Description
The RSA ID Plus AdminLogs Connector provides the capability to ingest [Cloud Admin Console Audit Events](https://community.rsa.com/s/article/Cloud-Administration-Event-Log-API-5d22ba17) into Microsoft Sentinel using Cloud Admin APIs.
- Declared author / publisher
- RSA
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
RSA ID Plus API Authentication
To access the Admin APIs, a valid Base64URL encoded JWT token, signed with the client's Legacy Administration API key is required.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
>**NOTE:** This connector uses Codeless Connector Framework (CCF) to connect to the RSA ID Plus Cloud Admin APIs to pull logs into Microsoft Sentinel.
**STEP 1** - Create Legacy Admin API Client in Cloud Admin Console.
Follow steps mentioned in this [page](https://community.rsa.com/s/article/Manage-Legacy-Clients-API-Keys-a89c9cbc#).
**STEP 2** - Generate the Base64URL encoded JWT Token.
Follow the steps mentioned in this [page](https://community.rsa.com/s/article/Authentication-for-the-Cloud-Administration-APIs-a04e3fb9) under the header 'Legacy Administration API'.
**STEP 3** - Configure the Cloud Admin API to start ingesting Admin event logs into Microsoft Sentinel.
Provide the required values below:
Admin API URL
JWT Token
**STEP 4** - Click Connect
Verify all the fields above were filled in correctly. Press Connect to start the connector.
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
RSAIDPlus_AdmingLogs_Connector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC