A cloud-based identity and access management service for securing user authentication and resource access
Microsoft Graph Event Hub Subscription fails with ValidationError despite verified configuration
MQ
0
Reputation points
Problem Description
I'm unable to create Microsoft Graph Change Notification subscriptions with Azure Event Hub as the notification endpoint. The subscription creation consistently fails with a ValidationError.
Error Message
{
"error": {
"code": "ValidationError",
"message": "Invalid event hub notification url=''.",
"innerError": {
"date": "2025-10-19T09:29:16",
"request-id": "4cfd1dca-d878-41e8-8d0e-e8c9d2a59941"
}
}
}
Configuration (All Verified ✓)
Event Hub:
- Namespace:
mycompany-eventhub.servicebus.windows.net - Event Hub Name:
todo-sync - Status: Active
- Region: West Europe
Connection String:
- ✓ Contains
EntityPath=todo-sync - ✓ SharedAccessKeyName:
GraphChangeNotifications - ✓ Format:
Endpoint=sb://...;SharedAccessKeyName=...;SharedAccessKey=...;EntityPath=todo-sync
Permissions (Microsoft Graph Change Tracking):
- ✓ Service Principal ID:
fcbbf149-8ca2-4f2a-96e4-8a12b37191ff - ✓ Namespace-Level: Azure Event Hubs Data Sender
- ✓ Event Hub-Level: Azure Event Hubs Data Sender + Data Receiver
- ✓ Verified via
az role assignment list
Network:
- ✓ Public Network Access: Enabled
- ✓ Network Default Action: Allow
- ✓ Event Hub publicly accessible (tested via Test-NetConnection)
Notification URL:
- Format:
EventHub:https://mycompany-eventhub.servicebus.windows.net/todo-sync?tenantId=mycompany.onmicrosoft.com - Using domain name (not GUID)
- Length: 100 characters
- Follows Microsoft documentation specification
Subscription Request
POST https://graph.microsoft.com/v1.0/subscriptions
{
"changeType": "created,updated,deleted",
"notificationUrl": "EventHub:https://mycompany-eventhub.servicebus.windows.net/todo-sync?tenantId=mycompany.onmicrosoft.com",
"resource": "/users/{userId}/todo/lists/{listId}/tasks",
"expirationDateTime": "2025-10-21T...",
"clientState": "..."
}
Troubleshooting Steps Already Taken
- ✓ Created Shared Access Policy on Event Hub level (not namespace)
- ✓ Verified EntityPath is present in connection string
- ✓ Assigned both RBAC roles (Data Sender + Receiver) to Microsoft Graph service principal
- ✓ Enabled Public Network Access on namespace
- ✓ Set Network Default Action to "Allow"
- ✓ Tested with both Tenant GUID and domain name in URL
- ✓ Waited 2+ hours for permission propagation
- ✓ Verified network connectivity to Event Hub hostname (successful)
- ✓ Confirmed Microsoft Graph service principal exists in tenant
Documentation Followed
Observed Behavior
- Microsoft Graph receives the notification URL (hash changes when URL is modified)
- ValidationError occurs during Event Hub validation phase
- Error is consistent and reproducible across multiple attempts
- Same error regardless of using Tenant GUID vs domain name
Similar Reports
This issue appears in some public forums:
- Stack Overflow: "Invalid event hub notification url" with correct configuration
- Microsoft Q&A: Multiple reports of ValidationError with Event Hub subscriptions
- Some reports mention tenant-specific issues
Questions
- Is there a tenant-specific configuration preventing Event Hub validation?
- Are there additional undocumented requirements for Event Hub subscriptions?
- Is this a known issue with Microsoft Graph Event Hub integration?
Environment
- Microsoft Entra ID License: P1
- Event Hub Tier: Standard
- Region: West Europe
- Microsoft Graph API: v1.0
Any guidance would be greatly appreciated.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Sign in to answer