ms365 alert.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Microsoft 365 / Microsoft Defender

Microsoft 365 / Microsoft Defender

The Dropzone AI platform integrates with Entra ID, Exchange Online, and Microsoft Defender via the Microsoft Graph API. This document describes how to set up API credentials and install them into the Dropzone platform.

Integration Overview

To enable these integrations you will perform the following actions:

See the Microsoft Integrations page for instructions on how to register a new application, locate your Client ID and Tenant ID, and create a Client Secret.

Set Application Permissions

General instructions on how to assign API permissions to the application can be found in the Microsoft Integrations page.

MS 365/MS Defender can utilize the following APIs:

API Purpose
Microsoft Graph Required for the integration to function
Microsoft Cloud Apps Security. Required to query investigations from Microsoft Cloud Apps. When enabled, Dropzone is able to analyze cloud apps events
Windows Defender ATP - Live Response. Required to extract quarantined files from Defender alerts. When enabled, Dropzone is able to independently analyze the files which will improve conclusion accuracy
Office 365 Exchange Online Management Required to enable Office 365 Exchange Online Management, specifically to support retrieving quarantined emails during phishing analysis

Microsoft Graph Permissions

Select Microsoft Graph

Select Application Permissions

Add the following permissions:

Permission Purpose Used By
AuditLog.Read.All Retrieve audit information such as user MFA and administrator access status, for alert investigation and chat Data Source Integration, Alert Source Integration - Microsoft Entra ID Protection
Calendars.Read Allow access to Microsoft Calendar, for use in investigations to determine user OOO / travel status Data Source Integration - Calendar Features
Calendars.ReadBasic.All Retrieve basic calendar information for use in investigations to determine user OOO / travel status Data Source Integration - Calendar Features
MailboxSettings.Read Retrieve mailbox settings, such as OOO or vacation status Data Source Integration - Calendar Features
Presence.Read.All Retrieves presence information, such as availability status, location, etc Data Source Integration - Calendar Features
Directory.Read.All Retrieve directory information such as users, group membership, directory roles, etc, for alert investigation and chat Data Source Integration
Mail.Read Retrieve phishing emails for analysis; retrieve phishing alerts in some configurations Alert Source and Data Source Integrations
ThreatHunting.Read.All Investigating Microsoft Defender alerts Alert Source Integration
SecurityAlert.Read.All Pulling Microsoft Defender alerts Alert Source Integration
SecurityIncident.Read.All Pulling Microsoft Defender alerts Alert Source Integration
ThreatSubmission.Read.All Pulling Phishing Alerts Alert Source Integration
IdentityRiskEvent.Read.All Pulling Microsoft Entra ID Risk information Alert Source Integration - Microsoft Entra ID Protection
IdentityRiskyUser.Read.All Pulling Microsoft Entra ID Risk information Alert Source Integration - Microsoft Entra ID Protection
IdentityRiskyServicePrincipal.Read.All Pulling Microsoft Entra ID Risk information Alert Source Integration - Microsoft Entra ID Protection
User.Read.All Allow Dropzone to read all user profile properties when investigating suspicious alerts Remediator Integration
User.RevokeSessions.All Allow Dropzone to revoke user sessions of users indicated in suspicious alerts Remediator Integration
User.EnableDisableAccount.All Allow Dropzone to suspend accounts indicated in suspicious alerts Remediator Integration

Example - adding the "User.Read.All" permission

{% hint style="info" %} Some of these permissions are only necessary for the Data Source and Remediator integrations. If you don't intend to perform those integrations, you may ignore them.

Enabling Dropzone's Data Source Calendar Features is optional. Enabling Dropzone's Alert Source Microsoft Entra ID Protection feature is optional. {% endhint %}

Grant admin consent

Grant admin consent

Microsoft Cloud Apps Security Permissions

Microsoft Cloud App Security

Add the following permissions:

Permission Purpose
investigation.read Read Cloud App investigations

Windows Defender ATP - Live Response

WindowsDefenderATP

Add the following permissions:

Permission Purpose
File.Read.All Read file profiles. Note that this is different from the "Files.Read.All" permission
Library.Manage Extract quarantined files for analysis
Machine.LiveResponse Extract quarantined files for analysis
Machine.Read.All Read machine details

Example - adding the "File.Read.All" permission

Locate Organization ID

Azure Custom Domain Names

Azure Custom Domain Names List

Locate Cloud Apps Information

Defender Cloud Apps API URL

Record the "API URL" for use later in the Dropzone UI where it is called "Portal URL".

Enable Microsoft 365/Microsoft Defender

The Alert Source integration allows Dropzone AI to pull alerts from Exchange Online and Microsoft Defender for investigation.

You'll need the following information:

Dropzone Field Source
Client ID The "Application (client) ID" you copied earlier
Tenant ID The "Directory (tenant) ID" you copied earlier
Client Secret The client secret "value" you copied earlier
Organization ID The "Organization ID" you copied earlier

To enable the Alert Source integration, do the following:

Integrations Dropdown

Click Available

The Microsoft 365/Defender Source Tile

The Microsoft 365/Defender Alert Configuration (pt 1)

The Microsoft 365/Defender Alert Configuration (pt 2)

The Microsoft 365/Defender Alert Configuration (pt 3)

The Microsoft 365/Defender Alert Configuration (pt 4)

The Microsoft 365/Defender Alert Configuration - Entra ID (pt 1)

The Microsoft 365/Defender Alert Configuration - Entra ID (pt 2)

The Microsoft 365/Defender Alert Configuration - Entra ID (pt 3)

{% hint style="success" %} This will allow your organization to limit the scope of Dropzone AI's Mail.Read permissions. See the Mail-Enabled Security Group documentation for instructions on how to create a designated phishing account. {% endhint %}

The Microsoft 365/Defender Alert Configuration (pt 5)

The Microsoft 365/Defender Alert Configuration (pt 6)

The Microsoft 365/Defender Alert Configuration (pt 7)

The Microsoft 365/Defender Alert Configuration (pt 7)

The Microsoft 365/Defender Alert Configuration (pt 8)

The Microsoft 365/Defender Alert Configuration (pt 9)

Click Test & Save

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.