Skip to main content

Overview

This guide walks through how to create a Microsoft Azure connection and the permissions it requires to be used in Blink’s Automated Case Management, primarily for Enrichment workflows (Azure resource activity logs and resource enrichment).
The Azure connection talks to the Azure Resource Manager (ARM) API, which authorizes differently from the Microsoft Graph–based security products (Defender, Sentinel, Entra ID, etc.). ARM uses Azure role-based access control (Azure RBAC) (you assign a role to a service principal at a chosen scope) rather than Microsoft Graph API scopes. For this reason, there is no Microsoft Graph connection option for Azure. See Required Permissions.

Creating a Connection

Microsoft Azure Connection Guide

Follow this guide to create a Microsoft Azure connection

Required Permissions

Azure access is granted by assigning an Azure RBAC role to the connection’s service principal at a chosen scope (subscription, resource group, or resource).