Unable to integrate Knox Asset Intelligence with Microsoft Sentinel

Last updated September 23rd, 2026

Categories:

Environment

  • Knox Asset Intelligence
  • Microsoft Sentinel

Overview

When you attempt to integrate Knox Asset Intelligence with Microsoft Sentinel, you may encounter the following error message:

400 - DCE provided appears to be invalid. Please verify if the correct DCE was provided.

Cause

This error may be caused by one or more of the following Data Collection Endpoint (DCE) misconfigurations:

  1. Incorrect DCE URL or format: The DCE URL you entered during the Knox Asset Intelligence configuration process doesn’t match the actual DCE resource in Microsoft Azure, or the URL format is invalid.
  2. DCE and Log Analytics workspace are in different Microsoft Azure regions: The DCE and the Log Analytics workspace must be provisioned in the exact same Microsoft Azure region. A region mismatch causes the DCE validation to fail.
  3. Insufficient Resource Group permissions: The account you used to configure the Samsung Knox Asset Intelligence for Sentinel solution doesn’t have owner or contributor permissions for both the Sentinel resource group and the DCE resource.

Resolution

Incorrect DCE URL or format

To verify if the DCE URL is valid:

  1. Sign in to your Microsoft Azure Portal, then click your Resource group resource.
  2. In the resource list on your resource group’s Overview page, click on your Data collection endpoint resource.
  3. Verify the Logs Ingestion URL in Sentinel data connectors matches the Sentinel URL (Data Collection Endpoint) in your Knox Asset Intelligence console.

DCE and Log Analytics workspace in different Microsoft Azure regions

To verify that the DCE and Log Analytics workspace aren’t in different Microsoft Azure regions:

  1. Sign in to your Microsoft Azure Portal, then click your Resource group resource.
  2. In the resource list on your resource group’s Overview page, click on your Data collection endpoint resource.
  3. Verify that the Location of the DCE is the same as the Log Analytics workspace. If they’re in different regions, you’ll need to re-create the DCE resource in the same region as the Log Analytics workspace.

Insufficient Resource Group permissions

Verify the account used to configure the Samsung Knox Asset Intelligence for Sentinel solution has an owner or contributor role for both the Sentinel resource group and the DCE resource. See Check access for a user to a single Microsoft Azure resource for more information.

After verifying these configurations, retry the integration to complete the setup.

If you’re still experiencing issues, submit a support ticket.

Is this page helpful?