Security Pulse : Microsoft Integrations (Microsoft 365, Microsoft Cloud App Security, Microsoft Defender ATP)

This article provides instructions for connecting all Microsoft 365 integrations to Security Pulse. After completing the setup, Microsoft 365 will provide details on alerts from the configuration integrations and will populate the Security Pulse dashboards.

 

Prerequisites

Microsoft 365 : To successfully connect Microsoft 365, you must have one of the following Microsoft license packages:

  1. Microsoft 365 E5 with the Microsoft 365 E5 Security and Microsoft 365 E5 Compliance add-ons

  2. Microsoft Enterprise Mobility with the Microsoft 365 E5 Security add-on

  3. Microsoft Office 365 E5

Additional details can be found in Microsoft’s Defender XDR licensing requirements.

Integration Setup Process

The integration setup consists of the following steps:

  1. Register the Security Pulse Application

  2. Add API Permissions

  3. Create a Client Secret & Configure Phriendly Phishing Platform. 

Step 1 : Register the Security Pulse Application

To begin, register the Security Pulse application within the Microsoft Azure portal. Use the following instructions to complete the registration:

  1. Access your Microsoft Azure portal and go to Microsoft Entra ID.

  2. In the left navigation menu, choose App registrations. Alternately you can find it in the search bar. 

  3. Click + New registration and enter a name for your application, such as "SecurityPulseAPIAccess".

  4. Click Register.

Step 2 : Add API Permissions

After you have registered the Security Pulse application, you can add API permissions. To add API permissions, follow the steps below:

  1. Log in to your Microsoft Azure portal and navigate to your Microsoft Entra ID.

  2. From the sidebar on the left side of the page, select App registrations.

  3. Select the registered application you created in the Register the Security Pulse Application section of this guide.

  4. From the sidebar on the left side of the page, select API permissions. Click + Add a permission.

  5. Select Microsoft Graph from the Microsoft APIs subtab.

  6. Click Application permissions.

  7. Click the SecurityAlert drop-down menu and select the check box next to each of the following

    • SecurityEvents.Read.All
    • SecurityAlert.Read.All
    • SecurityIncident.Read.All
  8. Click Add permissions.

  9. Click Grant admin consent for [your active directory name]. Once permission is granted, the triangle symbol on the right side of the page will change to a green check mark.


     

Step 3 : Create a Client Secret & Configure Phriendly Phishing Platform

After you have registered the Security Pulse application and added API permissions, you can create a client secret. To create a client secret, follow the steps below:

  1. Log in to your Microsoft Azure portal and navigate to your Microsoft Entra ID.

  2. From the sidebar on the left side of the page, select App registrations and click on the registered application you added permissions to in the Add API Permissions section of this article. When you click on the registered application, the application's overview page will display.

  3. From the sidebar on the left side of the page, select Certificates & secrets.

  4. Click + New client secret.

  5. Enter a description for the client secret and select an expiry window.

  6. Click Add. Once you click Add, the client secret Value and Expires date will display.

  7. Copy and save the client secret Value as you will need these credentials to complete the configuration setup in the Phriendly Phishing Platform. 

  8. You also need to note down the Application (Client) ID. This can be found in the Overview tab on the left of the application you created.  

  9. You then need to note down the Primary Domain of your tenant. This can found by searching and selecting Entra ID, selecting overview and then copying primary Domain. 

  10. Once you have all 3 of the following values, navigate to the Phriendly Phishing Platform and select the setting cog. 

    • Application (Client) ID
    • Client secret Value
    • Primary Domain (Tenant Domain)
  11. Then select App Integrations tab and then the arrow drop down for the integration you want to configure. 

  12. Next enter the values into the respective fields

  13. Once all values have been entre you will be able to select Test Connection.

    You will receive the following message if it was configured correctly. 

  14. Lastly, you can select Add integrations which will save the settings. 

  15. You have now configured this integration. You can use the same values for all 3 Microsoft integrations. Just repeat steps 11-14 for each of them. 

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.