> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Azure

## Overview

This guide walks through how to create a Microsoft Azure connection and the permissions it requires to be used in Blink's Automated Case Management, primarily for **Enrichment** workflows (Azure resource activity logs and resource enrichment).

<Note>
  The Azure connection talks to the **Azure Resource Manager (ARM)** API, which authorizes differently from the Microsoft Graph–based security products (Defender, Sentinel, Entra ID, etc.). ARM uses **Azure role-based access control (Azure RBAC)** (you assign a role to a service principal at a chosen scope) rather than Microsoft Graph API scopes. For this reason, there is no Microsoft Graph connection option for Azure. See [Required Permissions](#required-permissions).
</Note>

***

## Creating a Connection

<Card title="Microsoft Azure Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/azure">
  Follow this guide to create a Microsoft Azure connection
</Card>

***

## Required Permissions

Azure access is granted by assigning an **Azure RBAC role** to the connection's service principal at a chosen scope (subscription, resource group, or resource).

| Role | Access | Needed for |
| - | - | - |
| `Reader` | Read-only access to Azure resources and their metadata | Azure resource enrichment and activity log lookups (recommended default) |
| `Contributor` | Read/write access to manage resources | Only if Blink must create or modify Azure resources |

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✗ No | Not applicable |
    | Enrichment | ✓ Yes | Azure resource activity log and resource enrichment (`Reader`) |
    | Response | ✗ No | Not applicable |
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.