Error 403 Forbidden when connect to Microsoft Defender API

Yu Feng Ong 6 Reputation points
2021-05-18T05:33:18.733+00:00

Hi all

I am trying to connect to Microsoft Defender API using Elastic Filebeat. I followed the instructions here exposed-apis-create-app-webapp register a new application with granted permission.

97355-capture.png

However, when trying to call the api, i encountered this message:

Error while processing http request: failed to execute http client.Do: server responded with status code 403:
{"error":{"code":"Forbidden","message":"The application does not have any of the required application permissions
(Alert.ReadWrite.All, Alert.Read.All, Incident.ReadWrite.All, Incident.Read.All) to access the resource.","target":<target id>}}
{"input_source": "https://api.security.microsoft.com/api/incidents", "input_url": "https://api.security.microsoft.com/api/incidents"}

Can anyone assist me on this ?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,559 questions
{count} vote