Secure & Controlled Access for Nodinite Logging and Monitoring Agents in Azure
Gain full control and peace of mind by configuring secure, least-privilege access for your Nodinite Logging and Monitoring Agents in Azure. This guide walks you through every step to:
✅ Register Azure App Registrations for secure API access
✅ Assign only the required built-in roles for compliance and security
✅ Enforce least privilege to minimize risk and meet audit requirements
✅ Use X.509 v3 certificates for robust authentication
Granting Access to Nodinite Logging and Monitoring Agents
The Nodinite Azure Logging and Monitoring Agents interact with the Azure Service Management REST API, executing queries and commands to monitor and log events efficiently. To enable this functionality, you must:
- Register an Application in Azure – Set up App Registrations in the Azure Management Portal
- Assign Required Roles – The necessary permissions for Nodinite Agents are listed in the Least Privileges reference page
- Secure Authentication – Nodinite uses SSL and the authentication process is using X.509 v3 certificates for robust security
The Azure Service Management API provides programmatic access to most of the features available in the Azure Management Portal, allowing Nodinite to seamlessly integrate with your Azure environment.
Info
Nodinite follows best practices for security, ensuring all API access is granted with least privileges by design.
Why This Matters for Your Business
✅ Full Control Over Access Rights – Ensure agents only have the permissions they need, reducing security risks.
✅ Seamless Integration – Easily connect Nodinite Log- and Monitoring Agents with Azure services.
✅ Improved Compliance & Security – Enforce best practices for least privilege access, protecting your data and infrastructure.
✅ Reduced Configuration Errors – With many Nodinite Agents, it's easy to misconfigure access—this guide ensures a smooth setup.
✅ Optimized Performance – Proper role assignments help avoid permission-related errors, keeping your monitoring and logging efficient.
To configure the Nodinite Log- and Monitor-Agents; use this guide to find the following set of required properties:
1. TenantId
2. SubscriptionId
3. ResourceGroup
4. ClientId and ClientSecret
1. TenantId
The TenantId is the GUID uniquely identifying the Microsoft Entra ID (formerly Azure Active Directory) instance.
From the Azure Portal; Enter tenant properties and navigate to Properties for Microsoft Entra ID. The TenantId is available on the page.

2. SubscriptionId
The Microsoft Azure subscription is the unique user account in Azure. All Azure Resources and services are available to the REST-based Service Management API.
When you create an Azure subscription, it is uniquely identified by a SubscriptionId. The subscription Id is part of the call to the Azure Service Management API.
- The SubscriptionId is a GUID.
To acquire the SubscriptionId, enter Subscriptions in the search, and navigate to the Subscriptions page. Copy and use the GUID value:

Copy the SubscriptionId GUID to use.
3. Resource Group
For each Nodinite Log- and Monitor Agent; You must specify the Resource Groups to Monitor and Manage. There are different ways to manage these lists from within Nodinite depending on the type of agent.
One way to get the value is to use the Azure Portal; You can view the available Resource Groups.

Copy and use the Name of the Resource Group.
4. ClientId and ClientSecret
Important
Ensure you have at least one App Registration for each Subscription AND each Nodinite Monitoring Agent for Azure. This allows additional requests per timeframe is then allowed. You can read more about Azure Resource Manager throttling limits. If you have three Nodinite Monitoring Agents, you should have at least three App Registrations.
To retrieve the 'ClientId' and the 'ClientSecret' an Application must first exist/be created.
The following steps are required to create a new Application (Client Id):
- Select Microsoft Entra ID (formerly Azure Active Directory)
- From the Selected Active Directory instance, click on App registrations
- Click the New registration button
- Enter the name of the Application
- Select Accounts in this organizational directory only - least privileges
- Select the Web option
- Enter the URL to your user management website (can be changed later)
Note
The redirect URI can be any address like https://yournonexistinguserportal.nowhere.org
- Click the Register button to begin the creation process
This operation may take some time.
Create Permissions
Click the newly created Application to start creating permissions.
Request API Permissions
Next; select which API Permissions to assign for the Application. This may be different depending on which Nodinite Monitoring Agent to use.
Type of Permissions
Another modal is now displayed, and you need to specify the type of permissions required by the Application:
- Select Delegated permissions
- Check the user_impersonation checkbox
- Click the Add permissions button

Steps to perform when specifying the type of permissions granted for Application.
Consent
You can safely skip this step.

Create Client Secret
In the following dialogue, enter:
- A user-friendly name for the Client secret
- Select when the secret expire
- click the Add button
Next, the Client secret presents (once - this time only)

Important
REMEMBER TO COPY THE KEY and store it securely and accessible for your colleagues! Since it will only be displayed upon first save!
Add permission to monitor and manage the Resource Group
You can fine-tune permission on individual levels.
- Subscription (highest level)
- Resource Group (recommended)
- Object (lowest level)
Our recommendation is to assign as in the Roles with least privileges reference page.
To assign the role membership on the Resource Group level:
- Search and navigate to the list of Resource Groups.
- Select the Resource Group to add the permission to.
- Select Access Control (IAM).
- click the Add button.
- Select Add role assignment
- Select the built-in Contributor Role OR, use the table in the Roles with least privileges reference page.
- Select Azure AD user, group. pr service principal.
- Select one or more members (Application Name from step 4 - ClientId and ClientSecret).
To find the named Application(s), you need to type some characters to active the filter.
Note
Remember to click on the Save button

Click the Save button to persist the role assignment.
List of permissions
When finished, you will now see all User (Application) permissions in the list for the Resource Group(s) and/or Subscriptions. The User (Application) will be listed as part of the Contributor role.
Info
The full least-privilege role assignment reference has moved to its own page: Azure Application Access - Least Privileges. Use that page to identify the exact roles required for each agent.
Lower Azure retention to reduce TCO
A common cost-optimization pattern is to keep Azure Event Hub retention short and let Nodinite become the long-term storage and analysis layer. The Azure Event Hub and storage account are mainly used as a short-lived processing buffer, while the Nodinite database stores the retained business data and operational history.
This typically lowers total cost of ownership because:
- Azure Event Hub cost increases with retention and throughput
- blob checkpoint storage adds a small but real recurring cost
- long-term business value usually lives in Nodinite’s SQL/log databases, not in Azure diagnostics storage
- most customers only need a short replay window in Azure, such as 4–7 days
Important
When the data has already been ingested into Nodinite, there is usually no need to keep the Azure Event Hub data for months or years. Shortening Azure retention is a valid and recommended optimization.
How to reduce retention in the Azure portal
- Open the Azure portal
- Navigate to the Event Hub namespace that receives your Logic App diagnostics
- Select the target Event Hub entity used by the diagnostic setting
- Open Settings → Retention (or Message retention)
- Set the value to a short replay window such as 4–7 days
- Save the configuration
For Microsoft guidance, review:
If you are using Azure Diagnostics for Logic Apps, keep the Event Hub dedicated to the Logic App stream and avoid mixing unrelated telemetry. This makes retention tuning simpler and prevents unnecessary Azure storage cost.
Next Step
Related Topics
- Azure Application Access - Least Privileges – Minimum role assignments per agent
- Log Agents









