Overview
This guide walks through how to create a Microsoft Azure connection and the permissions it requires to be used in Blink’s Automated Case Management, primarily for Enrichment workflows (Azure resource activity logs and resource enrichment).The Azure connection talks to the Azure Resource Manager (ARM) API, which authorizes differently from the Microsoft Graph–based security products (Defender, Sentinel, Entra ID, etc.). ARM uses Azure role-based access control (Azure RBAC) (you assign a role to a service principal at a chosen scope) rather than Microsoft Graph API scopes. For this reason, there is no Microsoft Graph connection option for Azure. See Required Permissions.
Creating a Connection
Microsoft Azure Connection Guide
Follow this guide to create a Microsoft Azure connection
Required Permissions
Azure access is granted by assigning an Azure RBAC role to the connection’s service principal at a chosen scope (subscription, resource group, or resource).Which stage of Alert Processing need this connection?
Which stage of Alert Processing need this connection?