↳ GitHub sourceConnector

Frends iPaaS Audit Logs (via Codeless Connector Framework)

Description

Ingests the [Frends iPaaS](https://frends.com) Tenant audit trail (configuration changes, user actions and system events) into Microsoft Sentinel via the Frends Platform API Audit Trail Log endpoint. Prerequisites: the Frends Platform API and the Audit Log API route (Flags:EnableFrendsApiAuditLogRoute) must be enabled by Frends Support, and an Entra ID app registration with an admin-consented 'Administrator' application role is required. Any Platform API IP allowlist must permit calls from Azure.
Declared status
1
Declared author / publisher
Microsoft Security Community

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Frends Platform API
Platform API and Audit Log API route enabled by Frends Support; IP allowlist must permit Azure/Sentinel egress.
Entra ID app registration
App registration with client secret and an 'Administrator' app role (Applications member type) granted admin consent. Token audience must match the Application ID URI registered with Frends Support.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect the Frends Platform API Audit Trail Log
Provide the Entra ID app registration used for Frends Platform API access and your Frends tenant name (the subdomain of frendsapp.com). These values are stored on the data connector connection, not in the initial ARM deployment parameters.
Entra ID Tenant ID
Application (client) ID
Client Secret
Frends Tenant Name

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
[variables('connectorDefinitionName')]
Additional source files 1DataConnectors/Frends iPaaS/FrendsAuditLogs_Sentinel_CCF.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.