming, and native REST APIs for Entra ID, Defender for Cloud, and Sentinel. All activity logs, sign-in events, resource configuration changes, and security alerts are ingested into a normalised OCSF timeline covering every Azure subscription enrolled through a single service principal.

Azure Activity Log ingestion via Event Hub or Diagnostic Settings

Entra ID sign-in and audit log collection

Microsoft Defender for Cloud alert correlation

Data collected

  • Azure Activity Logs (control-plane operations across all services)
  • Entra ID Sign-In Logs (interactive, non-interactive, service principal)
  • Entra ID Audit Logs (user, group, application changes)
  • Defender for Cloud security alerts and recommendations
  • Azure Policy compliance events

Actions supported

  • Disable Entra ID user via Graph API on verdict
  • Revoke Entra ID user sessions immediately
  • Create Azure Security Center suppression rule
  • Tag Azure resource with ManySignal investigation label
  • Block network access via Azure Firewall policy update

Getting started

Set up in minutes

  1. 1

    Register an Entra ID app

  2. 2

    Configure Diagnostic Settings

  3. 3

    Add the connector in ManySignal

  4. 4

    Enrol subscriptions

  5. 5

    Enable Defender for Cloud alerts

Microsoft Azure Integration: frequently asked questions

How many subscriptions can ManySignal monitor?

ManySignal supports unlimited Azure subscriptions through a single Entra ID app registration. Add subscription IDs in the connector settings without any per-subscription credential.

Does this replace Microsoft Sentinel?

ManySignal can ingest data from Microsoft Sentinel via the Sentinel integration, or replace it entirely. Many customers run ManySignal as their primary SOC layer and disable or downscale Sentinel, saving significantly on ingestion costs.

What Entra ID permissions are required?

Read-only Graph API permissions: AuditLog.Read.All, Directory.Read.All, User.Read.All. For automated response actions, User.ReadWrite.All or specific administrative roles are also required.

Can ManySignal correlate Azure logs with on-prem AD?

Yes. ManySignal builds an entity graph that correlates Entra ID cloud identities with on-premises Active Directory events ingested via Windows Security Event Log connectors.

How are Azure Entra ID Conditional Access failures handled?

Conditional Access failure events appear in Sign-In Logs with the corresponding error code and policy name. ManySignal detects policy bypass attempts and anomalous conditional access failures as part of identity threat detections.

Is Azure Government (GovCloud) supported?

Yes. Configure the connector with Azure Government endpoints (login.microsoftonline.us, management.usgovcloudapi.net) in the advanced settings.

How long does initial historical backfill take?

Backfill is limited to the retention window of your Diagnostic Settings export (typically 90 days for Entra ID). Initial ingestion of 90 days of logs for a mid-size tenant typically completes within 2–4 hours.

Can ManySignal trigger Logic App workflows?

Yes. ManySignal's universal action layer can POST webhooks that trigger Azure Logic Apps, enabling native Azure automation responses without additional middleware.

What happens if Event Hub has a lag?

ManySignal tracks consumer group offsets and will catch up automatically when Event Hub lag occurs, without dropping events. Alerts for sustained lag are available in the connector health dashboard.

Does ManySignal support Azure China (21Vianet)?

Azure China endpoints are supported via custom endpoint configuration in the connector advanced settings. Contact support for a guided setup if your environment uses 21Vianet.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.