This repository provides an overview of the WASOC DMARC Pilot onboarding process, along with a technical onboarding guide to support integration with the DMARC platform.
- Refer to information and instructions provided in [WASOC DMARC (Pilot)] (https://soc.cyber.wa.gov.au/onboarding/dmarc/) and get onboard to the Program.
- Complete the integrations for DCR and Logic Apps Data Collection Rule and Logic App deployment guide
- Deploy analytic rules for Microsoft Sentinel Analytic Rules Deployment Guide
- Ensure analytic rules and Logic Apps have been enabled
- Initiate end-to-end test to generate alert
For questions or feedback, please contact cybersecurity@dpc.wa.gov.au
The following steps will guide you on utilising Azure ARM templates to create a Data Collection Rule and Logic App to integrate DMARC platform with Microsoft Sentinel.
- Requires an Azure Log Analytics Workspace (to ingest the data from the DMARC platform).
- A DMARC group that has been provisioned by WASOC.
- Requires Contributor permission to the Microsoft Subscription to deploy the required resources.
- Requires a minimum of 'User Access Administrator' for role assignment to the target subscription.
To start the integration of the DMARC platform with your Sentinel SIEM, click on the 'Deploy to Azure' button shown below. This will deploy the Data Collection Rule and Custom tables required for the integration.
You will be redirected to the custom deployment screen in azure portal. Select/ fill-in the required information.
- Subscription: The subscriptions where the Data Collection Rules will be deployed to.
- Resource Group: The resource group where the Data Collection Rules will be deployed to.
- Workspace Name: The name of the Workspace you have selected above.
- Data Collection Rule Name: Name for the Data Collection Rule (Note: No special characters or numbers).
Review and ensure all details provided in the deployment are correct and proceed with creating the resources. Otherwise, select the 'previous' button to go back and make any changes.
Click on the Data Collection Rule resource that was just deployed and get the immutable id for the DCR, then click on the JSON view of the DCR resource.

From the JSON view, get the logsIngestion url and the stream name from the streamDeclarations field.
Now the full Log Ingestion URL is:
logsIngestionURL/dataCollectionRules/{immutable_id}/streams/{streamName}?api-version=2023-01-01
It would be similar to:
Now select the 'Deploy to Azure' below and open it in a new tab to deploy the Logic Apps for sending the DMARC data over to the Log Analytic workspace/datalake and fill in the following information.
Field description:
- Subscription: The subscriptions where the Logic apps will be deployed to.
- Resource Group: The resource group where the Logic apps will be deployed to.
- Logic App Name: The name of the Logic App. (Please update the 'AGENCYNAME' to reflect your agency's name)
- Api Token: Get your API token from the PowerDMARC Platform
- Stream Name : Stream name as found in the DCR JSON view under ‘streamDeclarations’. (Highlighted in previous step: Custom-****_CL)
Once the information has been filled in and the resources are successfully deployed, select the deployed logic app resource.
{: .important } You may need to manually assign the Monitoring Metrics Publisher role to the Managed Identity of the Logic App, scoped to the resource group that contains the Data Collection Rule (DCR). Ensure that the Logic App has its system assigned identity enabled.
This completes the integration for the DMARC pilot project. You can now perform testing to ensure the integration is working correctly.




