Apps
Microsoft Graph
Interpres Application - Microsoft Graph
- Type: Endpoint
- Vendor: Microsoft
This app integrates with Microsoft Graph Advanced to get detections, alerts, and telemetry
- Search for App registrations
data:image/s3,"s3://crabby-images/1318a/1318a14f83723b76424fc63bd3c42325a066335d" alt="Document image Document image"
- Click + New registration
data:image/s3,"s3://crabby-images/03972/039729d64e34d684f1c3944185f02a7eb1904012" alt="Document image Document image"
- Enter "Interpres" for the app name. Leave the other defaults (Single-tenant, no Redirect URI). Click "Register".
data:image/s3,"s3://crabby-images/2edbd/2edbda23a8b54f88b76a6e40aad237bf6cd18ecf" alt="Document image Document image"
- Copy the application (client) ID and the Directory (tenant) ID over to the Interpres integration setup page
data:image/s3,"s3://crabby-images/70337/703374c0f791a9bdb1ca638730b28976539ba53b" alt="Document image Document image"
- Click Manifest
data:image/s3,"s3://crabby-images/1a832/1a8321d18ce6eefabb6dedf50e9992a30961869c" alt="Document image Document image"
- Replace requiredResourceAccess with the following:
As an alternative to Step 7, you can manually add the following permissions (as Application):
- Click Save
data:image/s3,"s3://crabby-images/ea9ea/ea9ea3f33d6b7eac472d1a994cacd329786db451" alt="Document image Document image"
- Click API permissions then Grant admin consent for YOUR_TENANT
data:image/s3,"s3://crabby-images/edbfa/edbfa38413132f6aa21b00b69c4c3b654365cefb" alt="Document image Document image"
- Click Certificates & Secrets then New client secret
data:image/s3,"s3://crabby-images/50c98/50c98f3cbfaefc49aa70afb60112f4106e475aca" alt="Document image Document image"
- Enter "Interpres" for the description and choose "12 months".
data:image/s3,"s3://crabby-images/d3fb1/d3fb14fe025b20c6b2294fa230c578e55d555e96" alt="Document image Document image"
- Copy the client secret "Value" over to the Interpres integration setup.
- tenant_id (string): Tenant ID
- client_id (string): Client ID
- client_secret (password): Client Secret
- max_search_size (numeric): The maximum number of alerts to grab per query frequency. The query frequency is set to 10 minutes by default.
Check there is connectivity (green light) in the integration created.
- get_alerts: Gets the latest alerts.
- get_available_telemetry: Returns a list of telemetry identifiers with their current status.
- get_detections: Returns a list of detections.