Microsoft Cloud
Phased Rollout
Expanded cloud event sources are being made available through a phased rollout and may not yet be visible to all users. If you don’t see these event sources, your organization hasn’t yet received access. Existing event source functionality remains unchanged in the meantime.
Microsoft Cloud is SIEM (InsightIDR)‘s unified expanded cloud event source for Microsoft 365 and Azure. It connects to your Microsoft Entra ID tenant through a single app registration, then pulls data from three channels: Microsoft Graph (Defender alerts and incidents, Entra sign-ins, users and groups, risky users, Intune devices, and Advanced Hunting), the Office 365 Management Activity API (the unified audit log), and, optionally, an Azure Event Hub streaming feed (Cloud App Events and the Azure Activity Log).
When you configure your Microsoft tenant and connect it to SIEM (InsightIDR)‘s Microsoft Cloud event source, SIEM (InsightIDR) will:
- Parse Microsoft Defender alerts and incidents as third-party alert detections.
- Parse Microsoft Entra ID sign-in and directory events to offer ingress authentication, single sign-on (SSO), cloud service activity, and cloud service admin activity detections.
- Parse unified audit log events (Exchange, Entra ID, and general Microsoft 365 activity) for additional cloud service activity and ingress authentication events.
- If you enable the streaming channel, parse Cloud App Events and Azure Activity Log events for additional cloud service and admin activity visibility.
Streaming is optional
The Event Hub streaming channel (Cloud App Events and Azure Activity Log) is not required to use this event source. If you don’t need this data, you can skip the Event Hub and Blob Storage setup steps below and configure only the Graph and audit log channels.
To set up Microsoft Cloud:
- Read the requirements and complete any prerequisite steps.
- Configure your Microsoft tenant to send data to SIEM (InsightIDR).
- Configure SIEM (InsightIDR) to collect data from the event source.
- Test the configuration.
Requirements
To successfully configure the Microsoft Cloud event source, you must:
- Have Global Administrator or Application Administrator access in Microsoft Entra ID, in order to create an app registration and grant API permissions.
- Have an Azure subscription with rights to create resources, if you’re enabling the streaming channel (an Event Hub namespace and a storage account).
- Have access to the Microsoft Purview compliance portal, in order to verify or enable the unified audit log.
- Collect the following values over the course of this setup, which you’ll enter into SIEM (InsightIDR) at the end:
| Value | Example |
|---|---|
| Tenant ID | xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx |
| Client ID | 84ade012-1b85-4933-95af-573980193a7a |
| Client Secret | opaque string |
| Event Hub namespace hostname | <namespace>.servicebus.windows.net |
| Event Hub name | for example, contoso-telemetry |
| Consumer group | $Default, or a dedicated group |
| Blob Storage account URL | https://<account>.blob.core.windows.net |
| Blob container name | for example, contoso-eventhub-checkpoints |
Event Hub namespace hostname, Event Hub name, Consumer group, Blob Storage account URL, and Blob container name are only required if you enable the streaming channel
If you’re not using Event Hub streaming, you only need the Tenant ID, Client ID, and Client Secret.
Configure your Microsoft tenant to send data to SIEM (InsightIDR)
Complete these tasks to establish communication between SIEM (InsightIDR) and your Microsoft tenant.
Something not quite right?
Sometimes we’re not able to provide the most current information about other vendors. For the most up-to-date information, refer to Microsoft’s documentation, including:
- App registrations in Microsoft Entra ID: https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app
- Add credentials to your app registration: https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app#add-a-client-secret
- Microsoft Graph permissions reference: https://learn.microsoft.com/en-us/graph/permissions-reference
- Office 365 Management Activity API reference: https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference
- Create an event hub: https://learn.microsoft.com/en-us/azure/event-hubs/event-hubs-create
- Turn on auditing in Microsoft Purview: https://learn.microsoft.com/en-us/purview/audit-log-enable-disable
Task 1: Create the Entra ID app registration
Create a single app registration in your tenant. SIEM (InsightIDR) uses this one app registration to authenticate to all three data channels.
To create the app registration:
- Go to the Microsoft Entra admin center: https://entra.microsoft.com/
- Go to App registrations, then click + New registration.
- Enter a Name for the app (for example,
SIEM InsightIDR Integration). - Under Supported account types, select Accounts in this organizational directory only (Single tenant).
- Leave Redirect URI blank. This integration uses the client-credentials flow and doesn’t need one.
- Click Register.
- On the app’s Overview page, record the following values for later use:
- Application (client) ID → this is your Client ID.
- Directory (tenant) ID → this is your Tenant ID.
Task 2: Generate the client secret
To generate a client secret:
- In the app registration, go to Manage > Certificates & secrets.
- Select the Client secrets tab, then click + New client secret.
- Enter a Description that identifies the secret and when it was created, for example
siem-idr-2026-09, to make rotation easier to track. - Set Expires to a maximum of 24 months. This is Microsoft’s policy cap for client secrets.
- Click Add.
