Datadog for Azure
implemented and operated in the UK.
We integrate Datadog across your Azure subscriptions, consolidate a fragmented native tooling estate into one query surface, and run it 24x7. Critical Cloud is a Microsoft Partner and the world's first Powered by Datadog accredited MSP.
What Datadog gives you on Azure that Azure Monitor does not
Azure Monitor, Log Analytics, Application Insights, Defender and Sentinel are five products with five query surfaces.
Azure's observability story is capable but fragmented. Metrics live in Azure Monitor, logs in Log Analytics behind KQL, application traces in Application Insights, security posture in Defender for Cloud and security events in Sentinel. Each is good at its job. None of them gives an on-call engineer a single place to ask what changed.
Datadog sits across them. Infrastructure metrics, application traces, logs and synthetics share one tag model and one query surface, so an AKS node pressure event, an App Service response time change and a dependency failure line up on the same timeline.
This is not an argument for switching Azure Monitor off. Azure-native tooling remains the collection layer and, for Defender and Sentinel, the security system of record. The pattern that works is Azure-native for collection and control, Datadog for correlation and alerting.
What we connect, and in what order
Most of the work in an Azure rollout is subscription structure and tagging, not agent installation.
Subscriptions Azure integration and app registration App registration per tenant, scoped across subscriptions and management groups.
We configure the Datadog Azure integration through an app registration with reader scope, applied across subscriptions rather than one at a time. Where management groups are in use, we integrate at that level so new subscriptions inherit the configuration instead of being onboarded manually.
Resource tag collection is enabled at this point. Azure Policy can then enforce the tag schema going forward, which is the difference between a tag model that holds and one that decays over the first quarter.
Compute AKS, App Service and virtual machines Agent deployment matched to the hosting model, with Kubernetes metadata mapped to service names.
On AKS the Agent runs as a DaemonSet with the cluster agent handling cluster-level metrics and orchestration metadata. App Service uses the site extension or container-based instrumentation. Virtual machines and scale sets use the standard agent through your existing configuration management.
As on any platform, the value comes from the tag mapping. Pod, node, resource group, subscription and environment tags need to resolve to the service names your teams use in conversation, or the data stays technically correct and practically unusable.
Applications Application Insights and APM A deliberate decision about which system owns application tracing.
Running Application Insights and Datadog APM side by side on the same services is a common and expensive mistake: you pay twice and your engineers check both. We make an explicit call per application, usually consolidating onto Datadog APM where cross-service correlation matters and leaving Application Insights where a team depends on it.
Where both need to coexist during a migration, we set an end date rather than letting the overlap become permanent.
Security Defender for Cloud and Sentinel Security signal surfaced in Datadog without displacing the security system of record.
Defender for Cloud and Sentinel stay where they are. What we do is bring the operationally relevant signal into Datadog so a security finding and the workload it affects are visible together, rather than requiring a context switch during an incident.
Sentinel remains the SIEM. Datadog becomes the place where a posture finding is correlated with the deployment, the service owner and the runtime behaviour.
Signal Log Analytics and cost control Deciding what to ingest, before ingesting it.
Azure diagnostic settings will happily stream every category of every resource into both Log Analytics and Datadog. Doing so is the single most reliable way to produce an observability bill nobody can explain.
We work through diagnostic settings resource type by resource type, deciding what earns ingestion, what belongs in a cheaper archive tier and what should never have been collected. This normally happens before the first invoice rather than after it.
Cost Azure Cost Management attribution Azure spend alongside the observability data that explains it.
Cloud Cost Management ingests Azure cost data so spend appears in the same timeline as deployments and performance changes, attributed by subscription, resource group and tag. As with everything else here, attribution quality is a direct function of tag discipline.
Data residency, and what it means for a UK Azure estate
Running in UK South does not mean your telemetry stays in the UK.
Azure region and Datadog site region are separate decisions. Workloads in UK South or UK West can still be sending observability data to a Datadog site outside the UK unless that is configured deliberately. Datadog has historically operated a US site and an EU1 site, with EU1 storing data in Frankfurt, and has been expanding its data residency options since.
For most UK organisations EU1 is sufficient. For those with an explicit UK-only mandate, notably in financial services, healthcare and parts of the public sector, the site region needs deciding before ingestion starts. Changing it afterwards means re-instrumenting and losing history. Our guide to Datadog UK data residency, DORA and NIS2 covers the detail.
We operate and evidence the runtime controls that support your compliance obligations: retention aligned to your policy, access controlled through Entra ID and role mapping, and an audit trail of configuration change.
How a Datadog for Azure engagement actually runs
Four named services, used in the order that fits where you are.
Trial FETCH Complimentary trial enablement, so an evaluation produces a real answer.
FETCH gets a Datadog trial instrumented properly. Most trials fail because too little was connected to judge the platform on, not because the platform was wrong.
Rollout LaunchPad Fully project-managed rollout across subscriptions and environments.
LaunchPad covers integration, agent rollout, tag model, diagnostic settings review, dashboards, monitors and runbooks, delivered as a managed project.
Assess HealthScan Read-only assessment of an existing Datadog estate.
Where Datadog is already deployed and underperforming, HealthScan is an independent read-only review producing a health scorecard and a prioritised backlog.
Run Managed Observability Ongoing operation of the platform, powered by Datadog.
We run it month to month: monitor tuning, noise reduction, cost governance and coverage as the estate changes. Critical Cloud is the world's first Powered by Datadog accredited MSP.
UK Datadog partner
The world's first Powered by Datadog accredited MSP. What we do, how we work, and the proof behind it.
Read about our Datadog practice →Frequently asked questions
Direct answers to the questions we are asked most often.
Q Should we use Datadog or Azure Monitor?
They are complementary rather than alternatives. Azure Monitor, Log Analytics and Application Insights are the native collection layer and remain the source of truth for many Azure services. Datadog is the correlation layer across them, giving one query surface and one tag model spanning infrastructure, applications, logs and synthetics. Most teams keep Azure-native tooling for collection and control, and use Datadog for investigation and alerting.
Q Can we run Application Insights and Datadog APM together?
Technically yes, but running both on the same services means paying twice and asking engineers to check two tools during an incident. We normally make an explicit decision per application: consolidate onto Datadog APM where cross-service correlation matters, and keep Application Insights where a team genuinely depends on it. Where both must coexist during a migration, we set an end date for the overlap.
Q Does Datadog replace Microsoft Sentinel?
No. Sentinel remains the SIEM and the security system of record, and Defender for Cloud remains the posture management tool. What Datadog adds is operational context: bringing the relevant security signal alongside the workload, the deployment and the service owner, so an incident does not require switching between security and operations tooling to understand what is happening.
Q What drives Datadog cost on Azure?
Most commonly, Azure diagnostic settings. It is straightforward to stream every diagnostic category of every resource into Datadog, and doing so produces a large bill with very little added signal. Log volume, custom metric cardinality and APM host count are the three levers that matter. We review diagnostic settings by resource type before ingestion rather than after the first invoice.
Get Datadog working properly on Azure
Whether you are evaluating Datadog, rolling it out across subscriptions, or trying to fix a deployment that is noisy and expensive, we can help.