IBM Security QRadar

 View Only
  • 1.  Microsoft Defender 365 - Graph Security API

    Posted Mon March 18, 2024 12:05 PM

    Hi everyone, i have a problem on configuring the microsoft defender log source protocol tab for my client. I didn't find anything about what kind of url i need to add at "Login Endpoint" voice. I try with login.microsoftonline.com or https://login.microsoftonline.com/"with tenant id correct"/oauth2/v2.0/authorize but the test at the dns resolutions step tell me "Unable to resolve login.microsoft.com" any suggestions on the cause of the problem? and anyone could tell me the right url to add? 

    Thanks a lot 



    ------------------------------
    Simone Tacchella
    ------------------------------


  • 2.  RE: Microsoft Defender 365 - Graph Security API

    Posted Tue March 19, 2024 09:29 AM

    The API is probably no longer available from Microsoft. I assume neither work:
    "Microsoft no longer allows the onboarding of new integrations with their SIEM API. For more information, see Deprecating the legacy SIEM API (https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/deprecating-the-legacy-siem-api/ba-p/3139643)." 
    Reference: https://www.ibm.com/docs/en/dsm?topic=m3d-microsoft-defender-endpoint-siem-rest-api-log-source-parameters



    ------------------------------
    JOHN HANDROP
    ------------------------------



  • 3.  RE: Microsoft Defender 365 - Graph Security API

    Posted Tue March 19, 2024 09:46 AM

    Really appreciated your answer, so the only way to integrate on Qradar the microsoft 365 defender logs it is with the azure event hub, cause my costurmer didn't want to configure it, all API the REST one and the GRAPH one aren't avaible right?



    ------------------------------
    Simone Tacchella
    ------------------------------



  • 4.  RE: Microsoft Defender 365 - Graph Security API

    Posted Tue March 19, 2024 12:52 PM

    No, you can still use Graph API. The only one that is deprecated is the REST API. Here is how to configure on Azure side: https://www.ibm.com/docs/en/dsm?topic=options-configuring-microsoft-graph-security-api-communicate-qradar

    I've used it a dozen times for clients using /alerts_v2 and Microsoft 365 Defender DSM. No issues. 

    If you use log source type 'Microsoft 365 Defender' and protocol type 'Microsoft Security Graph API' you don't get asked for a login endpoint. 



    ------------------------------
    Jason Quinn
    ------------------------------