...
8.Click Application permissions
...
If using hostname in integration parameters:
graph.microsoft.com/v1.0/security/alerts
: Expand SecurityActions and SecurityEvents, select Read.All permissions under both and click on Add permissions.If using hostname in integration parameters:
graph.microsoft.com/beta/security/alerts_v2
, please Please grant SecurityAlert.Read.All permission.
...
On the next screen, click Grant Admin consent for Default Directory
...
Click on Certificates & secrets
...
Click on New Client secret, Create a new key as shown below
...
Copy the Secret Value displayed, this will be required for integration.
...
Secret Value will be displayed only once, so make sure to copy it first before leaving this page.
...
Property | Default Value | Description |
---|---|---|
OAUTH CLIENT ID | N/A | Specify the client ID of the Entra ID application to use for the integration. |
OAUTH CLIENT SECRET | N/A | Specify the client secret value (not the secret ID!) of the Entra ID app |
TENANT ID | N/A | Specify the Entra ID (tenant ID). |
API FULL PATH |
| API full pathFor alerts_v2 please use: |
API AUTHENTICATION ENDPOINT | The Microsoft Active Directory authentication endpoint. | |
ASSET NAMESPACE | N/A | To assign an asset namespace to all events that are ingested from a particular feed, set the |