{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-guides/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Azure Network Security Provider Configuration Guide","siteUrl":"https://docs.synqly.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This guide walks you through creating a Microsoft Entra application, assigning Azure RBAC roles for Network Watcher flow logs, and gathering the configuration needed to create an Azure Network Security integration with Synqly."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This provider currently supports flow logs written to Azure Blob Storage. Log Analytics destinations are not supported."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Prefer virtual network (VNet) flow logs for new setups. Network security group (NSG) flow logs are still readable when already configured, but Azure blocked creating new NSG flow logs as of June 30, 2025, and plans to retire them on September 30, 2027; migrate to VNet flow logs when possible. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-migrate"},"children":["Migrate from NSG flow logs to VNet flow logs"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":0},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you begin, ensure that you have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Access to the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://entra.microsoft.com/"},"children":["Microsoft Entra admin center"]}," with the Application Developer role (or other permissions that allow creating an app registration)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Access to an Azure subscription with a Network Watcher and flow logs publishing to an Azure Storage account"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Permission to assign Azure RBAC roles to a service principal"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"required-permissions","__idx":1},"children":["Required Permissions"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Permission"},"children":["Permission"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Purpose"},"children":["Purpose"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Microsoft.Network/networkWatchers/flowLogs/read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Discover Network Watcher flow log configurations"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Storage Blob Data Reader"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List and download flow log blobs from the destination storage account"]}]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Assign ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reader"]}," (or a custom role that includes ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Microsoft.Network/networkWatchers/flowLogs/read"]},") on the Network Watcher resource, resource group, or subscription, and assign ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Storage Blob Data Reader"]}," on the storage account or container that receives flow log data. Control-plane Reader on the storage account alone is not sufficient to download blobs."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"create-an-entra-application-and-service-principal","__idx":2},"children":["Create an Entra Application and Service Principal"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"1-create-an-application-and-service-principal","__idx":3},"children":["1. Create an application and service principal"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign in to the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://entra.microsoft.com/"},"children":["Microsoft Entra admin center"]}," with an account that can create app registrations."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Entra ID"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["App registrations"]},", then select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New registration"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]}," for the application."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Supported account types"]},", choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Accounts in this organizational directory only"]}," (single tenant) unless you need a multi-tenant app. If you are unsure, choose the single-tenant option. For more information, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/entra/identity-platform/single-and-multi-tenant-apps"},"children":["Tenancy in Microsoft Entra ID"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Overview"]}," page, copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application (client) ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Directory (tenant) ID"]}," and store them in a safe location."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more details, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app"},"children":["Register an application with the Microsoft identity platform"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"2-create-an-application-client-secret","__idx":4},"children":["2. Create an application client secret"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the app registration, go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Certificates & secrets"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client secrets"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New client secret"]},", enter a description and expiration, then select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Copy the secret ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Value"]}," immediately and store it with the client ID and tenant ID. You will not be able to view the value again after you leave the page."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"3-assign-azure-rbac-roles","__idx":5},"children":["3. Assign Azure RBAC roles"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Assign the roles from ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#required-permissions"},"children":["Required Permissions"]}," to the application's service principal."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assign Reader on the Network Watcher scope:"]}]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://portal.azure.com"},"children":["Azure portal"]},", navigate to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Network Watcher"]}," resource (or the resource group or subscription that contains it)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Access control (IAM)"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ Add"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add role assignment"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Search for ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reader"]},", select it, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ Select members"]},", add the application from step 1, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Select"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Review + assign"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assign Storage Blob Data Reader on the flow log storage account:"]}]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the Azure portal, navigate to the storage account (or container) that receives Network Watcher flow logs."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Access control (IAM)"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ Add"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add role assignment"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Search for ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Storage Blob Data Reader"]},", select it, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ Select members"]},", add the application from step 1, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Select"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Review + assign"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more details, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal"},"children":["Assign Azure roles using the Azure portal"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"4-gather-network-watcher-values","__idx":6},"children":["4. Gather Network Watcher values"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the Azure portal, navigate to your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Network Watcher"]}," resource."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the Overview page, note the following values:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Subscription ID"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Resource group"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]}," (Network Watcher name)"]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"configure-the-integration","__idx":7},"children":["Configure the Integration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create your integration by supplying the following values."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Integration Parameter"},"children":["Integration Parameter"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The Application (client) ID from the Entra app registration Overview page"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client Secret"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The client secret Value from Certificates & secrets"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Tenant ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The Directory (tenant) ID from the Entra app registration Overview page"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Subscription ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The Azure subscription ID that contains the Network Watcher"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Resource Group"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The Azure resource group name that contains the Network Watcher"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Network Watcher Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The name of the Network Watcher resource"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Azure Cloud ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["(optional)"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Microsoft cloud environment. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["public"]}," (default) or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["government"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Traffic Log Configuration IDs ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["(optional)"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Flow log short names or full ARM IDs ending in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".../flowLogs/{name}"]},". When omitted, all configurations discoverable by the Network Watcher are used"]}]}]}]}]}]},"headings":[{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Required Permissions","id":"required-permissions","depth":2},{"value":"Create an Entra Application and Service Principal","id":"create-an-entra-application-and-service-principal","depth":2},{"value":"1. Create an application and service principal","id":"1-create-an-application-and-service-principal","depth":3},{"value":"2. Create an application client secret","id":"2-create-an-application-client-secret","depth":3},{"value":"3. Assign Azure RBAC roles","id":"3-assign-azure-rbac-roles","depth":3},{"value":"4. Gather Network Watcher values","id":"4-gather-network-watcher-values","depth":3},{"value":"Configure the Integration","id":"configure-the-integration","depth":2}],"frontmatter":{"slug":"guides/provider-configuration/azure-networksecurity-setup","seo":{"title":"Azure Network Security Provider Configuration Guide"}},"lastModified":"2026-08-19T20:11:23.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/provider-configuration/azure-networksecurity-setup","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}