Description
The [Tailscale](https://tailscale.com/) solution for Microsoft Sentinel ingests Tailscale identity, device, configuration, audit and (Premium) network-flow telemetry via OAuth2-secured APIs. Built on the Codeless Connector Framework (CCF) - no Function App or container required.
**Data connectors in this solution (install the one matching your Tailscale plan):**
- **Tailscale Standard (CCF)** - Configuration audit, devices, users, keys, webhooks, DNS, settings. Use on **Personal (Free), Starter and Premium** tailnets.
- **Tailscale Premium (CCF)** - Everything in Standard plus network flow logs and posture integrations. Use on **Premium and Enterprise** tailnets for full coverage.
**Pre-requisites:**
1. Sign in to [Tailscale OAuth settings](https://login.tailscale.com/admin/settings/oauth)
2. Create an OAuth client with the scopes for your tier (see the README in this solution).
3. Copy the client ID and client secret (secret shown once).
4. Note your tailnet name (e.g. `tailb094d7.ts.net`) from the [Keys page](https://login.tailscale.com/admin/settings/keys).
- Version
- 3.0.0
- Declared author / publisher
- noodlemctwoodle - ccfconnectors.county118@passmail.com
- Support tier
- Community
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-solution-tailscale-ccf
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC