Connect to Azure Active Directory

MVP

Hello, 

 

I'm trying to connect Azure Sentinel to Azure Active Directory , however the process doesn't seem to end and it doesn't connect. 

 

az-sentinel`.png

 

 

 

9 Replies

Same issue here.. its just stuck at Connecting Azure Active Directory (been going for 19 hours).  I have Azure AD Premium P2 licenses and have Global Admin

Had same issue and I think you first need to enable integrate Azure AD Logs with Log Analytics - (https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-... ). After doing that it it successfully connected. HTH
Hi Uri

Do you Need to configure the same log analytics workspace for both Solutions?

Thanks
Alex


+1 here!

That resolved it for me. Thanks!!

HI I have enabled azure monitor logs, since I saved the settings the status is as following since a couple of hours. 

 

 

Updating diagnostics for '/providers/microsoft.aadiam'.

Hi Alex,

Not sure if this is mandatory, I've used the same workspace for both, haven't tested yet with a different one.

Cheers,

Uri

Had the same issue. In my tenant, connecting Azure AD to Sentinel would not work. The process hung, just like Alex'. Going through the manual steps (https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-...) worked.

 

The funny thing is that other tenants (like a customer where I enabled the preview), did not have this issue.

 

Having some sort of log regarding this would be helpful to troubleshoot. Right now, the information is rather limited.

@Michael Van Horenbeeck& all, 

 

I solved the issue yesterday, seemded to be a permission issue, while I had full rights on the workspace, I did not have that on the Azure Tenant itself, hence once my colleague logged in with Azure Tenant owner rights , the activation worked nicely.