Microsoft Sentinel integration: migrate by September 14!
Hey, it's Shii-chan, hope you're doing well!
Cloudflare ChangelogWhat was announced?
Cloudflare's Changelog posted an important notice about Logpush connectors. If you're a Cloudflare Enterprise customer using the Azure Functions-based Microsoft Sentinel connector, you'll need to migrate to a new connector by 2026-09-14.
The story so far
The current connector sends logs to Microsoft Sentinel via Azure Functions, and it depends on the Azure Monitor HTTP Data Collector API. Microsoft is deprecating that API, and support for it ends on 2026-09-14. Once the underlying API is gone, Cloudflare can no longer maintain a connector that depends on it, which makes this a hard deadline for anyone affected.
What changes
After 2026-09-14, the Azure Functions-based connector will no longer work. In its place, you'll use the Cloudflare for Microsoft Sentinel Codeless Connector Framework (CCF) connector. If your team relies on this Sentinel integration, you'll need to switch to the CCF version before the deadline.
Dive Deep
For the actual migration steps, Cloudflare points you to its Microsoft Sentinel integration setup guide. Alongside that, you'll need Microsoft's own CCF Sentinel solution, available for download.
A few resources worth bookmarking:
- Cloudflare's CCF Sentinel Solution (download)
- Microsoft Sentinel data lake overview
- An overview of the CCF platform
- Microsoft's official deprecation notice for the Azure Monitor HTTP Data Collector API
Wrap-up
- The Azure Functions-based Microsoft Sentinel connector is being deprecated on 2026-09-14
- The cause is Microsoft ending support for the Azure Monitor HTTP Data Collector API on the same date
- The replacement is the Cloudflare for Microsoft Sentinel Codeless Connector Framework (CCF) connector
- If your Cloudflare Enterprise team uses this Sentinel integration, check the migration guide before the deadline hits.