Integrations
OPC UA to Azure IoT Hub, without a script.
Read the OPC UA nodes with MaestroHub, give them meaning, and send them to Azure IoT Hub as device-to-cloud telemetry with routing properties. Cloud-to-device messages and Device Twin properties work the other way, and messages are buffered through outages.
The flow
One value, from the machine to Azure IoT Hub. Illustrative.
OPC UAindustrial protocolns=2;s=Robot4.Torque
MaestroHubRobot 4 joint torque · 41 Nm · Good
- named, unit, quality
- origin stamped
- buffered on disk
Azure IoT Hubcloud IoT serviceIoT Hub telemetryWhy do it with MaestroHub
More than a pipe from OPC UA to Azure IoT Hub.
Two-way, not just upload
Device Twin desired properties and cloud-to-device commands come back into MaestroHub, under the same permissions.
Clean messages for routing
Routing properties are set from the namespace, so IoT Hub sends each message to the right endpoint.
One edge for every protocol
OPC UA, S7, Modbus and Allen-Bradley sources all arrive in Azure the same way.
What lands in Azure IoT Hub
An example. You choose the fields in the pipeline.
| deviceId | asset | signal | value | unit | quality |
|---|---|---|---|---|---|
| plant1-line2 | line2/robot4 | joint_torque | 41 | Nm | good |
Set it up in three steps
- 1
Connect OPC UA
Add the OPC UA server, browse its address space and pick the nodes, or add hundreds at once with bulk creation.
- 2
Give the values meaning
Map each value to a topic in the namespace with its name, unit and schema. Quality and origin are stamped on every value.
- 3
Deliver to Azure IoT Hub
Add an Azure IoT Hub output with the device credentials; routing properties steer messages to the right endpoint.
Before you start
What each side needs, from the connector documentation.
OPC UA
- The server address, built as opc.tcp://host:port/path. The standard OPC UA port is 4840.
- For any Security Policy other than None, a client certificate: paste your own (RSA keys only) or let MaestroHub generate a self-signed one.
- If you use the auto-generated certificate, the OPC UA server administrator must trust it on the server.
- A username and password when the server does not allow Anonymous access.
Example settings
- Server Hostname
- opcua.example.com
- Port
- 4840
- Security Policy
- Basic256Sha256
- Security Mode
- SignAndEncrypt
- Certificate Mode
- Auto-generate (self-signed)
- Authentication Type
- UsernamePassword
Azure IoT Hub
- An IoT Hub hostname, for example myhub.azure-devices.net, and a device identity registered in the hub.
- Credentials for that device: its symmetric key, a shared access policy name and key, or an X.509 certificate and private key in PEM.
- For X.509, a certificate whose CN matches the Device ID.
- Network access to the hub over MQTT 3.1.1 with TLS on port 8883.
Example settings
- IoT Hub Hostname
- myhub.azure-devices.net
- Device ID
- <your-device-id>
- Authentication Method
- X.509 Certificate
- Keep Alive (seconds)
- 230
- Connection Timeout (seconds)
- 30
- QoS Level (D2C Send)
- 1
Things to know
Pitfalls and limits the documentation calls out, so they don't surprise you on site.
OPC UA
- Security Policy and Security Mode must agree. Policy None requires Mode None. Any other policy requires Sign or SignAndEncrypt.
- Node identifiers need a namespace index and a type prefix (i=, s=, g=, b=). Namespace 0 is typically standard nodes, 2 and up custom nodes. Browse a small scope first to find the exact IDs.
- On Monitor functions, set the sampling interval equal to or faster than the publishing interval, or changes can be missed. Subscriptions are recreated automatically after a lost connection or a session timeout.
Limits
- Manual client certificates support RSA keys only. Auto-generated certificates are RSA 2048-bit and valid for 365 days.
- Monitor functions cannot be created through Quick Add. Use the full Function Builder.
Azure IoT Hub
- IoT Hub supports QoS 0 and 1 only. QoS 2 is not supported.
- Keep Content Type application/json and Content Encoding utf-8 if you route messages on the JSON body.
- Turn on Sync Full Twin on Twin Desired functions so changes made while offline are delivered after every reconnect, including the periodic SAS token renewal.
Limits
- D2C message payloads are limited to 256 KB and Device Twin reported properties to 32 KB.
- Keep alive is capped at 1177 seconds by Azure IoT Hub, and the device twin round-trip has its own 10 second reply window.
What teams use it for
Azure analytics pipelines
IoT Hub onward to Stream Analytics, Event Hubs or Fabric.
Remote configuration
Desired properties from the cloud adjust edge behaviour.
Alerting in Azure
Telemetry rules and notifications on named, quality-checked values.
Ways to connect OPC UA to Azure IoT Hub
In general terms. Check any specific product for its own details.
Compare a custom script, a flow tool, a cloud vendor's edge service and MaestroHub
Swipe sideways to see every column
| A custom script | A flow tool | A cloud vendor's edge service | MaestroHub | |
|---|---|---|---|---|
| Talks OPC UA | A library you choose | Community plug-ins | Depends on the vendor | Built in, one of 90+ connectors |
| Names, units and schema | You write it | You build it | Partly, in the vendor's model | One governed namespace |
| Quality on every value | You write it | You build it | Depends on the vendor | Built in, carried through calculations |
| Where each value came from | You write it | You build it | Depends on the vendor | Stamped on every value |
| Survives a network outage | You build it | You build it | Usually, to that vendor's cloud | On disk, per destination, in order |
| Several destinations at once | One script each | Yes, flow by flow | Mostly that vendor's cloud | Any mix, each with its own buffer |
| Permissions and audit | You build it | You build it | Cloud account permissions | Roles, single sign-on, audit trail |
| AI agents can use the data | You build it | You build it | Depends on the vendor | Through the MCP server |
Questions
How do I send OPC UA data to Azure IoT Hub?
Read the OPC UA nodes with MaestroHub, give them meaning, and send them to Azure IoT Hub as device-to-cloud telemetry with routing properties. Cloud-to-device messages and Device Twin properties work the other way, and messages are buffered through outages.
Do I need to write code to connect OPC UA to Azure IoT Hub?
No. You configure the OPC UA connection and the Azure IoT Hub output in MaestroHub and join them with a pipeline. Transformations can be added where you need them.
Where does MaestroHub run for this?
On your own infrastructure next to the machines: an edge box, a virtual machine or Kubernetes. Nothing has to leave your network.
Why not just write a script for OPC UA to Azure IoT Hub?
A script works on day one. The cost comes later: decoding and naming values, handling bad quality, buffering through outages, keeping credentials safe, and doing it again for the next machine and the next destination. MaestroHub does those once, for every connector.
What else can OPC UA data go to?
More than 90 connectors are included in every edition, among them historians, databases, cloud warehouses, message brokers and business systems, so the same values can feed several destinations at once.
Try OPC UA to Azure IoT Hub yourself.
The free trial includes every connector. No factory to hand? The Digital Factory Simulator serves OPC UA, Modbus, MQTT and more on your laptop.