- Immediately copy the value in the Value column. This is your Client Secret.
You can only copy the secret value once
Once you navigate away from this page, the secret value is hidden permanently. If you lose it, you’ll need to create a new client secret and revoke the old one.
Task 3: Grant API permissions
Grant the app registration the permissions it needs to read data from your tenant. All permissions must be Application permissions, not delegated permissions.
To grant API permissions:
- In the app registration, go to API permissions, then click + Add a permission.
- Add each permission listed below under the appropriate API, selecting Application permissions each time.
- After adding all required permissions, click Grant admin consent for [your organization].
Required permissions
Microsoft Graph
| Permission | Description |
|---|---|
| AuditLog.Read.All | Read all audit log data |
| Device.Read.All | Read all devices |
| DeviceManagementManagedDevices.Read.All | Read Microsoft Intune devices |
| Directory.Read.All | Read directory data |
| Group.Read.All | Read all groups |
| GroupMember.Read.All | Read all group memberships |
| IdentityRiskyUser.Read.All | Read all identity risky user information |
| SecurityAlert.Read.All | Read all security alerts |
| SecurityIncident.Read.All | Read all security incidents |
| ThreatHunting.Read.All | Run hunting queries |
| User.Read.All | Read all users’ full profiles |
Office 365 Management APIs
| Permission | Purpose |
|---|---|
| ActivityFeed.Read | Read unified audit log content (Exchange, Entra ID, and general Microsoft 365 activity) |
| ServiceHealth.Read | Read Microsoft 365 service health advisories |
Optional permissions
Only add these permissions if you plan to use the corresponding SIEM (InsightIDR) feature.
If you plan to use response actions:
| Permission | API | Purpose |
|---|---|---|
| User.EnableDisableAccount.All | Microsoft Graph | Enable or disable an Entra ID user |
| Machine.Isolate | WindowsDefenderATP | Isolate or release a Defender for Endpoint machine |
If you plan to use bidirectional alert sync:
| Permission | API | Purpose |
|---|---|---|
| SecurityAlert.ReadWrite.All | Microsoft Graph | Update alert status and disposition |
| SecurityIncident.ReadWrite.All | Microsoft Graph | Update incident status |
Task 4: Create the Event Hub namespace and event hub
Skip this task if you're not using the streaming channel
Only complete this task if you want Cloud App Events and Azure Activity Log data.
To create the Event Hub namespace:
- Go to the Azure portal: https://portal.azure.com/
- Go to Event Hubs, then click + Create.
- Choose a Pricing tier appropriate for your expected data volume and number of partitions.
- Select the same Region as your other workloads.
- Complete the remaining namespace settings and click Review + create, then Create.
- Once the namespace is created, go to Settings > Properties and copy the Service bus endpoint, without the trailing
:443. This is your Event Hub namespace hostname (for example,contoso-onboarding.servicebus.windows.net).
To create the event hub inside the namespace:
- In the namespace, go to Entities > Event Hubs, then click + Event hub.
- Enter a unique name for the event hub and complete the creation steps.
- Copy the event hub’s Name. This is your Event Hub name.
To create a consumer group:
- Open the event hub, then go to Entities > Consumer groups, then click + Consumer group.
- Enter a name, or use
$Defaultonly if no other consumer shares it. - Copy the consumer group name. This is your Consumer group value.
To grant the app registration access to the event hub:
- In the event hub, go to Entities > Access Control (IAM), then click + Add > Add role assignment.
- Search for and select Azure Event Hubs Data Receiver, then click Next.
- Under Assign access to, select User, group, or service principal.
- Under Members, click + Select members, then search for the app registration you created in Task 1.
- Click Review + assign.
Task 5: Create the Blob Storage checkpoint container
Skip this task if you're not using the streaming channel
The Event Hub consumer uses a small Blob container to persist per-partition checkpoints (partition ownership and the last-processed sequence number). Any general-purpose v2 storage account works.
To create the storage account:
- In the Azure portal, go to Storage accounts, then click + Create.
- On the Basics tab, enter a globally unique, lowercase alphanumeric Storage account name (3–24 characters), and select the same Region as your Event Hub namespace.
- Set Performance to Standard and Redundancy to Locally-redundant storage (LRS), which is sufficient for checkpoint data.
- On the Advanced tab, set Access tier to Hot. Checkpoints are overwritten frequently, so Hot avoids retrieval charges. Leave hierarchical namespace, SFTP, and NFS v3 off.
- On the Networking tab, set Public network access to Enable, since SIEM (InsightIDR) reaches your storage account over the public internet.
- On the Data protection tab, leave point-in-time restore, blob soft delete, container soft delete, blob versioning, and blob change feed off. These add cost without benefit for regenerable checkpoint data.
- On the Security tab, require secure transfer for REST API operations, and set Minimum TLS version to 1.2.
- Complete the remaining tabs with your organization’s standard settings, then click Review + create, then Create.
- Once created, go to Settings > Endpoints and copy the Blob service > Primary endpoint URL, with the trailing slash removed (for example,
https://contosoonboarding.blob.core.windows.net). This is your Blob Storage account URL.
