> Source: [sk185014](https://support.checkpoint.com/results/sk/sk185014)

# sk185014 - Azure Event Hub and Storage Account allow public network access after Identity and Trust integration

| Property | Value |
|----------|-------|
| Solution ID | sk185014 |
| Date Created | 2026-05-31 |
| Last Modified | 2026-06-07 |
| Technical Level | General |
| Products | Identity and Trust |
| Versions | Cloud |

## Solution

Check Point Identity and Trust uses Microsoft Azure Event Hub and Azure Storage Account resources to collect data from Microsoft services when integrating with Microsoft Intune and Microsoft Defender.  

When the Intune or Defender integration is created automatically, the Azure Event Hub namespace and the associated Azure Storage Account are created with public network access enabled for all networks by default. This default behavior ensures that the integration works immediately after setup and does not require manual network configuration during the initial deployment phase.  

This behavior is expected.  

To limit EventHub and Storage Account access to specific IPs, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) for assistance.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
