Azure Data Explorer
The Dropzone platform integrates with Azure Data Explorer (Kusto) so analysts can investigate organization-specific logs and telemetry that may not exist in Sentinel or Defender.
Dropzone uses your Microsoft Entra service principal to authenticate to one or more ADX clusters, discover available databases and tables, and execute read-only KQL queries. The ADX scanner builds table metadata (descriptions, fields, and query guidance) so the assistant can choose relevant tables and generate better queries.
Integration Overview
To enable these integrations you will perform the following actions:
Register a new application in Microsoft Entra Admin Center
Locate your Client ID, Tenant ID, and create a Client Secret
Assign Azure Data Explorer permissions for your service principal
Collect your ADX Cluster URL(s)
Install the credentials into your Dropzone tenant
Run the scanner to discover ADX tables and schemas
See the Microsoft Integrations page for instructions on how to register a new application, locate your Client ID and Tenant ID, and create a Client Secret.
When registering the application, set the "Supported account types" to "Accounts in this organizational directory only" and leave "Redirect URI" blank. No Microsoft Graph API permissions are required for this integration.
Assign Azure Data Explorer Permissions
Your application must have read access to the ADX databases you want Dropzone to query.
You may use a Kusto management command to grant access. See here for more information.
Example management commands (run by an ADX admin):
Alternatively, you may use the Microsoft Azure portal to assign access to each database manually.
For each Azure Data Explorer cluster you want Dropzone to be able to access, do the following:
As someone with Role-Based Action Control (e.g. as an Owner or User Access Administrator), navigate to your Azure portal
Open your Azure Data Explorer cluster
In the left hand side bar, navigate to Security + networking > Permissions

Click "Add"
Select the "AllDatabasesViewer" role

In the "New Principles" section, add the application you just created

Click "Select"

Repeat for each cluster you will use.
For each database within the Azure Data Explorer clusters you want Dropzone to access, do the following:
In the Overview section of your cluster, under "Database," select the database you want Dropzone to access

In the left hand side bar, click "Permissions"
Click "Add"

In the "New Principles" section, add the application you just created

Click "Select"

Repeat for each database you will use.
Locate your ADX Cluster URL(s)
Dropzone can connect to one or more ADX clusters.
To collect a cluster URL, do the following:
In the left sidebar of your Azure Data Explorer page, open the desired cluster

In the Cluster details section, copy the Cluster URL for use later in the Dropzone UI where it is called "Cluster URL"

Repeat for each cluster you want Dropzone to query
Enable Azure Data Explorer
To enable the Data Source integration, you will need the following information:
Tenant ID
The Directory ID copied earlier
Client ID
The Application ID copied earlier
Client Secret
The Client Secret Value copied earlier
Cluster URL
The Cluster URLs copied earlier
To enable the Data Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom right corner, navigate to Settings > Integrations

Click "Available"

In the Search bar, search Azure Data Explorer, then click "Configure"

Input the Client ID, Tenant ID, and Client Secret

Under Cluster Configuration, click "Add Item" and input at least one Cluster URL

Input your desired timeout for queries (in minutes)

Click "Test & Save" to finish
After saving, run the integration's test connection (or validation) to confirm credentials and permissions. If you use the Azure scanner, run the scanner for this integration so that workspaces and table schemas are discovered. The integration will then use those workspaces for Log Analytics queries.
If you have any errors, contact your Dropzone AI support representative.
Troubleshooting
"Credentials are incomplete" or auth errors
Verify Tenant ID, Client ID, and Client Secret; ensure the secret has not expired.
"Failed to list resource groups"
Ensure Reader is assigned on that subscription; role assignment can take a few minutes to propagate.
"Failed to query Azure Log Analytics" or 403 on workspace query
Ensure Log Analytics Reader is assigned on that specific workspace; confirm the workspace ID in config matches the workspace.
Activity log query fails
Ensure Reader is assigned on the subscription (subscription-level Activity Log is covered by Reader).
Last updated
Was this helpful?