...
The Microsoft Graph Collector provides the ability to collect data and intelligence from services such as Microsoft 365, Windows, and Enterprise Mobility and Security. This data collector is able to ingest security alerts, scores, provisioning, audit, and sign-ins retrieved from Microsoft products, allowing you to empower the streamlined security operations and better defend against threats faced in Azure AD and Microsoft 365 environments.
...
Note |
---|
You need the Admin level permissions on the Azure portal as the subscription setup will require admin consent API permissions, authentications, and audits. |
| Action | Steps |
---|
1 | Register and configure the application | Go to Azure portal and click on Azure Active Directory. Click on App registration on the left-menu side. Then click on + New registration. On the Register and Application page: Name the application. Select Accounts in any organizational directory (Any Azure AD directory - Multitenant) and personal Microsoft accounts (e.g. Skype, Xbox) in Supported Accounts type. In Redirect URI (optional) leave it as default (blank). Click Register.
App registration page will open. Click on your app to configure it and give it permissions. You will see your app’s dashboard with information (docs, endpoints, etc.) when clicking it. Click Authentication on the left-menu side, then choose + Add a platform and select Mobile and desktop application. Select the three redirects URIs: https://login.microsoftonline.com/common/oauth2/nativeclient https://login.live.com/oauth20_desktop.srf msale36f3a02-3eef-437b-874e-8a0aa29a2bf0://auth
Click Configure.
|
---|
2 | Grant the required permissions | Go to API permissions on the left-menu side. Click + Add permission in case you don’t have Microsoft Graph in the API/Permission list. Select Application permissions and search for Security. Check SecurityEvents.Read.All . Repeat the same step 3 for AuditLog.Read.All ,Directory.Read.All and User.Read . If you did everything correctly, permissions will display. Select Grant admin consent for the applications.
Info |
---|
You do not need to activate permissions if you are not going to use its corresponding resource. Check the Permissions reference per service section for a detailed breakdown on resource and their needed permissions. |
|
---|
3 | Obtain the requires credentials for the collector | Go to Certificates & Secrets, select + New client secret . Named it and copy the token value. Go to Overview to get your Tenant ID and Client ID and copy both values.
Note |
---|
The token will display only once. You will need to create another one if you didn’t copy it the first time. |
|
---|
...