Skip to content
English
  • There are no suggestions because the search field is empty.

Data Integration Guide - Microsoft O365/Graph

For Microsoft's documentation on this process, please see this link

🔒 Granting Access 

  1. To grant access you will need to register a new “Application” in Azure Active Directory 
  2. Grant the appropriate permissions to the newly created application 
  3. Generate a client secret that the Unify platform can use to access the API.
  4. Enter the generated values into the Microsoft Graph Client Unify integration page:

✅ Permissions 

⚠️ Please ensure that all permissions granted for the API credentials are set as Application Level Permissions

If your organization subscribes to the following policies/services, please ensure these 

providers are configured to send alerts to the graph API: 

  • Microsoft Defender for Endpoint* 
  • Microsoft Defender for Identity** 
  • Microsoft Cloud App Security 
  • Microsoft 365 
  • Azure Security Center 
  • Azure Active Directory Identity Protection 
  • Azure Information Protection 
  • Azure Sentinel 
API Access Level
SecurityAlert.Read.All
SecurityEvents.Read.All
Azure AD User.Read.All
Intune DeviceManagementApps.Read.All
  DeviceManagementConfiguration.Read.All
  DeviceManagementManagedDevices.Read.All
  DeviceManagementServiceConfig.Read.All
  Device.Read.All
Privileged Identity Monitoring PrivilegedAccess.Read.AzureAD
  PrivilegedAccess.Read.AzureADGroup
Attack Simulation AttackSimulation.Read.All
Sign-Ins AuditLog.Read.All 
Service Usage Reports Reports.Read.All
Additional Security Events Policy.Read.ConditionalAccess

 

* Microsoft Defender for Endpoint requires additional user roles to those required by 

the Microsoft Graph Security API. Only the users in both Microsoft Defender for 

Endpoint and Microsoft Graph Security API roles can have access to the Microsoft 

Defender for Endpoint data. Because application-only authentication is not limited by 

this, we recommend that you use an application-only authentication token. 

** Microsoft Defender for Identity alerts are available via the Microsoft Cloud App 

Security integration. This means you will get Microsoft Defender for Identity alerts 

only if you have joined Unified SecOps and connected Microsoft Defender for Identity 

into Microsoft Cloud App Security. Learn more about how to integrate Microsoft 

Defender for Identity and Microsoft Cloud App Security

⚠️ Required Information

The values Living Security will need to access the API are:

  • Application/Client ID
  • Directory/Tenant ID
  • Client Secret