-
Notifications
You must be signed in to change notification settings - Fork 515
Open
Labels
Integration:microsoft_defender_cloudMicrosoft Defender for CloudMicrosoft Defender for CloudTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or requestneeds:triage
Description
Integration Name
Microsoft Defender for Cloud [microsoft_defender_cloud]
Dataset Name
No response
Integration Version
3.1.1
Agent Version
9.2.1
OS Version and Architecture
Debian
User Goal
Configure the integration to work with Microsoft's Partner Center and its granular delegated admin privileges (GDAP) constructs to authorize and collect tenant information.
Existing Features
Similar to work we previously did for both Microsoft Office 365 (#14924) and Microsoft Defender Endpoint (#15605), we need to expose the "OAuth2 Endpoint Params" via the integration to allow users to modify the grant_type and the refresh_token value.
What did you see?
This integrations options: https://www.elastic.co/docs/reference/integrations/microsoft_defender_cloud
The other integration options:
- https://www.elastic.co/docs/reference/integrations/o365
- https://www.elastic.co/docs/reference/integrations/microsoft_defender_endpoint
Anything else?
Metadata
Metadata
Assignees
Labels
Integration:microsoft_defender_cloudMicrosoft Defender for CloudMicrosoft Defender for CloudTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or requestneeds:triage