Integrations
Set up Microsoft Azure Monitor credentials in Duaer
Store Microsoft Azure Monitor connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
Register an Entra app
The Duaer Microsoft Azure Monitor OAuth2 API credential:
- In the Microsoft Entra admin center, create an app registration under App registrations and add the Duaer OAuth Redirect URL as a Web Redirect URI under Authentication, and create a client secret.
- Put Client ID, Client Secret, and Tenant ID in the credential. Pick the service in Resource: Log Analytics queries, Azure Monitor metrics, or Azure Management.
- With Grant Type set to Client Credentials, assign the app a role such as Log Analytics Reader or Monitoring Reader under Access control (IAM) on the workspace or subscription. With Authorization Code, it acts with your own rights; click Connect my account.
Duaer has no dedicated node for this service. In the HTTP Request node, set Authentication to Predefined Credential Type and pick the Microsoft Azure Monitor OAuth2 API credential. Refer to custom operations.
Microsoft Azure Monitor OAuth2 API fields in Duaer
In Duaer, choose Microsoft Azure Monitor OAuth2 API when you create a credential, then fill in these fields:
- Grant Type: Default: Authorization Code. Options: Authorization Code, Client Credentials.
- Client ID (required)
- Client Secret (required, secret)
- Tenant ID (required)
- Resource: Default: Azure Log Analytics. Options: Azure Log Analytics, Log Analytics, Azure Monitor, Azure Management.
- Custom Scopes: Define custom scopes. Default: off.
- Enabled Scopes: Scopes that should be enabled. Use {resource} as a placeholder that will be replaced with the Resource value. Default: {resource}/.default. Shown when Custom Scopes is on.
In the provider’s app settings, register the OAuth Redirect URL that the Duaer credential dialog shows (https://<your-duaer-host>/rest/oauth2-credential/callback). Then click Connect my account in Duaer and approve access.
By default, Duaer requests these scopes: {resource}/.default.
Optional settings shared by every Duaer OAuth2 credential: Send Additional Body Properties, Additional Body Properties, Ignore SSL Issues (Insecure), Token Expired Status Code, Encrypted Tokens (JWE), JWKS URI. They are described under OAuth2 API.
Save the connection in Duaer
Open Credentials and create Microsoft Azure Monitor. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.
Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys.
Who can use this credential
Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
Questions
Do Microsoft Azure Monitor secret values appear in Duaer node parameters?
No. In Duaer, Microsoft Azure Monitor secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.
What usually stops a Microsoft Azure Monitor credential from saving in Duaer?
Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Microsoft Azure Monitor expects, then confirm you can create credentials in that project.
In this section
Built-in integrations in Duaer
Built-in triggers, actions, and credentials in Duaer. Triggers start a digital organization. Actions run a step after it has started.
IntegrationsRisks of community nodes in Duaer
Before you install a community node in Duaer, know the code comes from a source the instance admin trusts, and know what permissions it gets.
IntegrationsTroubleshoot community nodes in Duaer
When a Duaer community node will not install or run, check the version, permissions, and node docs, then the instance logs.
IntegrationsMake custom API calls for an app in Duaer
When a Duaer app node does not expose the API you need, use HTTP Request and reuse that app’s saved authentication.
IntegrationsIntegrations in Duaer
Built-in triggers, actions, and credentials in Duaer. Community nodes are extra packages. Custom operations reuse saved authentication with HTTP Request.
CredentialsBuilt-in credentials in Duaer
Per-service credential notes for Duaer built-ins. The create flow is in the credentials overview; node docs link to the matching service page.
Create nodesCreate a custom node for Duaer
Write a node package for Duaer when built-in nodes and custom operations are not enough and you will reuse the step.