This article provides instructions for connecting all Microsoft 365 integrations to Security Pulse. After completing the setup, Microsoft 365 will provide details on alerts from the configuration integrations and will populate the Security Pulse dashboards.
Prerequisites
Microsoft 365 : To successfully connect Microsoft 365, you must have one of the following Microsoft license packages:
Microsoft 365 E5 with the Microsoft 365 E5 Security and Microsoft 365 E5 Compliance add-ons
Microsoft Enterprise Mobility with the Microsoft 365 E5 Security add-on
Microsoft Office 365 E5
Additional details can be found in Microsoft’s Defender XDR licensing requirements.
Integration Setup Process
The integration setup consists of the following steps:
Register the Security Pulse Application
Add API Permissions
Create a Client Secret & Configure Phriendly Phishing Platform.
Step 1 : Register the Security Pulse Application
To begin, register the Security Pulse application within the Microsoft Azure portal. Use the following instructions to complete the registration:
Access your Microsoft Azure portal and go to Microsoft Entra ID.
In the left navigation menu, choose App registrations. Alternately you can find it in the search bar.
Click + New registration and enter a name for your application, such as "SecurityPulseAPIAccess".
Click Register.
Step 2 : Add API Permissions
After you have registered the Security Pulse application, you can add API permissions. To add API permissions, follow the steps below:
Log in to your Microsoft Azure portal and navigate to your Microsoft Entra ID.
From the sidebar on the left side of the page, select App registrations.
Select the registered application you created in the Register the Security Pulse Application section of this guide.
From the sidebar on the left side of the page, select API permissions. Click + Add a permission.
Select Microsoft Graph from the Microsoft APIs subtab.
Click Application permissions.
-
Click the SecurityAlert drop-down menu and select the check box next to each of the following
- SecurityEvents.Read.All
- SecurityAlert.Read.All
- SecurityIncident.Read.All
Click Add permissions.
Click Grant admin consent for [your active directory name]. Once permission is granted, the triangle symbol on the right side of the page will change to a green check mark.
Step 3 : Create a Client Secret & Configure Phriendly Phishing Platform
After you have registered the Security Pulse application and added API permissions, you can create a client secret. To create a client secret, follow the steps below:
Log in to your Microsoft Azure portal and navigate to your Microsoft Entra ID.
From the sidebar on the left side of the page, select App registrations and click on the registered application you added permissions to in the Add API Permissions section of this article. When you click on the registered application, the application's overview page will display.
From the sidebar on the left side of the page, select Certificates & secrets.
Click + New client secret.
Enter a description for the client secret and select an expiry window.
Click Add. Once you click Add, the client secret Value and Expires date will display.
Copy and save the client secret Value as you will need these credentials to complete the configuration setup in the Phriendly Phishing Platform.
You also need to note down the Application (Client) ID. This can be found in the Overview tab on the left of the application you created.
You then need to note down the Primary Domain of your tenant. This can found by searching and selecting Entra ID, selecting overview and then copying primary Domain.
-
Once you have all 3 of the following values, navigate to the Phriendly Phishing Platform and select the setting cog.
- Application (Client) ID
- Client secret Value
- Primary Domain (Tenant Domain)
Then select App Integrations tab and then the arrow drop down for the integration you want to configure.
Next enter the values into the respective fields
Once all values have been entre you will be able to select Test Connection.
You will receive the following message if it was configured correctly.Lastly, you can select Add integrations which will save the settings.
You have now configured this integration. You can use the same values for all 3 Microsoft integrations. Just repeat steps 11-14 for each of them.
Comments
Please sign in to leave a comment.