Microsoft Graph Event Hub Subscription fails with ValidationError despite verified configuration

MQ 0 Reputation points
2025-10-19T10:30:14.1233333+00:00

Problem Description

I'm unable to create Microsoft Graph Change Notification subscriptions with Azure Event Hub as the notification endpoint. The subscription creation consistently fails with a ValidationError.

Error Message

{
  "error": {
    "code": "ValidationError",
    "message": "Invalid event hub notification url=''.",
    "innerError": {
      "date": "2025-10-19T09:29:16",
      "request-id": "4cfd1dca-d878-41e8-8d0e-e8c9d2a59941"
    }
  }
}

Configuration (All Verified ✓)

Event Hub:

  • Namespace: mycompany-eventhub.servicebus.windows.net
  • Event Hub Name: todo-sync
  • Status: Active
  • Region: West Europe

Connection String:

  • ✓ Contains EntityPath=todo-sync
  • ✓ SharedAccessKeyName: GraphChangeNotifications
  • ✓ Format: Endpoint=sb://...;SharedAccessKeyName=...;SharedAccessKey=...;EntityPath=todo-sync

Permissions (Microsoft Graph Change Tracking):

  • ✓ Service Principal ID: fcbbf149-8ca2-4f2a-96e4-8a12b37191ff
  • ✓ Namespace-Level: Azure Event Hubs Data Sender
  • ✓ Event Hub-Level: Azure Event Hubs Data Sender + Data Receiver
  • ✓ Verified via az role assignment list

Network:

  • ✓ Public Network Access: Enabled
  • ✓ Network Default Action: Allow
  • ✓ Event Hub publicly accessible (tested via Test-NetConnection)

Notification URL:

  • Format: EventHub:https://mycompany-eventhub.servicebus.windows.net/todo-sync?tenantId=mycompany.onmicrosoft.com
  • Using domain name (not GUID)
  • Length: 100 characters
  • Follows Microsoft documentation specification

Subscription Request

POST https://graph.microsoft.com/v1.0/subscriptions

{
  "changeType": "created,updated,deleted",
  "notificationUrl": "EventHub:https://mycompany-eventhub.servicebus.windows.net/todo-sync?tenantId=mycompany.onmicrosoft.com",
  "resource": "/users/{userId}/todo/lists/{listId}/tasks",
  "expirationDateTime": "2025-10-21T...",
  "clientState": "..."
}

Troubleshooting Steps Already Taken

  1. ✓ Created Shared Access Policy on Event Hub level (not namespace)
  2. ✓ Verified EntityPath is present in connection string
  3. ✓ Assigned both RBAC roles (Data Sender + Receiver) to Microsoft Graph service principal
  4. ✓ Enabled Public Network Access on namespace
  5. ✓ Set Network Default Action to "Allow"
  6. ✓ Tested with both Tenant GUID and domain name in URL
  7. ✓ Waited 2+ hours for permission propagation
  8. ✓ Verified network connectivity to Event Hub hostname (successful)
  9. ✓ Confirmed Microsoft Graph service principal exists in tenant

Documentation Followed

Observed Behavior

  • Microsoft Graph receives the notification URL (hash changes when URL is modified)
  • ValidationError occurs during Event Hub validation phase
  • Error is consistent and reproducible across multiple attempts
  • Same error regardless of using Tenant GUID vs domain name

Similar Reports

This issue appears in some public forums:

  • Stack Overflow: "Invalid event hub notification url" with correct configuration
  • Microsoft Q&A: Multiple reports of ValidationError with Event Hub subscriptions
  • Some reports mention tenant-specific issues

Questions

  1. Is there a tenant-specific configuration preventing Event Hub validation?
  2. Are there additional undocumented requirements for Event Hub subscriptions?
  3. Is this a known issue with Microsoft Graph Event Hub integration?

Environment

  • Microsoft Entra ID License: P1
  • Event Hub Tier: Standard
  • Region: West Europe
  • Microsoft Graph API: v1.0

Any guidance would be greatly appreciated.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.