# Triagic + Azure: ticket investigations over your cloud account, read-only

> Azure in Triagic: Ask about any Azure service the service principal can read: compute, storage, SQL, Cosmos, AKS, App Service, Monitor and more.

Source: https://triagic.com/integrations/azure

## What you can ask

- In Azure, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
- Did the error rate in Azure for the API gateway change in the last six hours?
- Which alarms in Azure fired this week, and which are still in alarm?
- Show me the Azure deployment that was live when ticket 4819 was filed
- What is the dead-letter queue depth in Azure right now?

## What the agent can do

- `subscription_list`
- `group_list`
- `group_resource_list`
- `acr`
- `advisor`
- `aks`
- `appconfig`
- `applens`
- `applicationinsights`
- `appservice`
- `compute`
- `containerapps`
- `cosmos`
- `eventgrid`
- `eventhubs`
- `fileshares`
- `functionapp`
- `grafana`
- `kusto`
- `monitor`
- `mysql`
- `policy`
- `postgres`
- `quota`
- `redis`
- `resourcehealth`
- `role`
- `search`
- `servicebus`
- `servicefabric`
- `signalr`
- `sql`
- `storage`
- `storagesync`
- `workbooks`

## Connect in three steps

1. **Mint a read-only credential in Azure.** Create a dedicated user or token that can only read. Started with --read-only, with an allowlist of routers that never names keyvault.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Azure. Fill in: Tenant ID (required): Entra ID → App registrations → your app → Directory (tenant) ID.; Client ID (required): The same app registration's Application (client) ID.; Client secret (required): Certificates & secrets → New client secret. These expire. Note the date.; Client certificate path (required): The certificate you uploaded under Certificates & secrets → Certificates. PEM or PFX; a PEM must contain the private key as well as the certificate. Only a PEM can be pasted. A PFX is binary, so give it as a path. Path on each machine running Triagic, or paste the file itself.; Subscription ID (required): The subscription to query. Grant the service principal Monitoring Reader on it, and Log Analytics Reader on the workspaces.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Azure locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/cloud#azure

## Read-only, by construction

Started with --read-only, with an allowlist of routers that never names keyvault.

## FAQ

**Can Triagic change anything in Azure?**
No. Started with --read-only, with an allowlist of routers that never names keyvault. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Azure?**
Tenant ID, Client ID, Client secret, Client certificate path, Subscription ID. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Azure cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [AWS CloudWatch](https://triagic.com/integrations/aws-cloudwatch)
- [AWS SQS / SNS](https://triagic.com/integrations/aws-sqs-sns)
- [Azure Monitor](https://triagic.com/integrations/azure-monitor)
- [Google Cloud Logging](https://triagic.com/integrations/gcp-logging)