Use the primary endpoint, not the secondary
The secondary endpoint is a read-only geo-replica and can’t receive checkpoint writes.
To create the checkpoint container:
- In the storage account, go to Data storage > Containers, then click + Container.
- Enter a name (3–63 lowercase alphanumeric characters and hyphens), for example
siem-idr-checkpoints. - Set Anonymous access level to Private (no anonymous access).
- Click Create, then copy the container name. This is your Blob container name.
To grant the app registration access to the container:
- Open the container, then go to Access Control (IAM).
- Click + Add > Add role assignment, and select the Storage Blob Data Contributor role.
- Under Members, search for the app registration you created in Task 1 (by Application ID or display name), then select it.
- Click Review + assign, then Assign.
Allow a couple of minutes for the role assignment to propagate before testing the connection.
Task 6: Configure streaming producers
Skip this task if you're not using the streaming channel
This task configures Microsoft to publish two additional data sources into the event hub you created in Task 4.
Cloud App Events, through the Defender XDR Streaming API:
- Go to https://security.microsoft.com
- Go to System > Settings > Microsoft Defender XDR > Streaming API, then click + Add.
- Enter a Name for the stream.
- Set Sink type to Event Hub.
- For Event Hub resource ID, enter the Resource ID of the Event Hub namespace (not the individual event hub). You can find this under the namespace’s Properties. It should look like
/subscriptions/{subId}/resourceGroups/{rg}/providers/Microsoft.EventHub/namespaces/{namespace}. - Enter the Event Hub name you created in Task 4.
- Under Event types, select Apps & Identities > CloudAppEvents. Microsoft Defender for Cloud Apps must be deployed and Microsoft 365 activities enabled before configuring streaming.
- Click Save.
It can take 5–10 minutes for the first batch of events to appear.
Azure Activity Log, through diagnostic settings:
- Go to https://portal.azure.com
- Go to Subscriptions, select your subscription, then go to Activity log > Export activity logs > + Add diagnostic setting.
- Enter a Diagnostic setting name.
- Select all available Categories.
- Under Destination details, select Stream to an event hub.
- Select the subscription, Event Hub namespace, and Event Hub name you created in Task 4.
- Set Event hub policy name to
RootManageSharedAccessKey(the default). Azure Monitor uses this policy to publish events; it isn’t used by SIEM (InsightIDR) to consume them. - Click Save.
Permissions required to save this setting
You need Monitoring Contributor (or Owner or Contributor) access at the subscription scope. If Save fails with an AuthorizationFailed error immediately after a role was granted, sign out of the Azure portal and back in — role claims can be cached in your session for up to an hour.
The first events typically land within about 5 minutes of any subscription-level activity.
Task 7: Enable the unified audit log
Some Microsoft tenants have the unified audit log disabled by default. If it isn’t enabled, SIEM (InsightIDR) will connect successfully but won’t receive any Exchange, Entra ID, or general Microsoft 365 audit events.
To enable the unified audit log:
- Go to the Microsoft Purview compliance portal: https://purview.microsoft.com
- Go to Solutions > Audit.
- If you see a banner that says Start recording user and admin activity, click it.
If you don’t see this banner, auditing is already enabled and no action is needed.
Configure SIEM (InsightIDR) to collect data from the event source
Once you’ve completed the tasks above and collected the required values, you can set up the Microsoft Cloud event source in SIEM (InsightIDR).
To configure the new event source in SIEM (InsightIDR):
- Click Data Collection in the left menu, and go to Event Sources.
- Click Add Event Source.
- Under the Collected By filter, select Expanded Cloud.
- Select the Microsoft Cloud event source tile.
- Name the event source. This name will be used to name the log that contains the event data in Log Search.
- Click Add a New Connection.
- Enter the values you collected earlier in their respective fields: Tenant ID, Client ID, Client Secret, and, if you enabled streaming, the Event Hub namespace hostname, Event Hub name, Consumer group, Blob Storage account URL, and Blob container name.
- For Product Access, select All Rapid7 Products.
- Click Save.
- Optionally, enable Bidirectional Sync if you configured the optional alert-sync permissions in Task 3 and want SIEM (InsightIDR) to write back alert and incident status changes to Microsoft.
- Click Save to finalize the event source configuration.
Test the configuration
To test that event data is flowing into SIEM (InsightIDR):
- Click Data Collection in the left menu, and go to Event Sources.
- Find the event source you created and click View raw log.
- If the Raw Logs modal displays raw log entries, logs are successfully flowing.
- Wait a few minutes, then open the Log Search page.
- Select the applicable Log Sets and the Log Name that matches the event source name you chose.
- Set the time range to Last 10 minutes, and click Run.
The Results table displays log entries received in the last 10 minutes.
If the streaming channel shows no data
Confirm that the Defender XDR Streaming API and Azure Activity Log diagnostic setting are both configured and saved (Task 6), and that enough time has passed for the first batch of events.