Azure Activity Sentinel Data Connector

Rondo Huang (SOS Group Limited) 20 Reputation points
2025-02-27T09:28:56.4766667+00:00

Hi, I'm trying to enable Azure Activity Sentinel Data Connector. I've manage to install it and when I follow the 'Launch Azure Policy Assignment Wizard' it completes successfully, however the Azure Activity Data Connector never shows 'green/connected' and no data is ingested.

On the Azure Activity Data Connector instructions and "Prerequisites To integrate with Azure Activity" make sure I have:

Green Tick > Workspace: read and write permissions.

Information Symbol >Policy: owner role assigned for each policy assignment scope.

Information Symbol >Subscription: owner role permission on the relevant subscription

Additionally, I am a subscribed account admin and owner

Any help / ideas appreciated.

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Answer accepted by question author
  1. Raja Pothuraju 43,750 Reputation points Microsoft External Staff Moderator
    2025-02-27T12:19:23.6266667+00:00

    Hello @Rondo Huang (SOS Group Limited),

    Thank you for posting your query on Microsoft Q&A.

    Based on your description, I understand that you have installed the Azure Activity Data Connector in Microsoft Sentinel and successfully completed the Azure Policy Assignment Wizard. However, the Data Connector status remains Not Connected, and no data is being ingested.

    Please follow the below steps to make the status Connected.

    1. Sign in to the Azure Portal and navigate to Subscriptions.
    2. Select the relevant subscription and go to Activity Log.
    3. Click on Export Activity Logs → Under the Diagnostic Settings page, select "Add Diagnostic Setting".
    4. In the Diagnostic Settings page:
      • Provide a name for the setting.
      • Select all logs to collect.
      • Under Destination details, choose "Send to Log Analytics workspace".
      • Select your subscription and the targeted Log Analytics workspace.
    5. Click Save, then verify that the setting has been created successfully.
    6. Allow at least 45 minutes to 1 hour for the Data Connector status to update to Connected.

    Please refer to the screenshot below for a clearer understanding.

    User's image For more details you can refer this QnA post on same issue: https://learn.microsoft.com/en-us/answers/questions/2143871/how-to-connect-azure-activity-data-connector-in-se

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.